Malicious RTF — malware analysis report

Static analysis result for SHA-256 22a4faf7f35524d3…

MALICIOUS

RTF

876.2 KB Created: 2018-05-02 20:33:00 First seen: 2019-01-20
MD5: 78d2ee802800afd044ab403f7e7f4c7e SHA-1: 3d3abc5ce57161466f545f6acc9c408b1ef48ee8 SHA-256: 22a4faf7f35524d3dd1c29af94494900e75c40745a205f3f8d0cedd8a618e44b
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 12 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 12

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c16.bin rtf-objdata-decoded RTF \objdata at offset 0x2C16 24123 bytes
SHA-256: e0179a6dc5d6413400b617d0e01274b8b13012f6bdbaab421b5ce89a95443f83
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off0001429c.bin rtf-objdata-decoded RTF \objdata at offset 0x1429C 24123 bytes
SHA-256: 31d3edf757e5614bb5c578a83bac1d8a2b61668cca24d7692b7ccef25b385591
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00025922.bin rtf-objdata-decoded RTF \objdata at offset 0x25922 24123 bytes
SHA-256: 9beb41d98ed8eecbc3364d89fe5826d3f840a9d8207baf149fa05623e978dc5f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00036fa8.bin rtf-objdata-decoded RTF \objdata at offset 0x36FA8 24123 bytes
SHA-256: 0128b0bafaf1fb067d3b15094a7894b74e277765a84811a66331cda5ab25cb6f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0004862e.bin rtf-objdata-decoded RTF \objdata at offset 0x4862E 24123 bytes
SHA-256: 4ee32ff6d8f732483b27a480db2d1450f4a283427c8dc12407466b34f086e70c
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off00059cb4.bin rtf-objdata-decoded RTF \objdata at offset 0x59CB4 24123 bytes
SHA-256: 590f2b82fa99d3c0efb8af7d029134a876e09de60508879add9266afaccd94db
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006b33a.bin rtf-objdata-decoded RTF \objdata at offset 0x6B33A 24123 bytes
SHA-256: 42db68a0c3960ef6a4b83f172afff53e8c01be41c78f2ec8b50da617547ee980
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007c9c0.bin rtf-objdata-decoded RTF \objdata at offset 0x7C9C0 24123 bytes
SHA-256: f99eb93304e77034e6a06e2c56fdfd4740e0792d99abeb6503f90b824ae57ac5
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off0008e046.bin rtf-objdata-decoded RTF \objdata at offset 0x8E046 24123 bytes
SHA-256: 3b9acc7e1dca031ad0b6ed5dd539094f688922c99652d10bb2cad06478ab7b84
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off0009f6cc.bin rtf-objdata-decoded RTF \objdata at offset 0x9F6CC 24123 bytes
SHA-256: 627831b81d607e5454b9840609fc1b2f1906326f9fc6ba517422141085d099f9
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_10_off000b0d52.bin rtf-objdata-decoded RTF \objdata at offset 0xB0D52 24123 bytes
SHA-256: 9f4fff374013bc443d627ba3dcd8f6ed9a2e4c5e96ea3b096e69b5a389d6a722
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_11_off000c23d8.bin rtf-objdata-decoded RTF \objdata at offset 0xC23D8 24123 bytes
SHA-256: 178152945652d4af79c6f3ac3044db78ebeaa9e43ba3d2437a489cbd95f545cc
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely