Malicious RTF — malware analysis report

Static analysis result for SHA-256 3649ba44c8bfa465…

MALICIOUS

RTF

750.7 KB Created: 2018-04-27 01:41:00 First seen: 2018-06-21
MD5: 8b2a645f67f155822963e3456fc4f157 SHA-1: ed879b714d70072ff96e658552994370e7997fad SHA-256: 3649ba44c8bfa4652e21d86f48ac37cc78853b3b441b1cf6c87904a7f89a5ae3
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c47.bin rtf-objdata-decoded RTF \objdata at offset 0x2C47 24123 bytes
SHA-256: c4e1fb180c9046b342965a6fa33b5abcfa89aacca51331891c0d40cfdf75f263
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off0001483e.bin rtf-objdata-decoded RTF \objdata at offset 0x1483E 24123 bytes
SHA-256: 90741a9b13b43bce5f055ce9d9cb92883c3d3d42fd818a5fc94ddb255e37a266
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00026435.bin rtf-objdata-decoded RTF \objdata at offset 0x26435 24123 bytes
SHA-256: c2ae20a2d0fa0f72082511996441f198956912ebf1c364d51aaa179d27c68cc7
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off0003802c.bin rtf-objdata-decoded RTF \objdata at offset 0x3802C 24123 bytes
SHA-256: 7906990fa296c98871c9c0cbc067b857e02ccf0c453b832393e58ed4a4107ca4
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00049c23.bin rtf-objdata-decoded RTF \objdata at offset 0x49C23 24123 bytes
SHA-256: 82fc954069a2569b100d4dd6d1bc1739765678998bbbf7c1c45d4de8c0b64d34
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off0005b864.bin rtf-objdata-decoded RTF \objdata at offset 0x5B864 24123 bytes
SHA-256: 541949a7efbf69b78a4a41a499f23eb0f3a73a8cb729cddd817cb35d1b268a5a
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006d45b.bin rtf-objdata-decoded RTF \objdata at offset 0x6D45B 24123 bytes
SHA-256: 817be69c40b938982d9ff75e9100f005d7e3d93cbee4384c00344ea5b7fe9426
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007f052.bin rtf-objdata-decoded RTF \objdata at offset 0x7F052 24123 bytes
SHA-256: cb13abc965f8facb08583033808f17c4959afa1f62c84a54d92f11c99e0d17bb
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off00090c49.bin rtf-objdata-decoded RTF \objdata at offset 0x90C49 24123 bytes
SHA-256: bae5e0e460b3ceefdc46e6ec783901c160a62683ac068fef0a6879c7d44f745f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000a2840.bin rtf-objdata-decoded RTF \objdata at offset 0xA2840 24123 bytes
SHA-256: 16a3ea4809ee180170292b05a2523f151fcea1818fb12e5f40a0142eb5c29efb
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely