Malicious RTF — malware analysis report

Static analysis result for SHA-256 dfad11b652c183e0…

MALICIOUS

RTF

319.8 KB Created: 2019-01-07 23:54:00 First seen: 2019-12-10
MD5: b42c8250204ec28d57f369beb0389347 SHA-1: 6ea3447e3f986d23d2b1e3b3152fcd854a667f40 SHA-256: dfad11b652c183e0a911913bb05e2c72e27a302a18f0c93c3f1dd2d443fbce4f
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains multiple OLE object embeddings, with specific rules indicating the presence of package objects and an \objupdate command designed to force OLE activation. This suggests the file is designed to exploit vulnerabilities within OLE object handling to execute arbitrary code. The embedded object file 'objdata_00_off00000b2c.bin' is the primary artifact of interest.

Heuristics 5

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • Package object class high RTF_OBJCLASS_PACKAGE
    OLE Package object — can wrap arbitrary files
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002438.bin rtf-objdata-decoded RTF \objdata at offset 0x2438 136750 bytes
SHA-256: 23a10b3a8ae5667a3142fff357ebcb9d165e43601d223037eb26931c48d835f0
objdata_01_off00045d76.bin rtf-objdata-decoded RTF \objdata at offset 0x45D76 6502 bytes
SHA-256: 4d78aaeea748a71dcb0130caf1f2c86d1f67ede8256319ad5cd481b642f10cad