Malicious RTF — malware analysis report

Static analysis result for SHA-256 323d8ea89749f1c6…

MALICIOUS

RTF

918.5 KB Created: 2018-05-10 16:08:00 First seen: 2018-06-14
MD5: ebd2b797b574b772c80e4acf12d51016 SHA-1: d48b1f2692c637684dcfacadd3425d11674d20a7 SHA-256: 323d8ea89749f1c6edddd33365507fb30fe33bbcba383ec7111c2d2d51775dbe
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c17.bin rtf-objdata-decoded RTF \objdata at offset 0x2C17 33339 bytes
SHA-256: dee51aec8a774f6dbcfb9c744a082c7971d1bfe1613d1984e723140c37e216a1
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018b33.bin rtf-objdata-decoded RTF \objdata at offset 0x18B33 33339 bytes
SHA-256: dad4be3434140aa70cf56a0120b55d1dadb7fe8640ec2ccd772f504620362dc3
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002ea4f.bin rtf-objdata-decoded RTF \objdata at offset 0x2EA4F 33339 bytes
SHA-256: f8c12130826ecfb3a9e5b806d381e8f3489341bc665675e003f47c3d1203e566
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off0004496b.bin rtf-objdata-decoded RTF \objdata at offset 0x4496B 33339 bytes
SHA-256: 8eaa519e779caa4f2bbd87e4b7d588e4083c70e5d006a2cabdf331fe46266409
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a887.bin rtf-objdata-decoded RTF \objdata at offset 0x5A887 33339 bytes
SHA-256: 94e1a4a1cacc175608b426cd8840311f3f22e7bab88d75e46c3438847ebbed16
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000707ef.bin rtf-objdata-decoded RTF \objdata at offset 0x707EF 33339 bytes
SHA-256: 164d5176a9ff49a3ff4e677fa3789adebe10f175966bddf93b273de5f44f4910
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0008670b.bin rtf-objdata-decoded RTF \objdata at offset 0x8670B 33339 bytes
SHA-256: fa061ffb6f9813f57b74c5f74d9ddbec27b0e5800b395b6c1c8ab6adedda0809
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0009c627.bin rtf-objdata-decoded RTF \objdata at offset 0x9C627 33339 bytes
SHA-256: 8172a78055fca851daf0c1daa0098f4fe9f5c528f653b16842a399cde67ec9e3
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b2543.bin rtf-objdata-decoded RTF \objdata at offset 0xB2543 33339 bytes
SHA-256: 6e1f198201f05fb1c61d18f1703720f28a1774ca0b0096f7b8dd3a39fc0df26b
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c845f.bin rtf-objdata-decoded RTF \objdata at offset 0xC845F 33339 bytes
SHA-256: 51770bcb12bc0031c23642d383f47e79350357dc5fb8ca3164a471b0bd25109d
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely