Malicious RTF — malware analysis report

Static analysis result for SHA-256 cd25cea911bae68c…

MALICIOUS

RTF

438.3 KB Created: 2020-03-22 17:37:00
MD5: 76387fb419cebcfb4b2b42e6dc544e8b SHA-1: b1229b3f6ee85d550e6c0ed8de69571b1cc2cd32 SHA-256: cd25cea911bae68cf7672539cf6d2748753719bd7494bc9330171d83e4330d03
80 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains multiple OLE objects, with one specifically triggering an \objupdate command. This indicates an attempt to exploit embedded OLE functionality, likely for malicious purposes such as executing embedded code or downloading a secondary payload. The presence of large objdata sections suggests the embedding of significant content, potentially the payload itself. No document body text was available for further context.

Heuristics 4

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 3 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000094b3.bin
27a3e86635d16cf573a3b75af69d5dcf6794e77708d268bc7f26d435e3e47d5d
rtf-objdata-decoded RTF \objdata at offset 0x94B3 107 bytes
objdata_01_off0000a517.bin
294f4dbac0a5821a6e0a7747227f87e9870e67ae445e78d0eb8a44755f94c95d
rtf-objdata-decoded RTF \objdata at offset 0xA517 32 bytes
objdata_02_off0000a619.bin
9c3a4d543f24d9129f00c2a28da875269d8d7d106f3dc3e81c42ab609a8ab11f
rtf-objdata-decoded RTF \objdata at offset 0xA619 114294 bytes