Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 fe639b858b96cfe7…

MALICIOUS

RTF / .DOC

9.1 KB First seen: 2022-06-09
MD5: ecec1e067f1cfac97a04c3a90ac93810 SHA-1: 11a34f4565930bb5e74367f931f85e4099a6f7e6 SHA-256: fe639b858b96cfe7c0deef639234ce112c6e35c83d5026d96c0cb1dd09e640c4
121 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains embedded OLE objects, indicated by the RTF_OBJDATA heuristic. The RTF_OBJUPDATE heuristic suggests that these objects are configured to activate automatically upon opening the document. This mechanism is commonly used to download and execute a secondary payload. No specific family could be identified, and no IOCs were directly extractable from the provided evidence.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000ba3.bin
0ae881d0e916aaa4e0210ededaafffbe096fa1ab1bc3aae166e743394e2fc96f
rtf-objdata-decoded RTF \objdata at offset 0xBA3 1923 bytes