Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 fd9fe0ade0e4a028…

MALICIOUS

RTF / .DOC

126.5 KB
MD5: b9dde198d2ca4cb42b39ed65c78a7432 SHA-1: 3b9266bf5d632b03d4d68de30dc3c42454b9422d SHA-256: fd9fe0ade0e4a0288bc1274ad9ebd5b080c82e6b221e243cd2810d94368e097b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.001 PowerShell

The RTF document contains OLE object data and triggers an \objupdate event, indicating an attempt to exploit a vulnerability for code execution. The high-severity RTF_OBJUPDATE heuristic suggests that embedded OLE objects are being activated, which is a common technique for delivering malicious payloads. While no specific script was extracted, the heuristics strongly suggest a malicious RTF exploit. The exact payload and delivery mechanism remain unclear without further analysis or script content.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000020da.bin
e0cf98c5474b5845186f1016da704daa95201bc4f43002b52f3afc8e96ba1c66
rtf-objdata-decoded RTF \objdata at offset 0x20DA 2464 bytes