MALICIOUS
100
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
T1566.001 Spearphishing Attachment
The sample is an RTF document containing embedded OLE objects, indicated by RTF_OBJDATA and RTF_OBJUPDATE heuristics. The RTF_OBJAUTLINK heuristic suggests that these objects are automatically linked and activated upon opening, which is a common technique for exploiting client execution vulnerabilities. The embedded OLE object data itself is likely a payload or a loader for one.
Heuristics 3
-
Automatically linked OLE object high RTF_OBJAUTLINKRTF contains \objautlink — an automatically linked OLE object surface that can be updated or activated when Word opens the document.
-
\objupdate forces OLE activation high RTF_OBJUPDATERTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
-
OLE object data medium RTF_OBJDATARTF contains 1 \objdata section(s) — embedded OLE objects
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
objdata_00_off000015d1.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x15D1 | 63965 bytes |
SHA-256: ba5d9fc9475cb167f4abf625c206e2c958772bc9099d0f07f80eeda6a4d67d62 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.