Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 694d433a729b6599…

MALICIOUS

RTF / .DOC

35.1 KB Created: 2017-04-20 02:36:00
MD5: 03674b4f49ea0fef46fd83d5cdb27443 SHA-1: 6c01fe16e8cffa3049e84707672b82dc32f1cf72 SHA-256: 694d433a729b65993dae758e862077c2d82c92018e8e310e121e1fa051567dba
62 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF document contains a critical heuristic indicating remote template injection, pointing to a suspicious URL. This suggests the document is designed to exploit this vulnerability to download and execute a secondary payload from the identified remote template. The primary attack vector is likely spearphishing, with the document acting as an attachment.

Heuristics 2

  • Remote template injection (\*\template → remote URL) critical CVE related RTF_REMOTE_TEMPLATE
    The RTF's \*\template destination is a remote URL/UNC path. When Word opens the document it fetches and loads that template, which can carry macros or an exploit, deliver a scriptlet/HTA, or leak NTLM credentials over UNC. Benign documents attach only a local template, so a remote \*\template target is template-injection delivery (MITRE T1221). remote \*\template target (Word fetches it on open); destination obfuscated with \uN/\'xx escapes; dynamic-DNS / abuse-prone host.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://idmquick.xyz/jack/IvGRnMiDzgderQQteqNjNgKoIYqaLW6C.dot
    • http://schemas.microsoft.com/office/word/2003/wordml