Malicious RTF — malware analysis report

Static analysis result for SHA-256 d4f218978b7b1f49…

MALICIOUS

RTF

3.8 KB First seen: 2021-01-11
MD5: 21d9ad9492e9e80d42b4cda5160261ce SHA-1: 5d3c546c3c8696d0f2010ec9c23d29536b74eac8 SHA-256: d4f218978b7b1f49a6729135dedb55253d86e229c71ac1c834160029c9b1eed8
60 Risk Score

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000013b.bin rtf-objdata-decoded RTF \objdata at offset 0x13B 1789 bytes
SHA-256: bde7ac9dcfd95297810c95f57184425f69a8baa2e988deb9f10e6f1ad4c755aa