Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 c7483917e65c4064…

MALICIOUS

RTF / .DOC

64.7 KB
MD5: 4a487b531ffe123cc53ced92dbb6ec34 SHA-1: de5bd51eb6de4d7644d4589821ba3f766f5db822 SHA-256: c7483917e65c4064ffd877568165efa1e895022d11941aed9e2742cdcc847c32
80 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.001 PowerShell

The file is an RTF document containing embedded OLE objects, with heuristics indicating that \objupdate forces OLE activation. This suggests the document is designed to exploit a vulnerability, likely to execute a malicious payload. The specific exploit and payload are not detailed in the provided evidence, leading to an 'unknown family' classification and a moderate confidence score.

Heuristics 3

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000875.bin
cc75778808ee20c6961cda05791936867e966407941c1afe8b1d4186c4b3cba8
rtf-objdata-decoded RTF \objdata at offset 0x875 3669 bytes