Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 cea0ca0197aa8c5b…

MALICIOUS

RTF / .DOC

1.28 MB Created: 2019-09-17 13:59:00
MD5: e707dfcdb5edd1f139f8730499ff9bf6 SHA-1: 7996bd161b50e78e2679931185e8b901b865aa08 SHA-256: cea0ca0197aa8c5bc921a8ae07b362ac4f532893344bf417082ac65bc448837e
140 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204 User Execution

The file is an RTF document containing embedded OLE objects, with critical heuristics indicating the exploitation of CVE-2017-8759. This vulnerability allows for OLE activation via ".objupdate", suggesting the document is designed to trigger malicious code execution upon opening. The embedded URL, while benign, is present within the document structure, further supporting the attack pattern.

Heuristics 5

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0014005b.bin
602d8ec25df9b644644c2e0127e2a85785a3215a7216cb52b6436b69fee05643
rtf-objdata-decoded RTF \objdata at offset 0x14005B 1485 bytes