Malicious RTF — malware analysis report

Static analysis result for SHA-256 29c38638b2238fca…

MALICIOUS

RTF

750.7 KB Created: 2018-05-02 20:29:00 First seen: 2019-05-31
MD5: 68b119d4720bf8595e495ed2f32a045d SHA-1: df72b10bf70b26b87d3bc1583a7b011161850287 SHA-256: 29c38638b2238fcac89c872e7684d18bfcb1e371af317eb262848990bfdb6bc0
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c4c.bin rtf-objdata-decoded RTF \objdata at offset 0x2C4C 24123 bytes
SHA-256: b81f0c4da1395b46ea10683ab167d6c1b7359b6b38d554f82f0d814397a627d5
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00014849.bin rtf-objdata-decoded RTF \objdata at offset 0x14849 24123 bytes
SHA-256: d7f2b9bea81c329079a0d5d10749d83117cfd6bcf47a5e391017bfc28118a395
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00026446.bin rtf-objdata-decoded RTF \objdata at offset 0x26446 24123 bytes
SHA-256: cfc32367fd52c5284cf78074adcfcaa3301179749e54607821c25df5c492963b
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00038043.bin rtf-objdata-decoded RTF \objdata at offset 0x38043 24123 bytes
SHA-256: c99c89356c67e17f4829d79365e7db8758ac39810d05bc7fd86512ae53690dd1
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00049c40.bin rtf-objdata-decoded RTF \objdata at offset 0x49C40 24123 bytes
SHA-256: 9aa398ddc8a7f6181dfb248fc128a80a790c51d9fd8955594b022714c2ca1243
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off0005b889.bin rtf-objdata-decoded RTF \objdata at offset 0x5B889 24123 bytes
SHA-256: 3dfe72a07fdff1ca7b8a5fa57fc79a3d90ed15581165089d38661f0586811e00
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006d486.bin rtf-objdata-decoded RTF \objdata at offset 0x6D486 24123 bytes
SHA-256: c3327eeba3fe20b688120cfbfeafbe4e1fe16abab63092ecb3564361b4761566
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007f083.bin rtf-objdata-decoded RTF \objdata at offset 0x7F083 24123 bytes
SHA-256: ee925f95cc98561b5ca0b8d555e97a70ca8cacf2dd34df458d48821ff9a87010
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off00090c80.bin rtf-objdata-decoded RTF \objdata at offset 0x90C80 24123 bytes
SHA-256: 2c737ade0c3d83dae0fd88c31133dc049bc49d5e9561f7f650ed256b951e0938
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000a287d.bin rtf-objdata-decoded RTF \objdata at offset 0xA287D 24123 bytes
SHA-256: b1b61c8d2514b4e504c43a95dd6883e9832e535334cd78f35d8ba3f119c520a6
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely