Malicious RTF — malware analysis report

Static analysis result for SHA-256 8f54055e0712bc2c…

MALICIOUS

RTF

106.8 KB Created: 2006-09-19 13:31:00 Authoring application: Microsoft Word 11.0.8026 First seen: 2015-09-26
MD5: 70a365fa1baf892fbf707149efcffee0 SHA-1: fdb712bc4ac03a5a60e66328fe0d743b426844be SHA-256: 8f54055e0712bc2c985c8e59e81cd8d00f606f44d8a54a86837dc8f12536eabd
162 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The sample is an RTF file that exploits the CVE-2010-3333 vulnerability, a known stack overflow in Microsoft Word. It also attempts to inject a remote template from \\lcashare1\eulamaster\EULA.dot. The embedded URL http://usetermassembly/dealbuilder_live/DealBuilderNET/dealbuilder.aspx is likely used to download a secondary payload. The Korean text appears to be a standard Microsoft EULA, likely used as a lure.

Heuristics 4

  • CVE-2010-3333 — pFragments RTF stack overflow critical CVE exact CVE_2010_3333
    RTF shape property pFragments has an oversized value, matching the CVE-2010-3333 stack-overflow trigger in Microsoft Word 2002/2003.
  • Remote template injection (\*\template → remote URL) high CVE related RTF_REMOTE_TEMPLATE
    The RTF's \*\template destination is a remote URL/UNC path. When Word opens the document it fetches and loads that template, which can carry macros or an exploit, deliver a scriptlet/HTA, or leak NTLM credentials over UNC. Benign documents attach only a local template, so a remote \*\template target is template-injection delivery (MITRE T1221). remote \*\template target (Word fetches it on open).
  • ClamAV: BC.Legacy.Exploit.CVE_2010_3333-5 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: BC.Legacy.Exploit.CVE_2010_3333-5
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://usetermassembly/dealbuilder_live/DealBuilderNET/dealbuilder.aspx In RTF body