Malicious RTF — malware analysis report

Static analysis result for SHA-256 774a54300223b421…

MALICIOUS

RTF

2.62 MB Created: 2007-05-25 11:15:00
MD5: 027f5ae272bbb6bbc3e1fdf230a4e3f6 SHA-1: 57142832e5453cb0e2c3e6c1a3d7536131b3ed72 SHA-256: 774a54300223b421854d2e90bcf75ae25df75ba9f3da1b9eb01138301cdd258f
184 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects, with one specifically triggering the ".objupdate" directive, indicating an attempt to activate embedded content. The critical heuristic firing for CVE-2017-8759 confirms this vulnerability is being exploited. The presence of large hex-encoded data within OLE objects suggests a hidden payload, likely delivered through this exploit.

Heuristics 7

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • Large hex data blocks in OLE object high RTF_EXCESSIVE_HEX
    RTF contains ~1130KB of hex-encoded data inside \objdata sections — may hide a payload
  • OLE object data medium RTF_OBJDATA
    RTF contains 3 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0025be09.bin
adb4170defa619e508097b74351a09fee8c22c12a3de2ccf64d278576e3bcea6
rtf-objdata-decoded RTF \objdata at offset 0x25BE09 131746 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
objdata_01_off0029c373.bin
1982dfcf6da3c5839ca0d22f219638b65950e2c8586afc4461b39d0c76747140
rtf-objdata-decoded RTF \objdata at offset 0x29C373 6847 bytes
objdata_02_off0029c38d.bin
836c1996986d5c66632bdfecd2ddbeb89030a3566f3185f46fef4a1a02ee5307
rtf-objdata-decoded RTF \objdata at offset 0x29C38D 6843 bytes