Malicious RTF — malware analysis report

Static analysis result for SHA-256 2699f47fc3c90494…

MALICIOUS

RTF

991.6 KB Created: 2018-03-31 17:11:00 First seen: 2018-04-30
MD5: 3d5775e17dcd2be5f54fc3d62a47cc2d SHA-1: ccd44bc3132901b7addeb646ae7be5f7f5ce793c SHA-256: 2699f47fc3c90494d12c55ecdee6af701b3715e3e5c9545e8d3a65e0daa134c7
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 12 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 12

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c65.bin rtf-objdata-decoded RTF \objdata at offset 0x2C65 27707 bytes
SHA-256: 6356b4f651378aff85db7eb551547ace5a94a8962535cefcdd1f73da46d53e8d
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00015fb7.bin rtf-objdata-decoded RTF \objdata at offset 0x15FB7 27707 bytes
SHA-256: dfafffd3b49e61ead0af46754f4bdd32612bccb223ef992f8c47efeab3c7646e
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00029309.bin rtf-objdata-decoded RTF \objdata at offset 0x29309 27707 bytes
SHA-256: 5b53cb27942304513332524ebf33cadc66a2cf648f7bdb2f67cb9e99d29a601d
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003c662.bin rtf-objdata-decoded RTF \objdata at offset 0x3C662 27707 bytes
SHA-256: 02093e1464909b4c73b6ad4592016569e283ae28b96b811d68d558bc18232a9d
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off0004f9b4.bin rtf-objdata-decoded RTF \objdata at offset 0x4F9B4 27707 bytes
SHA-256: c37c342bb60220de5110133c61bd13186f44b121b0e73777a42ee91e408930a8
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off00062d06.bin rtf-objdata-decoded RTF \objdata at offset 0x62D06 27707 bytes
SHA-256: 8ccc62c0d0276d00b1c29e0f6d23fff9794da16a13a0ff7430a7b71f15c259bf
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off00076049.bin rtf-objdata-decoded RTF \objdata at offset 0x76049 27707 bytes
SHA-256: 77007a2884c24ef96770a6145b99392747c22d7dd4ffc92987a2a3bf8b726609
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008edc4.bin rtf-objdata-decoded RTF \objdata at offset 0x8EDC4 27707 bytes
SHA-256: c2bc346392fd16df5643330b999d60c4c7a509096ba72ac171d6994306dee7f9
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off000a25f5.bin rtf-objdata-decoded RTF \objdata at offset 0xA25F5 27707 bytes
SHA-256: 35c2e82613319bc64001f58954cd5587c57181b42b1a648884cc12840a6164b7
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b5e70.bin rtf-objdata-decoded RTF \objdata at offset 0xB5E70 27707 bytes
SHA-256: f2fa75280de79b224e56548fd7524c763c35d59b78bd745b14c108d13487e9cc
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_10_off000c96a1.bin rtf-objdata-decoded RTF \objdata at offset 0xC96A1 27707 bytes
SHA-256: 2fbc4504958f5a17b36994746496fa88598c342e5d20356d7bd9c73f2a505806
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_11_off000dced2.bin rtf-objdata-decoded RTF \objdata at offset 0xDCED2 27707 bytes
SHA-256: d1b4ac95b2b3799bda6a70089c2fb82b6a68ec536d16e42f67e7c598eb6c888f
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely