Malicious RTF — malware analysis report

Static analysis result for SHA-256 104b0920ce99f790…

MALICIOUS

RTF

842.2 KB Created: 2018-03-12 02:39:00 First seen: 2018-06-14
MD5: 6da913bb8b1530aa3787811dcc41974f SHA-1: d1d394b668608e34cfe1d26ef8c7d43872c35389 SHA-256: 104b0920ce99f7907429e0e6792e8cb9524472dcfc00c8b652f4c1c923ff19f3
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Xls.Downloader.Generic-6750544-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Generic-6750544-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003655.bin rtf-objdata-decoded RTF \objdata at offset 0x3655 27707 bytes
SHA-256: 63e1647bfdf82a9acb073175e03d88709e23bdf42ea5e4b5e40d24e015fdd143
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_01_off00017569.bin rtf-objdata-decoded RTF \objdata at offset 0x17569 27707 bytes
SHA-256: ee69db949d1554c7a112a6e7c3e37076cec49beac875385c7f01e413a1b5b1de
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_02_off0002b47d.bin rtf-objdata-decoded RTF \objdata at offset 0x2B47D 27707 bytes
SHA-256: 8bda6e853ff0deaa6393b515bb39a5efc3cbdf8af0185bbb4d3e54bfcfce0637
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_03_off0003f391.bin rtf-objdata-decoded RTF \objdata at offset 0x3F391 27707 bytes
SHA-256: 905f1ece906ac6228ca813475df496764f1c721cdb1f1c8bd07e3510ba808047
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_04_off000532a5.bin rtf-objdata-decoded RTF \objdata at offset 0x532A5 27707 bytes
SHA-256: 0dec03180a830ac22f09c800a787f6821f4bb524de18c1ae02a62fda475b118c
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_05_off00067203.bin rtf-objdata-decoded RTF \objdata at offset 0x67203 27707 bytes
SHA-256: da2267d7faa7a600035530a3ad6d185cdfa6e52cd7676955863b6af3450a4988
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_06_off0007b117.bin rtf-objdata-decoded RTF \objdata at offset 0x7B117 27707 bytes
SHA-256: 13dd5ad86bf1ec956dc27e02bfd05e6319b19e5ba2b9195e552ff52eb0b8236a
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_07_off0008f02b.bin rtf-objdata-decoded RTF \objdata at offset 0x8F02B 27707 bytes
SHA-256: 3d4fbd09888b773bcadc5e78d0a5f10ad52a844b56faf78b824762867a83a7f1
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_08_off000a2f3f.bin rtf-objdata-decoded RTF \objdata at offset 0xA2F3F 27707 bytes
SHA-256: 84c3036972f50846261198b28ba9497a77f3e2358654710e092d60d9e34c8e1c
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_09_off000b6e53.bin rtf-objdata-decoded RTF \objdata at offset 0xB6E53 27707 bytes
SHA-256: 8e54149d551a99ce62282795649debeab82c9e75bcefa76b8bbd3514e2593ba5
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely