Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 f5893287478488bf…

MALICIOUS

RTF / .DOC

13.5 KB First seen: 2022-05-24
MD5: 2f128134cacab4e4b78536da780f954d SHA-1: dff60b4f14fec9b0cef3e108f4bed86fefb5fd88 SHA-256: f5893287478488bff118b8dc31bc8ebac1f7c6fc755534c4072072ea667a1840
121 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.001 PowerShell

The RTF document contains embedded OLE object data and utilizes an \objupdate directive, indicating an attempt to exploit vulnerabilities related to OLE object activation. This strongly suggests a malicious intent to execute embedded code or trigger a download. While no specific family is identified, the technique points towards a downloader or exploit delivery mechanism.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001fab.bin
2f81c8b0a8d27bfa4ad161bc882e6fda3ff1853f7f200a415c68405d510c1aef
rtf-objdata-decoded RTF \objdata at offset 0x1FAB 1753 bytes