Malicious RTF — malware analysis report

Static analysis result for SHA-256 09253109b7b16bf5…

MALICIOUS

RTF

918.5 KB Created: 2018-05-10 16:10:00 First seen: 2019-04-18
MD5: 1d710dcce0ceee7916eee856096b3439 SHA-1: f13a1d9c7014c3dbe6c78f1e17208e9bbc6609ff SHA-256: 09253109b7b16bf5019ce9fe7dc4dd0b0fdac6c51be499f719df56644412af5f
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c1c.bin rtf-objdata-decoded RTF \objdata at offset 0x2C1C 33339 bytes
SHA-256: 2a32d7c7ed8e4479e1466b1251d09a144c739fc28fd2a358090fd102dcb97d51
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018b38.bin rtf-objdata-decoded RTF \objdata at offset 0x18B38 33339 bytes
SHA-256: 2809937414e38dfe0010a5a9c4eebc9cdb9ecbbdbe58383e64467563d87c5c30
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002ea54.bin rtf-objdata-decoded RTF \objdata at offset 0x2EA54 33339 bytes
SHA-256: b116d3665e4774fb2b56a4025576dc54f7d4e71379ec00f72564de4db5b16347
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00044970.bin rtf-objdata-decoded RTF \objdata at offset 0x44970 33339 bytes
SHA-256: 8022f52e9b55aadce181485037bc2c44c10fa9a27779642795ab7a10f80d67a7
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a88c.bin rtf-objdata-decoded RTF \objdata at offset 0x5A88C 33339 bytes
SHA-256: 213a39f3efd30a7016d3b74bd536a3658b4d47d6c1d2dd0eb6674eec54fa914f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000707f4.bin rtf-objdata-decoded RTF \objdata at offset 0x707F4 33339 bytes
SHA-256: 230c5b43d5f1b89385ecd6187f2703d7f836ec91c0bdf13d34cc98cb236e4792
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off00086710.bin rtf-objdata-decoded RTF \objdata at offset 0x86710 33339 bytes
SHA-256: 3327fe5bd66386716b286a5683169a3e6f0639b105f9604c4fccec70f1d22544
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0009c62c.bin rtf-objdata-decoded RTF \objdata at offset 0x9C62C 33339 bytes
SHA-256: 17f09770afb0f1dbd52bb83f3d52e9757480ff6c2c9ecf5532deebc9f42f212d
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b2548.bin rtf-objdata-decoded RTF \objdata at offset 0xB2548 33339 bytes
SHA-256: f4a1ca2d42f28f1b61f4205691976966ff63a097fde63e9cd75b0f88e77bb896
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c8464.bin rtf-objdata-decoded RTF \objdata at offset 0xC8464 33339 bytes
SHA-256: 975445bd952562a8db4fa6b777c05967dab6c805bbb2cb5f10e6a59783df197a
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely