Malicious RTF — malware analysis report

Static analysis result for SHA-256 3886efd64799ccf1…

MALICIOUS

RTF

821.2 KB Created: 2018-03-31 16:27:00 First seen: 2018-04-30
MD5: 11b8ac9a0ca8f098a720ade719796a91 SHA-1: 80959b643c02bf261df55f39b727edb581c2c04e SHA-256: 3886efd64799ccf14090480c26fa688d9219a5030c0b30cefcd253e310d34304
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c3b.bin rtf-objdata-decoded RTF \objdata at offset 0x2C3B 27707 bytes
SHA-256: 0339e05b1c84beb368c21613b8e8c0d0db7e57e12793de1c0b9cffb27a08408e
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off0001646c.bin rtf-objdata-decoded RTF \objdata at offset 0x1646C 27707 bytes
SHA-256: 3f4b4077aa6d2c4759eaac113bcc16806949cf42ff913d242b57f823f128f8f3
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00029c9d.bin rtf-objdata-decoded RTF \objdata at offset 0x29C9D 27707 bytes
SHA-256: 76e7faf7fd68402bf8b2a320649f35deef5db2b0bf640dfcf2d67242ae579364
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003d4ce.bin rtf-objdata-decoded RTF \objdata at offset 0x3D4CE 27707 bytes
SHA-256: 28930c99faa73b4bc9ac2be3eabed356f5e73fed5a948bd9e0083e3a9eae46a2
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off00050cff.bin rtf-objdata-decoded RTF \objdata at offset 0x50CFF 27707 bytes
SHA-256: 37ac2297fad7ee9a46e1e3acc1055c7b8c14a4daf379dd082caebae486e47e9e
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off0006457a.bin rtf-objdata-decoded RTF \objdata at offset 0x6457A 27707 bytes
SHA-256: 65559b1600fe1cc0d63577177c6ca294f71595c27c68f4d0577565adefcd7f9f
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off00077dab.bin rtf-objdata-decoded RTF \objdata at offset 0x77DAB 27707 bytes
SHA-256: aaafdc80910600b261161b7a59ece9fe7a674c93b2e3e0c97bcae97298b4df64
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008b5dc.bin rtf-objdata-decoded RTF \objdata at offset 0x8B5DC 27707 bytes
SHA-256: 6328442958258d06aac426cebc67e2f48190f17a0a486eecd2f26a5a7649878c
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off0009ee0d.bin rtf-objdata-decoded RTF \objdata at offset 0x9EE0D 27707 bytes
SHA-256: 292882765bf21971356c805de186e63402dcdc0939f35f664ba33bb13f990884
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b263e.bin rtf-objdata-decoded RTF \objdata at offset 0xB263E 27707 bytes
SHA-256: 11b3b036f7d72f80633950d94b49b4d6b75a8c4aa3fbaadf494c0d14b7906c54
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely