Malicious RTF — malware analysis report

Static analysis result for SHA-256 2a2dd2ffa8cc6fad…

MALICIOUS

RTF

737.1 KB Created: 2018-04-27 01:50:00 First seen: 2020-02-04
MD5: 6346ba76e06d08c78a987e1f85d02d6e SHA-1: 63d87393917eb2821a32e7d0713bc81042f601f3 SHA-256: 2a2dd2ffa8cc6fad1f07e41dd8815dcd4b6ce3c18760fb582232e41128560c37
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c09.bin rtf-objdata-decoded RTF \objdata at offset 0x2C09 24123 bytes
SHA-256: ecd5076725e45f48a434c8574cbde5bd50563ec46087eaaa8b63f007b6a7b0a1
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off0001428f.bin rtf-objdata-decoded RTF \objdata at offset 0x1428F 24123 bytes
SHA-256: 9b60a0a67d810c60f1a7d140392c1be600a27b0295432d4bf5770aba7fdad167
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00025915.bin rtf-objdata-decoded RTF \objdata at offset 0x25915 24123 bytes
SHA-256: 05846a75cedf1ec11346a9868a519e6af07ee31d847f9c19cb6f84a2ff5c3fc1
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00036f9b.bin rtf-objdata-decoded RTF \objdata at offset 0x36F9B 24123 bytes
SHA-256: 9a5dd71a8e8d95dd1a2f6a28a05b48f792b688c7d2355792b99fb9d161610db5
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00048621.bin rtf-objdata-decoded RTF \objdata at offset 0x48621 24123 bytes
SHA-256: 900a3d910c4e090bc603cc4db2a334eb8be4482fde2a8f7078452919949dd34e
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off00059cf1.bin rtf-objdata-decoded RTF \objdata at offset 0x59CF1 24123 bytes
SHA-256: 8d067ff53030ce92806751b59b4f78aec53f628fa9f173454dfbd9f2da7f1bca
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006b377.bin rtf-objdata-decoded RTF \objdata at offset 0x6B377 24123 bytes
SHA-256: 228fb71e369cae527483507d9b50e8dfb7da2782df7cf2c33f224a6388c8c75a
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007c9fd.bin rtf-objdata-decoded RTF \objdata at offset 0x7C9FD 24123 bytes
SHA-256: d8d7d9fe3033b408200c1d7df03a328f8312e66c5388cfcb68f206be19c71435
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off0008e083.bin rtf-objdata-decoded RTF \objdata at offset 0x8E083 24123 bytes
SHA-256: 5d8fae1af2e6bbf4cdc7d90c651eddc21f670a7b8189094d7298db3ea4fab9c5
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off0009f709.bin rtf-objdata-decoded RTF \objdata at offset 0x9F709 24123 bytes
SHA-256: 208bae216624e062c1123f237619bd74a681c78b732afa75e12f9851c6f90232
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely