Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 dc9078bfe5df2881…

MALICIOUS

RTF / .DOC

79.5 KB
MD5: eb5e4ebc48b2571c476fcc2a82cfaca0 SHA-1: 50fa0b6f586df240c2419cc79abcdbe832041834 SHA-256: dc9078bfe5df2881fadd8a4e9fbea936ad5acd1060dba9036d3f5c7ab1008a48
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File T1059.001 PowerShell

The RTF document contains an embedded OLE object, indicated by the RTF_OBJDATA heuristic. The RTF_OBJUPDATE heuristic suggests that this object is designed to be activated automatically upon opening, which is a common technique for exploiting vulnerabilities in applications like Microsoft Office. While no specific exploit is identified, the presence of these indicators strongly suggests an attempt to leverage an Office vulnerability to execute arbitrary code, likely for downloading and running a second-stage payload. No document body or script content was available for further analysis.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000182a.bin
5cea36270e4908117994651be56e23faabd413e1fcc21ccd298f84d77d4ed820
rtf-objdata-decoded RTF \objdata at offset 0x182A 4228 bytes