Malicious RTF — malware analysis report

Static analysis result for SHA-256 1717f1f6d7333f05…

MALICIOUS

RTF

918.5 KB Created: 2018-05-07 First seen: 2018-06-30
MD5: d63879f56510e852a58710c22ac8033d SHA-1: d219abab7acdd71960053a929c211dcd2173af5b SHA-256: 1717f1f6d7333f05371a45e1613fd60fcf6b38deae50e9cbebeef70c19ad520a
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c12.bin rtf-objdata-decoded RTF \objdata at offset 0x2C12 33339 bytes
SHA-256: fe19da04fbeede05d97ac9bfb0154432e1a429c5649c286691427fe8696b424b
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018b2e.bin rtf-objdata-decoded RTF \objdata at offset 0x18B2E 33339 bytes
SHA-256: e2bcd91bc23d30ed36719921516a88750b6ae57b723f05467084289bb069a35a
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002ea4a.bin rtf-objdata-decoded RTF \objdata at offset 0x2EA4A 33339 bytes
SHA-256: 912586b3984e89a03f11b609a3e9deb5d5c647ac75d6d0820c9f7e6f6b503d84
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00044966.bin rtf-objdata-decoded RTF \objdata at offset 0x44966 33339 bytes
SHA-256: 1c489d3a57342f042ae5e0da822c36dc012461520461cb0251a530ef1ac77d7e
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a882.bin rtf-objdata-decoded RTF \objdata at offset 0x5A882 33339 bytes
SHA-256: 646374852f711f8829b3fb3ebfaa46be2b2c34470292775b682ef3e7b1f19e4a
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000707ea.bin rtf-objdata-decoded RTF \objdata at offset 0x707EA 33339 bytes
SHA-256: 20c8dd4ec3ba1a0166fc6a288f1320fb89de749b4d30ca198d33ea1722de5d01
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off00086706.bin rtf-objdata-decoded RTF \objdata at offset 0x86706 33339 bytes
SHA-256: 333a5d6bd7af6975029ddb2c29576ede3b67fa2ad460e9b61dc7fed0158aa260
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0009c622.bin rtf-objdata-decoded RTF \objdata at offset 0x9C622 33339 bytes
SHA-256: 7b9cfe13bb93a8e660626cf2488127943b381324598f9c83eb2a5c7b02ea3992
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b253e.bin rtf-objdata-decoded RTF \objdata at offset 0xB253E 33339 bytes
SHA-256: 626747b11a691d756de9f979d3f6517c1b9cc264d37e01901a0631b088d2bb1f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c845a.bin rtf-objdata-decoded RTF \objdata at offset 0xC845A 33339 bytes
SHA-256: 333cb0c185b5fbd1e59d4554a12732b62bd44443890604310988e5f5f911b389
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely