Malicious RTF — malware analysis report

Static analysis result for SHA-256 4b9a0e133472e7ca…

MALICIOUS

RTF

2.57 MB Created: 2018-02-04 22:31:00 First seen: 2018-02-19
MD5: f073328b984dc8ac06b23af413ad2afb SHA-1: a1a5aaf0eb929092c1fa4c5150005c274485ccea SHA-256: 4b9a0e133472e7caeeec448bb692d4e29e555c1d4856ebf4eb9913fb132c9c1d
282 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The sample is an RTF document that contains multiple OLE objects, with evidence of OLE activation via \objupdate. Critical heuristics indicate exploitation of CVE-2017-8759, a known vulnerability for client execution. The embedded URL points to a VBScript file, suggesting the document's purpose is to download and execute this script.

Heuristics 8

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • Large hex data blocks in OLE object high RTF_EXCESSIVE_HEX
    RTF contains ~1079KB of hex-encoded data inside \objdata sections — may hide a payload
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://fast-cargo.com/images/file/vb/22.vbs\\ In RTF body
    • http://schemas.microsoft.com/office/word/2003/wordmlIn RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c17.bin rtf-objdata-decoded RTF \objdata at offset 0x2C17 67630 bytes
SHA-256: 574a70d9f3259eac3bde3295f701b57b12a6077c55fa24d98d34e095f1c0a27f
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_01_off00029ace.bin rtf-objdata-decoded RTF \objdata at offset 0x29ACE 67630 bytes
SHA-256: 00b4ed2ee7f9f9d32a919a9a1703b532ce7be9ae35773af520e6863c63b14de9
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_02_off000508fc.bin rtf-objdata-decoded RTF \objdata at offset 0x508FC 67630 bytes
SHA-256: c84f8f6ec5e7d744dcebcaf94cd96d0ae0f42c4386a35fb6b0936bdeae5ab0d4
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_03_off0007772a.bin rtf-objdata-decoded RTF \objdata at offset 0x7772A 67630 bytes
SHA-256: 0ad283d2911e637762b90c51b317e06973fa3a627c37312a81f1c4c5dfae5171
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_04_off0009e5a6.bin rtf-objdata-decoded RTF \objdata at offset 0x9E5A6 67630 bytes
SHA-256: 681a56bf54eb0f94b9cef2c50c604b263d8c0e73d6a70fa893605542b8725bae
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_05_off000c53d4.bin rtf-objdata-decoded RTF \objdata at offset 0xC53D4 67630 bytes
SHA-256: 00b52948fecaef4526ac58013b3f4dbfd27b1bdef528c64fe3c7eca26542c79a
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_06_off000ec202.bin rtf-objdata-decoded RTF \objdata at offset 0xEC202 67630 bytes
SHA-256: 6bb5ce25aa48caa72ed6452d70c009708ba6439edbe9296098c10b24fa3b1863
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_07_off00113030.bin rtf-objdata-decoded RTF \objdata at offset 0x113030 67630 bytes
SHA-256: b501ed1aaa1918ea52b353363081037b71f8375a41c3afb88c2d3931f22d2b6a
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_08_off00139e5e.bin rtf-objdata-decoded RTF \objdata at offset 0x139E5E 67630 bytes
SHA-256: 608a717eb17d3461620afd78a83737458e1cbcac74b95d3863a1a0da573f0be4
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_09_off00160c93.bin rtf-objdata-decoded RTF \objdata at offset 0x160C93 67630 bytes
SHA-256: 733814dc13088acf6f8c763d8c97d72746a1486a330edfc5288cf52fa47b27b3
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): WScript.Shell Carved macro source contains an auto-exec entry point and execution/download terms.