Malicious RTF — malware analysis report

Static analysis result for SHA-256 c2ba362693aad868…

MALICIOUS

RTF

236.4 KB Authoring application: Msftedit 5.41.21.2510 First seen: 2022-07-08
MD5: b8387fc571a8e79efab3e2cc343aae24 SHA-1: 2b7975e6b1e9b72e9eb06989e5a8b1f6fd9ce027 SHA-256: c2ba362693aad8686f79822712c3871f0da1570465578843f5d73c70db07e631
82 Risk Score

Malware Insights

MITRE ATT&CK
T1559.002 Component Object Model Hijacking T1059.001 PowerShell

The RTF document contains multiple OLE objects, with one specifically triggered by \objupdate, indicating an attempt to exploit OLE activation. The embedded URL, although labeled benign, is present within the RTF body, suggesting a potential lure. The document's content, when decoded, appears to be a notification regarding a standardization program, which could be a pretext for the malicious activity.

Heuristics 4

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 3 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://fgis.gost.ru/share/page/help

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000cb6.bin
dc1232b57c5c684b6838329879533b945a263fd5a3bb1825d50f58d153a77e68
rtf-objdata-decoded RTF \objdata at offset 0xCB6 112380 bytes
objdata_01_off00037ad4.bin
624cd8895a4ecc5a0a871cb6215c2b19f4fae3b522107541fa9df8c8983ecb35
rtf-objdata-decoded RTF \objdata at offset 0x37AD4 6847 bytes
objdata_02_off00037aee.bin
05ba095ac605422898d063511280e25730e5e1dd91478e3cd20e32a7ee2beec8
rtf-objdata-decoded RTF \objdata at offset 0x37AEE 6843 bytes