Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 e878bc9103eb16c9…

MALICIOUS

RTF / .DOC

95.7 KB
MD5: 6c742b311a8b24d3b1978089205f4133 SHA-1: 85c410a246db5077f2f09e2daf9c088a71ad7850 SHA-256: e878bc9103eb16c9edec5cb0efbc8ae207b0a22eb8dcd022e22863eeb644b484
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains OLE object data and triggers an \objupdate event, indicating an attempt to exploit OLE object handling vulnerabilities. This suggests the document is designed to deliver a malicious payload when opened. No specific malware family could be identified, and no further IOCs were extracted.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001298.bin
323e042852eea9444c3e67843f8eb1a971e607fae33fa3f1ee8fca8ce5b06759
rtf-objdata-decoded RTF \objdata at offset 0x1298 1796 bytes