Malicious RTF — malware analysis report

Static analysis result for SHA-256 3541f3d15698711d…

MALICIOUS

RTF

403.4 KB Created: 2022-07-13 15:38:00 First seen: 2022-07-14
MD5: 9d56c86249323a0080755473a9e34e58 SHA-1: 0963ad604c315f649c2b03312029a90a13845267 SHA-256: 3541f3d15698711d022541fb222a157196b5c21be4f01c5645c6a161813e85eb
184 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.001 Malicious Link: Malicious Link T1566 Phishing T1566.001 Phishing: Spearphishing Attachment T1059 Command and Scripting Interpreter

The RTF file contains multiple OLE objects and triggers the ".objupdate" field, indicating an attempt to activate embedded objects. The critical heuristic firing for CVE-2017-8759 confirms exploitation of this vulnerability through MSXML SAX OLE activation. This suggests the file is designed to exploit this known vulnerability to achieve code execution.

Heuristics 7

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • Heap-spray pattern detected high SC_HEAP_SPRAY
    Repeated 0x41 (A) bytes found
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 3 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00007e73.bin
3d5232092292c498dcdc1a72e2cf95642b68beb95401192480a1de22544a2459
rtf-objdata-decoded RTF \objdata at offset 0x7E73 178614 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
objdata_01_off000601ea.bin
88fc218bafb1b2271fb9334d7a871f1cc3e74b7212b06f332c59ef9ad647a523
rtf-objdata-decoded RTF \objdata at offset 0x601EA 8896 bytes
objdata_02_off00060204.bin
2b49549e5ec9284652981beca078a75534d2ba3a47691962ddceb36a86f5e4f7
rtf-objdata-decoded RTF \objdata at offset 0x60204 8892 bytes