Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 4afbe2858548d422…

MALICIOUS

RTF / .DOC

3.20 MB Created: 2019-09-17 13:59:00
MD5: dfca37c53c61f8e12c200b57e85bae8c SHA-1: 315ff0edd7a887d78d67fa0f53436f75c723795a SHA-256: 4afbe2858548d42214584fe37c4064353a6e845a2552462d23bf017abcb10d4e
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.001 PowerShell

The sample is an RTF document that contains embedded OLE objects, with a critical heuristic indicating exploitation of CVE-2017-8759. This vulnerability allows for OLE activation, which is likely used to execute arbitrary code. The presence of ".objdata" and ".objemb" sections further supports the embedding of malicious content. No document body text was available for analysis, but the heuristics strongly suggest a malicious exploit delivery mechanism.

Heuristics 5

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0031bd9b.bin
b97b0d461277b07cf383bc22d7125a2e315512c21290d6010cc4b15d181f814c
rtf-objdata-decoded RTF \objdata at offset 0x31BD9B 1478 bytes