CISA received one artifact, ff4138ca9119ab0381ad6575f041e633, which appeared to be a crafted RTF document to perform penetration testing for the CVE-2012-0158 vulnerability found in Microsoft Office 2003, 2007 and 2010. It is actually an obfuscated RTF that when opened in Microsoft Word, it connected to and attempted to download an executable named Specification.exe, copied it over to word.scr and executed it immediately. At the time of this analysis, the domain returned HTTP 404 not found to the HTTP GET request.

For a downloadable copy of IOCs, see MIFR-10079683-1.v2.stix.

ebbca8bb8e... Connected_To

FF4138CA9119AB0381AD6575F041E633 is an obfuscated RTF document, appeared to be crafted to perform penetration testing when examined under a hexadecimal editor. Close to the end of file, ASCII data "For pentesting purposes only!" and the MD5 hash value of the RTF were found.

However, when the RTF was opened in Microsoft Word, it sent a HTTP GET request to the domain in order to download a binary named Specification.exe. If successfully downloaded it would copy Specification.exe to word.scr and immediately execute it.

When the RTF was examined under a debugger, the location of word.scr was in the C:\Windows\system32 directory; word.scr ran on the system followed by a system crash and reboot. However, when the RTF was opened without a debugger, word.scr was copied to the same directory where RTF was located at and the system did not crash.

At the time of this analysis, returned HTTP 404 Not Found to the HTTP GET request for the Specification.exe binary.

