Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 e444235d724ef3b0…

MALICIOUS

RTF / .DOC

57.2 KB
MD5: e96172eec7c451fd6900a78b254f53f3 SHA-1: 0f3dd04b03752aa2a1ce8d4f3752706fe0baedad SHA-256: e444235d724ef3b01a7f994af95d6f64027803048bc3e5f3e7e8542dfb705416
80 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains embedded OLE objects, with heuristics indicating that \objupdate forces OLE activation. This suggests the document is designed to exploit a vulnerability, likely through the embedded object, to achieve arbitrary code execution. No specific malware family could be identified from the available evidence.

Heuristics 3

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000560.bin
8170c91f56eec3f7acfe64677aca48798a6e7dac01634109c9587f92e2673e02
rtf-objdata-decoded RTF \objdata at offset 0x560 2055 bytes