Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 cb4ad208cd7b2227…

MALICIOUS

RTF / .DOC

109.8 KB
MD5: 505c3df00817113b98a4ebfeac89063f SHA-1: 4d12984ca26fbcc76044fcffaf22e036d93903e7 SHA-256: cb4ad208cd7b22277225b548a4a83b63daa0090070103a263b65b512dbe2884c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The RTF document contains OLE object data and an \objupdate directive, indicating it's designed to embed and activate external content. While no specific payload or URL was extracted, the heuristics strongly suggest a malicious OLE object is present. The lack of readable document body text or scripts limits further analysis, but the core mechanism points to a delivery attempt.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002072.bin
6f6cacfa8753cdcc072d8a94e0847e923ec3165e6218fa682ea2f1a9b6c7aec4
rtf-objdata-decoded RTF \objdata at offset 0x2072 1750 bytes