Malicious RTF — malware analysis report

Static analysis result for SHA-256 d0cfcebe3f36f754…

MALICIOUS

RTF

868.8 KB Created: 2018-08-17 15:31:00 First seen: 2021-10-23
MD5: 8e44bd514e698b973d5215ed743150d6 SHA-1: 77bc60c45924ed61c6afaeb58791fb12c23a513e SHA-256: d0cfcebe3f36f7546114f16d4a1e86be1bcb0bb2b69e21f7d3769f9db01fffdb
122 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple OLE objects with embedded data, and the ".objupdate" directive indicates an attempt to trigger OLE activation. This strongly suggests the file is designed to exploit vulnerabilities related to OLE object handling for client-side execution. The presence of a benign URL does not detract from the malicious indicators.

Heuristics 5

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000039fd.bin rtf-objdata-decoded RTF \objdata at offset 0x39FD 31291 bytes
SHA-256: d946bb71554764e3437685e692010106316c148ceecea3623ec9a7df0289ab9b
objdata_01_off00018691.bin rtf-objdata-decoded RTF \objdata at offset 0x18691 31291 bytes
SHA-256: c0c5d262760df20b42a20665d6591057d4ed91908b3ed9bd230a68e0e27baae3
objdata_02_off0002d327.bin rtf-objdata-decoded RTF \objdata at offset 0x2D327 31291 bytes
SHA-256: a90d4f1f80280deb05c59e9486378e57f3465ec500591d2636d9c6a67e964610
objdata_03_off00041fbd.bin rtf-objdata-decoded RTF \objdata at offset 0x41FBD 31291 bytes
SHA-256: cc96c261a1d2f62e57f622b2f233eded4fe31d5686894522d88c91417b169cea
objdata_04_off00056c53.bin rtf-objdata-decoded RTF \objdata at offset 0x56C53 31291 bytes
SHA-256: 142ca709aadd17857a1d4f28261a4232b0697149506be488cced14565cebaa4b
objdata_05_off0006bbcb.bin rtf-objdata-decoded RTF \objdata at offset 0x6BBCB 31291 bytes
SHA-256: b39a6cfce18247d031c7cbd115e3cc6255c8faa34e3aeb128242a7f552b13490
objdata_06_off0008085b.bin rtf-objdata-decoded RTF \objdata at offset 0x8085B 31291 bytes
SHA-256: 3bb8c3f922f37fa1e74bb63c1200e136ffef9acacea10112fb7f3972a3679de8
objdata_07_off000954ed.bin rtf-objdata-decoded RTF \objdata at offset 0x954ED 31291 bytes
SHA-256: 7e7ee0ce2b7cc1e3c0e6bde151880a79563cb07da3a5067e1864f016e450903c
objdata_08_off000aa17f.bin rtf-objdata-decoded RTF \objdata at offset 0xAA17F 31291 bytes
SHA-256: b77d455b5918d0f77b2b3511bbe5fac7e50305ed02da8df118e2a6cbdf847731
objdata_09_off000bee11.bin rtf-objdata-decoded RTF \objdata at offset 0xBEE11 31291 bytes
SHA-256: 9b0db8ec1535589be7cbab7b6a6aaa6ec1f837eca106f4ae1e7e7e87cdc3c02a