Malicious RTF — malware analysis report

Static analysis result for SHA-256 1065bae8c1ad1f0f…

MALICIOUS

RTF

791.0 KB Created: 2018-04-18 02:59:00 First seen: 2018-05-18
MD5: bb5eb0318e3c64454305db40d90e1452 SHA-1: 5f00460fe3717c77d168b448e450e85e89211d95 SHA-256: 1065bae8c1ad1f0f9ccc5de4b2f89f7e81bf9d3ba23d1a5e3cbb8a52590a8360
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6934406-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6934406-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c46.bin rtf-objdata-decoded RTF \objdata at offset 0x2C46 26171 bytes
SHA-256: 892e59491a1530bb8da63c9885c31b74fc681e4ad82e2f943a6ae45d92ea317f
Detection
ClamAV: Doc.Dropper.Agent-6934406-0
Obfuscation or payload: unlikely
objdata_01_off00015863.bin rtf-objdata-decoded RTF \objdata at offset 0x15863 26171 bytes
SHA-256: 331ca20b58944e6f7d0f74934804c78e69e33c2875a50b77e2aa46fccdcb99fc
Detection
ClamAV: Doc.Dropper.Agent-6934406-0
Obfuscation or payload: unlikely
objdata_02_off00028480.bin rtf-objdata-decoded RTF \objdata at offset 0x28480 26171 bytes
SHA-256: f11c0b15b02f2c861684a27ae2bd104d4e609ad40dc59c16898eae261ff8c22e
Detection
ClamAV: Doc.Dropper.Agent-6934406-0
Obfuscation or payload: unlikely
objdata_03_off0003b09d.bin rtf-objdata-decoded RTF \objdata at offset 0x3B09D 26171 bytes
SHA-256: 78e8b11b1d616e80fed917dbf96983561785de2ad4ee2e2ad26ea7608bd183a8
Detection
ClamAV: Doc.Dropper.Agent-6934406-0
Obfuscation or payload: unlikely
objdata_04_off0004dcba.bin rtf-objdata-decoded RTF \objdata at offset 0x4DCBA 26171 bytes
SHA-256: be6b72b39e69ba76b18eb5ba20415ba2e3a884b336ae0c0f3f32138859b15106
Detection
ClamAV: Doc.Dropper.Agent-6934406-0
Obfuscation or payload: unlikely
objdata_05_off00060923.bin rtf-objdata-decoded RTF \objdata at offset 0x60923 26171 bytes
SHA-256: 9756d3180a948736d51927d0af187a4b7bacfc450e2a29c66b6033a9eb566fe6
Detection
ClamAV: Doc.Dropper.Agent-6934406-0
Obfuscation or payload: unlikely
objdata_06_off00073540.bin rtf-objdata-decoded RTF \objdata at offset 0x73540 26171 bytes
SHA-256: 9ba57b36c608660adbb54271896a7907a471201623e841f483966becdd0b2e4c
Detection
ClamAV: Doc.Dropper.Agent-6934406-0
Obfuscation or payload: unlikely
objdata_07_off0008615d.bin rtf-objdata-decoded RTF \objdata at offset 0x8615D 26171 bytes
SHA-256: 58dca0d86f6ef4c7c7eb84a73ab07ccfbb9fe061fb9fcc53308bb90702ee46e6
Detection
ClamAV: Doc.Dropper.Agent-6934406-0
Obfuscation or payload: unlikely
objdata_08_off00098d7a.bin rtf-objdata-decoded RTF \objdata at offset 0x98D7A 26171 bytes
SHA-256: bdaf68b67dbac2dba85db561638ac7c93b3b8d3d5e12d7ea0002e3ea6633773b
Detection
ClamAV: Doc.Dropper.Agent-6934406-0
Obfuscation or payload: unlikely
objdata_09_off000ab997.bin rtf-objdata-decoded RTF \objdata at offset 0xAB997 26171 bytes
SHA-256: 73a23779089196592e64a7b50d931aba2b539ea5c26b851362746e1cb2dc859b
Detection
ClamAV: Doc.Dropper.Agent-6934406-0
Obfuscation or payload: unlikely