Malicious RTF — malware analysis report

Static analysis result for SHA-256 217320588447372c…

MALICIOUS

RTF

1.17 MB Created: 2019-09-17 13:59:00
MD5: a15628c6d9cb3a95c8e0377506da2b5b SHA-1: 80a690b36500eb86005958728a2c6ac3520a8c1c SHA-256: 217320588447372c5c1ebf772714afd60a382dae20ea675458144bbe95fb8556
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.001 PowerShell

The RTF document contains an embedded OLE object that is triggered by \objupdate, indicating an attempt to activate it. The critical heuristic firing for CVE-2017-8759 confirms exploitation of a known vulnerability in MSXML SAX OLE activation. This suggests the document is designed to exploit this vulnerability to execute arbitrary code, likely downloading a second-stage payload.

Heuristics 5

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00116280.bin
be94547f4819e7fc896cfb409645673f35b426de5e76d3aa4bbd2d36624acd11
rtf-objdata-decoded RTF \objdata at offset 0x116280 1478 bytes