Malicious RTF — malware analysis report

Static analysis result for SHA-256 bbe8d4f57f896b96…

MALICIOUS

RTF

856.6 KB Created: 2017-08-08 15:25:00 First seen: 2017-08-27
MD5: 41629255faedccbcb3bc9137cf51de00 SHA-1: d9b448364c0fe4a4a88fe432e694d5e56746ccf7 SHA-256: bbe8d4f57f896b96cb2f1c147afdf4bd50277d436bb68c03216547bdc9d88b7a
182 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers the \objupdate directive, indicating an attempt to activate them. The critical heuristic firing for CVE-2017-8759 confirms exploitation of this vulnerability for OLE activation. The embedded URL points to a suspicious executable, suggesting the exploit is used to download and run a second-stage payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://jasadoa.co.id/2222222222222money.exe In RTF body
    • http://schemas.microsoft.com/office/word/2003/wordmlIn RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000028c3.bin rtf-objdata-decoded RTF \objdata at offset 0x28C3 30254 bytes
SHA-256: 2c25856bb353fae9eb7ff78083548a58f0a84d810536fa211ee75d56be20c546
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_01_off00016cef.bin rtf-objdata-decoded RTF \objdata at offset 0x16CEF 30254 bytes
SHA-256: ba023265ea848b2cc30cf143b5472706f25dae61ae029a0e9640466645bd65e1
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_02_off0002b11b.bin rtf-objdata-decoded RTF \objdata at offset 0x2B11B 30254 bytes
SHA-256: 25021e3dde65ed4d7ffb66b9a541ba55af32d95bda95766bb96ee2e15970aebd
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_03_off0003f547.bin rtf-objdata-decoded RTF \objdata at offset 0x3F547 30254 bytes
SHA-256: 7c9ed3c3929698e6663440bc0f55fa529185604ab45617b06147c6058f620c47
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_04_off00053973.bin rtf-objdata-decoded RTF \objdata at offset 0x53973 38446 bytes
SHA-256: 3f273295700672293212fae5bd5fea82e4bda0f677f705d03aca495e26b0df89
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_05_off0006be21.bin rtf-objdata-decoded RTF \objdata at offset 0x6BE21 30254 bytes
SHA-256: ff4681a86df7dc854bb526cfee1687fc0d6840fd3ea731bdb7b0af6cbc9ed25a
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_06_off0008024d.bin rtf-objdata-decoded RTF \objdata at offset 0x8024D 30254 bytes
SHA-256: 8fa7f90eb603a41236746eaed6684b4e8f391ccb887d7e618198b11f2d7772e4
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_07_off00094679.bin rtf-objdata-decoded RTF \objdata at offset 0x94679 30254 bytes
SHA-256: df3003cf9a79ca291f11720f0ad79e0a537042e0b2011c13bc01a23866596eb4
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_08_off000a8aa5.bin rtf-objdata-decoded RTF \objdata at offset 0xA8AA5 30254 bytes
SHA-256: fe0c1964eb7e6765d6c102bedf2f50202d6dd92bdbc1242c05738bc18b402946
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_09_off000bced1.bin rtf-objdata-decoded RTF \objdata at offset 0xBCED1 30254 bytes
SHA-256: 5e8e5333c2999a7832431d4ad1c667adbbe5de3c92c3cf09cf3057634c700035
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.