Malicious RTF — malware analysis report

Static analysis result for SHA-256 3f1818132cc3647b…

MALICIOUS

RTF

918.5 KB Created: 2018-05-07 First seen: 2018-05-18
MD5: f5553782807b0c213c6ca374c98eb98c SHA-1: 1bb16b53e886beb53f5d6a4be447e7b14d9d8530 SHA-256: 3f1818132cc3647b8ef1f1b2e16db012af291815be36730cff0c1d047f65e3ea
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c0c.bin rtf-objdata-decoded RTF \objdata at offset 0x2C0C 33339 bytes
SHA-256: 24ef5c4529992bfc204bab22a0f1e39f70514963a7c436ab56fe008c8417ec31
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018b24.bin rtf-objdata-decoded RTF \objdata at offset 0x18B24 33339 bytes
SHA-256: 98c5ad5b4401507508646a44d2e8add2e21740ee576fdafa84938d1153f7dae3
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002ea3c.bin rtf-objdata-decoded RTF \objdata at offset 0x2EA3C 33339 bytes
SHA-256: 7422c50351d91df75a4143b24cd3b1735250d86a40e9c9ded5270af0b7c758e7
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00044954.bin rtf-objdata-decoded RTF \objdata at offset 0x44954 33339 bytes
SHA-256: c2e14792ce48289e0c129a89e9a024cdde5d694a933910ec03ea60a0ec538e45
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a86c.bin rtf-objdata-decoded RTF \objdata at offset 0x5A86C 33339 bytes
SHA-256: 9e03d276f6fc8281987c5f732f9be9611ad0a9ac1616186987ee8817b8ee613c
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000707ce.bin rtf-objdata-decoded RTF \objdata at offset 0x707CE 33339 bytes
SHA-256: 241d671e984607f2290b7a145e8ea435e947c7ba7f4da509cc42d01f12def122
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off000866e6.bin rtf-objdata-decoded RTF \objdata at offset 0x866E6 33339 bytes
SHA-256: 98b11299e57ae45157b4733722aa2a419d3396dab6bfd9f2a0c2ac44b3a8da35
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0009c5fe.bin rtf-objdata-decoded RTF \objdata at offset 0x9C5FE 33339 bytes
SHA-256: 7640754382b19c33debe1241ad2f6b66f8004ab01471b4f51f58d70308a9071f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b2516.bin rtf-objdata-decoded RTF \objdata at offset 0xB2516 33339 bytes
SHA-256: 4b116d7a555d9d60fdf500dd84a53387408c03e255acfdcbc55aa1097def0e0b
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c842e.bin rtf-objdata-decoded RTF \objdata at offset 0xC842E 33339 bytes
SHA-256: d4f3be555b258f6cd7f76f5218021dc813173c390897b79bd458454eac95046d
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely