Malicious RTF — malware analysis report

Static analysis result for SHA-256 f9cacd2c336fc632…

MALICIOUS

RTF

128.0 KB First seen: 2019-01-12
MD5: 84e71ae6583b0db49a96aa1a572dfe70 SHA-1: f7da7b94e7b930aabe9013d45c4e7a9e29e7a13a SHA-256: f9cacd2c336fc6327bed88ad6009d9faba1b0da781c34a9cb8ead882fda296ee
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains embedded OLE object data that is forced to activate via \objupdate. This indicates an attempt to exploit a vulnerability for client execution, likely delivered as a spearphishing attachment. The specific payload or its destination could not be determined from the available evidence.

Heuristics 3

  • Ole10Native stream in RTF OLE object high CVE related RTF_OLE10NATIVE_STREAM
    RTF contains an embedded OLE object with an Ole10Native stream. This is a strong payload-container signal and is related to Word/OLE exploit delivery, but it is not specific enough on its own to assign a CVE.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000003c.bin rtf-objdata-decoded RTF \objdata at offset 0x3C 35629 bytes
SHA-256: e0edc6c065dc9f0c58b024bd7828c4aa893cd95434971dcae1bc0c377d3c21ea