Malicious RTF — malware analysis report

Static analysis result for SHA-256 2e270e03789b09e1…

MALICIOUS

RTF

179.8 KB Created: 2019-09-08 16:28:00 First seen: 2020-02-04
MD5: cf1e71ba7104001fb7f249cedf0a2675 SHA-1: a74d0e0da6d17474d1981038bfda2bd897d4b12d SHA-256: 2e270e03789b09e134f0ef8b7e42bb874191dd0954efc710eb40c293ed686267
142 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains embedded OLE objects and triggers their activation using \objupdate, which is indicative of exploiting vulnerabilities like CVE-2017-8759. This exploit likely leads to the execution of a secondary payload. The presence of an embedded URL, even if benign, suggests an attempt to contact external resources. The document body content is heavily obfuscated and does not provide clear instructions.

Heuristics 5

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0001cd7d.bin rtf-objdata-decoded RTF \objdata at offset 0x1CD7D 25542 bytes
SHA-256: c1a6d4e0e676518ea6c911763e5b18875b548b1245f937ca8d9cad42db103b8b