Malicious RTF — malware analysis report

Static analysis result for SHA-256 0900b24117e6aeb7…

MALICIOUS

RTF

961.0 KB Created: 2018-03-31 16:14:00 First seen: 2018-04-12
MD5: f13d436f3f2d35fd4db0f75cd76bf34a SHA-1: 9bab491ff793e541421e38f2b10b81e21e876c42 SHA-256: 0900b24117e6aeb76f1193772d130be8ba6090b1a6a5f429fbd1a4ff149c9d3d
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 12 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 12

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002ab4.bin rtf-objdata-decoded RTF \objdata at offset 0x2AB4 27707 bytes
SHA-256: a1d82426a581098fd0e863cf392a172a8e7fbdd68bb23cdd03d0b7f074eb1918
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00015d74.bin rtf-objdata-decoded RTF \objdata at offset 0x15D74 27707 bytes
SHA-256: f28c53554c1e0a1c80392d3d6503db84591e7da005bef4c2d8e842ebc733ff45
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00028ffa.bin rtf-objdata-decoded RTF \objdata at offset 0x28FFA 27707 bytes
SHA-256: a800a7c5d5187e42392b570913d725a7b1d2a323e5334028cf811788e8d856e5
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003c2ba.bin rtf-objdata-decoded RTF \objdata at offset 0x3C2BA 27707 bytes
SHA-256: 0182920db84c7459e8197f29888e59f28af95833f5018a4a56b1e2dd342fd319
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off0004f5c4.bin rtf-objdata-decoded RTF \objdata at offset 0x4F5C4 27707 bytes
SHA-256: 4a33cb80d9704923b58d977c46a895b983f988ab9e5c8fafc991136af8625a16
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off00062884.bin rtf-objdata-decoded RTF \objdata at offset 0x62884 27707 bytes
SHA-256: 7dd9e6fc26e1394bb2af19ccbbfd3e75c990810d7c1fd2376229f6e0924f298a
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off00075c12.bin rtf-objdata-decoded RTF \objdata at offset 0x75C12 27707 bytes
SHA-256: c61ea50e104123ca2b91af0c0ff603608cf80d74dcb393cb0a4e59e51004ed8f
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off00088ed2.bin rtf-objdata-decoded RTF \objdata at offset 0x88ED2 27707 bytes
SHA-256: 6fab8ae33c3afbfefb5366313427d978cc23e51213472da0b54959df9216efc3
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off0009c1dc.bin rtf-objdata-decoded RTF \objdata at offset 0x9C1DC 27707 bytes
SHA-256: 06a202a4fc0bb2ed0200fe6034d06159cb655cc3a98ab3d1eb74a7d59b4c5ad4
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000af49c.bin rtf-objdata-decoded RTF \objdata at offset 0xAF49C 27707 bytes
SHA-256: 3297c5dcf2516973fecc32f5f93a1934a6686ad20612adcc129ed564a3c1eb2b
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_10_off000c27a6.bin rtf-objdata-decoded RTF \objdata at offset 0xC27A6 27707 bytes
SHA-256: 8f4ebeecdfa2160f6283c19b2d16e7718653b735217e0a032e69fc445e170742
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_11_off000d5a66.bin rtf-objdata-decoded RTF \objdata at offset 0xD5A66 27707 bytes
SHA-256: 71cce7d88d628393516a9ab0dbbdf346f6501a9371ccbf8883e725cef839c7a7
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely