Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 ea9f05c0901d0d49…

MALICIOUS

RTF / .DOC

96.2 KB
MD5: 9454f13a4b45914f3fe2360cafab5c6f SHA-1: c54301ba41e01da9527f4be0ebf6219d2f6001d7 SHA-256: ea9f05c0901d0d49db164b1f297db1e65fa167b4cd7724d4a79a20ab118da1b2
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File T1027 Obfuscated Files or Information

The RTF document contains OLE object data and is configured to automatically update and activate these objects. This suggests an attempt to exploit vulnerabilities or execute embedded code upon opening. No document body text or scripts were available for further analysis, limiting the ability to determine the specific payload or delivery mechanism.

Heuristics 3

  • Automatically linked OLE object high RTF_OBJAUTLINK
    RTF contains \objautlink — an automatically linked OLE object surface that can be updated or activated when Word opens the document.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000eef.bin
4355442d29fe43d7316c2ffa494bc6f7cbdbe481e8b96839a09a0ae14dcc0763
rtf-objdata-decoded RTF \objdata at offset 0xEEF 1736 bytes