Malicious RTF — malware analysis report

Static analysis result for SHA-256 0a10ccf25323107b…

MALICIOUS

RTF

913.7 KB Created: 2018-05-17 18:55:00 First seen: 2018-11-05
MD5: 1c2327f78e65cc0f6c48436ea4650d4c SHA-1: 8a40edb3458219342877eb3f26865759ced2bbe7 SHA-256: 0a10ccf25323107b577260ec0d883de33a3d1c253728df2089b9e94271d66ea5
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains multiple embedded OLE objects, with one specifically triggering an \objupdate command. This suggests an attempt to exploit OLE object activation to execute embedded content. The presence of suspicious extracted artifacts, including shellcode command strings and auto-exec VBA, further supports this. The unknown reputation URL http://loujabinsurance.com/toure.exe is likely the source or destination for a malicious payload.

Heuristics 5

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • OLE object data medium RTF_OBJDATA
    RTF contains 5 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loujabinsurance.com/toure.exe In RTF body
    • http://schemas.microsoft.com/office/word/2003/wordmlIn RTF body

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c91.bin rtf-objdata-decoded RTF \objdata at offset 0x2C91 78894 bytes
SHA-256: ab0a16e3d62b57b7be4aa6c2ec88f12ed4360864e1c3ae01733623b4e40de16a
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_01_off0002eecd.bin rtf-objdata-decoded RTF \objdata at offset 0x2EECD 78894 bytes
SHA-256: f320e15bf14caa41b6751c16d3ef9413048e3ed249be94376b72997020061214
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_02_off0005b109.bin rtf-objdata-decoded RTF \objdata at offset 0x5B109 78894 bytes
SHA-256: d10af821f62708aa58645f9b49d34820716c9d734ea965847ec2ba3de54a026d
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_03_off00087345.bin rtf-objdata-decoded RTF \objdata at offset 0x87345 78894 bytes
SHA-256: 26d715059fc7159bdef29ab0cbca8d9ddf31898324dd732890626eb6910d8d56
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_04_off000b3581.bin rtf-objdata-decoded RTF \objdata at offset 0xB3581 78894 bytes
SHA-256: 01b76a842732129fd0eccd4a62f529ef282804d7dc170f2211fb38efcab1af28
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.