Malicious RTF — malware analysis report

Static analysis result for SHA-256 dbdbf3ae75ae2a71…

MALICIOUS

RTF

20.3 KB
MD5: 957313f36053565ceaedcac055b1fd20 SHA-1: 1ef757ae3c0b16b9765a20e15968fd943619dd92 SHA-256: dbdbf3ae75ae2a711fb2548afd168d5664f897c0d42c0fd2041a2d854cb81712
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains embedded OLE objects, indicated by the RTF_OBJDATA and RTF_OLE10NATIVE_STREAM heuristics. The RTF_OBJUPDATE heuristic suggests that these objects are designed to be automatically activated upon opening the document. This points to a likely attack pattern involving exploiting RTF parsing vulnerabilities to deliver a malicious payload, potentially via a downloaded second-stage executable. No scripts were extracted, and the document body was unreadable, limiting further analysis of the specific lure.

Heuristics 3

  • Ole10Native stream in RTF OLE object high CVE related RTF_OLE10NATIVE_STREAM
    RTF contains an embedded OLE object with an Ole10Native stream. This is a strong payload-container signal and is related to Word/OLE exploit delivery, but it is not specific enough on its own to assign a CVE.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000004ba.bin
aa06d546ce22fa3ecf3303ec4df91d0f875c3e268ad0b59cac575b60842a664e
rtf-objdata-decoded RTF \objdata at offset 0x4BA 4192 bytes