Malicious Office (OOXML) / .DOCX — malware analysis report

Static analysis result for SHA-256 95e45d55e2fc6dd4…

MALICIOUS

Office (OOXML) / .DOCX

420.4 KB
MD5: 4d87b432d9c56c5677102264c6aee91f SHA-1: 586c960c19829c54a92276655cf9048a31e596f3 SHA-256: 95e45d55e2fc6dd48acddaeed3da271d42f1422fa49f13feeb42016a1a69816e
400 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model T1059.001 PowerShell

The OOXML document utilizes an altChunk to import an external RTF file named 'word/Bolivia.rtf'. This RTF file contains OLE objects that are triggered via \objupdate, indicating an attempt to execute embedded content. Heuristics like RTF_MZ_HEX and OOXML_ALTCHUNK_RTF_AUTOUPDATE_PE strongly suggest that this imported RTF contains and executes a Portable Executable (PE) file, likely a dropper or initial payload.

Heuristics 10

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    (in altChunk RTF word/Bolivia.rtf) RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • altChunk imports embedded RTF (RTF injection) critical OOXML_ALTCHUNK_RTF
    Document inlines an embedded RTF via an aFChunk relationship and a <w:altChunk> body element. This is the canonical RTF-injection wrapper used to smuggle RTF exploits (Equation Editor / URL Moniker / objdata) past DOCX-only scanners. Word opens the wrapper and executes the RTF inline. Recursing into the RTF for the exact exploit primitive.
  • PE header (with DOS stub) in hex data critical RTF_MZ_HEX
    (in altChunk RTF word/Bolivia.rtf) Hex-encoded PE (MZ + DOS stub) found inside RTF — likely an embedded executable payload
  • altChunk RTF auto-updates embedded executable object critical OOXML_ALTCHUNK_RTF_AUTOUPDATE_PE
    OOXML document imports an embedded RTF through altChunk; the RTF contains OLE object data, forces object update, and carries a hex-encoded PE payload. This is a stronger compound exploit-loader shape than a generic altChunk RTF wrapper, but it is not tied to a single CVE unless the nested RTF object primitive also matches one.
  • ClamAV: Rtf.Dropper.Agent-9965975-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Dropper.Agent-9965975-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    (in altChunk RTF word/Bolivia.rtf) RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • Large hex data blocks in OLE object high RTF_EXCESSIVE_HEX
    (in altChunk RTF word/Bolivia.rtf) RTF contains ~1905KB of hex-encoded data inside \objdata sections — may hide a payload
  • OLE object data medium RTF_OBJDATA
    (in altChunk RTF word/Bolivia.rtf) RTF contains 3 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    (in altChunk RTF word/Bolivia.rtf) RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://opendope.org/xpaths
    • http://opendope.org/conditions
    • http://opendope.org/questions
    • http://opendope.org/components
    • http://opendope.org/SmartArt/DataHierarchy
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/main
    • http://schemas.openxmlformats.org/schemaLibrary/2006/main
    • http://schemas.openxmlformats.org/drawingml/2006/chart
    • http://schemas.openxmlformats.org/drawingml/2006/chartDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/diagram
    • http://schemas.openxmlformats.org/drawingml/2006/picture
    • http://schemas.openxmlformats.org/drawingml/2006/spreadsheetDrawing
    • http://schemas.microsoft.com/office/drawing/2008/diagram
    • http://schemas.openxmlformats.org/officeDocument/2006/bibliography
    • http://schemas.openxmlformats.org/drawingml/2006/compatibility
    • http://schemas.openxmlformats.org/drawingml/2006/lockedCanvas

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003a12.bin
28d4d6f5ed1af74ac140d6d6ed0c34bba6a3fd60f608cee2cd2e0f648cc86802
rtf-objdata-decoded RTF \objdata at offset 0x3A12 483038 bytes
objdata_01_off000ff6e1.bin
ad71272bd05a0a950acf498ce32b18ff1fb9c68e4ee14344ee9fe06f3c9dcac2
rtf-objdata-decoded RTF \objdata at offset 0xFF6E1 500818 bytes
objdata_02_off001ff7b7.bin
359f1c8a7119d8f52bd4128ee1ec29c1776e538742ee42f6bc006ca277125b09
rtf-objdata-decoded RTF \objdata at offset 0x1FF7B7 534490 bytes