Malicious RTF — malware analysis report

Static analysis result for SHA-256 fc61d8560de8bea8…

MALICIOUS

RTF

711.2 KB Created: 2018-04-22 04:50:00 First seen: 2018-06-14
MD5: 04d38647d9744274a6d764c5f135e68c SHA-1: f02d813bec757536bf035bd548ca5fcc86c4d4f3 SHA-256: fc61d8560de8bea8b131776193503274dbfbaa12a8b81df1fe1863278dd4a40d
142 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF document contains multiple embedded OLE objects, with one specifically triggering the ".objupdate" directive. This directive is associated with the exploitation of CVE-2017-8759, which allows for client-side code execution. The presence of OLE objects and the specific CVE exploit indicate a malicious document designed to compromise the user's system upon opening.

Heuristics 5

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c45.bin rtf-objdata-decoded RTF \objdata at offset 0x2C45 21051 bytes
SHA-256: c31e466ee69bf12bd7fbbb6c17940ce821a9d5c2f4f01759e6668c8258ea9445
objdata_01_off00012bb0.bin rtf-objdata-decoded RTF \objdata at offset 0x12BB0 21051 bytes
SHA-256: dc2e385e82f4f0dbb3776424065189bcd2accbe6fa4884686d66ce252d8b1959
objdata_02_off00022b1b.bin rtf-objdata-decoded RTF \objdata at offset 0x22B1B 21051 bytes
SHA-256: 275eb29d9c8a558da8f0b636ac5b6fe8e0ebd09fd649f3d136f76a093520e034
objdata_03_off00032a86.bin rtf-objdata-decoded RTF \objdata at offset 0x32A86 21051 bytes
SHA-256: 216e647679ccd6fd61db7db5014e3f78ec0d1dd1a4051cfddc82857962eff3aa
objdata_04_off000429f1.bin rtf-objdata-decoded RTF \objdata at offset 0x429F1 21051 bytes
SHA-256: 9e3529e4aa2d0a34a037cbc41942f65b288eeea545c893272693905c26ec57a5
objdata_05_off00052963.bin rtf-objdata-decoded RTF \objdata at offset 0x52963 21051 bytes
SHA-256: e03f6110908134804df7da23cfdd4214a6ab9a684e7f96091d607bbf33bf7cbb
objdata_06_off000628ce.bin rtf-objdata-decoded RTF \objdata at offset 0x628CE 21051 bytes
SHA-256: 8e01afbf19f4599c21f63676d219ee4246630342a3da2634a8abac238722e215
objdata_07_off00072839.bin rtf-objdata-decoded RTF \objdata at offset 0x72839 21051 bytes
SHA-256: dee6bf0d1e68caec5ed4101836e9a1b4e22f3da3648778934bb5893a36d10b5b
objdata_08_off000827a4.bin rtf-objdata-decoded RTF \objdata at offset 0x827A4 21051 bytes
SHA-256: 06fb86ae6c4991e05c7d776aa8f37aecf48856ae35aea23462066a91eba96172
objdata_09_off0009270f.bin rtf-objdata-decoded RTF \objdata at offset 0x9270F 21051 bytes
SHA-256: 5fa78880ca1f0c4047cbeb9759e5e02cb1035ca0d32fbe5ec67e2c1ba3c2b1b0