Malicious RTF — malware analysis report

Static analysis result for SHA-256 42af2a690861f172…

MALICIOUS

RTF

918.5 KB Created: 2018-05-10 15:58:00 First seen: 2019-12-10
MD5: 9f01a66b3222c246170d8a97613dda9c SHA-1: 4a170d31cd09931c3404e50179074f51d3fea928 SHA-256: 42af2a690861f172f95280d1761ed6b44ff84df9dfeb8c3f472c5e2a4d9fa3b0
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c1e.bin rtf-objdata-decoded RTF \objdata at offset 0x2C1E 33339 bytes
SHA-256: e30fe11fd509f4920b1e28206b4069d92f65d0db0a1f7da53ec8fc504fc1a68e
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018b3a.bin rtf-objdata-decoded RTF \objdata at offset 0x18B3A 33339 bytes
SHA-256: 7a447c3217693eb8002c7fe531b14f6b8a22b66e10783ff9af290da14d26db39
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002ea56.bin rtf-objdata-decoded RTF \objdata at offset 0x2EA56 33339 bytes
SHA-256: 47974f37553a052cb35eab524116d465725e5576ac8239a6099bad5109cb51f0
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00044972.bin rtf-objdata-decoded RTF \objdata at offset 0x44972 33339 bytes
SHA-256: e3e75834a927e49e796173383384ca1be6cf79f08d1e14b8c36253fbbf44dce8
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a88e.bin rtf-objdata-decoded RTF \objdata at offset 0x5A88E 33339 bytes
SHA-256: 26bea8805c23accd86648f4689ed14d5ec08df87f3109f6ce071905371deb7d5
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000707f6.bin rtf-objdata-decoded RTF \objdata at offset 0x707F6 33339 bytes
SHA-256: 455f6cfd715a208d0ac84979f624e1153c4e44f5611819bc7f0389ad28db04db
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off00086712.bin rtf-objdata-decoded RTF \objdata at offset 0x86712 33339 bytes
SHA-256: e80b0e0763328afc3143e2dd831acbebc4473ff7906a6e548e756c41573db4d6
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0009c62e.bin rtf-objdata-decoded RTF \objdata at offset 0x9C62E 33339 bytes
SHA-256: c35ea8241f6e1d70472dbf7ced82830bc60ba0035211fe2994140ebdd181b3c5
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b254a.bin rtf-objdata-decoded RTF \objdata at offset 0xB254A 33339 bytes
SHA-256: c5a0ff4e524c56fbf269b7069365acb7f3dae893bacb4be9d9ffae53dd1ee6ac
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c8466.bin rtf-objdata-decoded RTF \objdata at offset 0xC8466 33339 bytes
SHA-256: 37c4ab127bc79392c281e180ce86833343f7eda4f078ea2c02fd7002cdfe24ec
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely