Malicious RTF — malware analysis report

Static analysis result for SHA-256 35d2ac91ea5986ab…

MALICIOUS

RTF

808.2 KB Created: 2018-03-12 22:03:00 First seen: 2018-06-25
MD5: f618fb1e1731adbd0b66fefae05c9f0f SHA-1: 1cc02cd92048c337a2cdca82690515301b0b80da SHA-256: 35d2ac91ea5986abe24b3daa29b37a89028ab12f5b3662a711f0166421377f25
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Xls.Downloader.Generic-6750544-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Generic-6750544-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c4c.bin rtf-objdata-decoded RTF \objdata at offset 0x2C4C 27195 bytes
SHA-256: 5b05731555b0c62bcf3b6e750985521bd3aa97f201f776bdbe700be4bb5d6b96
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_01_off00015f46.bin rtf-objdata-decoded RTF \objdata at offset 0x15F46 27195 bytes
SHA-256: 470ea89f7569bf1910805d1069fe44838d46c883beb84715f1f6b65e705a5f4e
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_02_off00029240.bin rtf-objdata-decoded RTF \objdata at offset 0x29240 27195 bytes
SHA-256: 459daffdadc12123a4123eb1494a0e4cca8b6036bd76df00c2dd2a5814321a40
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_03_off0003c53a.bin rtf-objdata-decoded RTF \objdata at offset 0x3C53A 27195 bytes
SHA-256: e2a2887be89ac0135cd6436c518d2575ece6ae869a3875e68893c5eb5764fc47
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_04_off0004f834.bin rtf-objdata-decoded RTF \objdata at offset 0x4F834 27195 bytes
SHA-256: cf13ce09b69be186881666bd99621049eb55e343b26fe7c1d84d158fbcd0207c
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_05_off00062b7a.bin rtf-objdata-decoded RTF \objdata at offset 0x62B7A 27195 bytes
SHA-256: da166b3603202feaecfddf1a5ef52eb23770338f524113658407605c1fd5457d
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_06_off00075e74.bin rtf-objdata-decoded RTF \objdata at offset 0x75E74 27195 bytes
SHA-256: 6023a05e8ced5f864e0e5eb420f741766e98185219d19e93d076d0a4647b3012
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_07_off0008916e.bin rtf-objdata-decoded RTF \objdata at offset 0x8916E 27195 bytes
SHA-256: b977df9d467c5beb4f3051e4685322e822e721cbe25c6f9459279a4a20f34afb
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_08_off0009c468.bin rtf-objdata-decoded RTF \objdata at offset 0x9C468 27195 bytes
SHA-256: 2b5888ff53b3eff965172f0990ef429a22e80bb82458ac2c461953ce41090ef7
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_09_off000af762.bin rtf-objdata-decoded RTF \objdata at offset 0xAF762 27195 bytes
SHA-256: 394b67104a180b7b55aede37f90e1ceae9625e39560c3bd1da501784469285e3
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely