Malicious RTF — malware analysis report

Static analysis result for SHA-256 53c325566fc88c83…

MALICIOUS

RTF

776.0 KB Created: 2017-11-10 23:12:00 First seen: 2017-12-24
MD5: 3ab552c382e138b428dfce60b031d818 SHA-1: 614fdebbacd319b78fe6e8abfd19935d7f77c584 SHA-256: 53c325566fc88c8355478e001445da54debb009c60581e2e6c3345f10c4f65f0
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002a87.bin rtf-objdata-decoded RTF \objdata at offset 0x2A87 26171 bytes
SHA-256: 8dd9d1fb85697457016592e241d26dd57067a1e42bacd71e463680fa479e4c5e
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off000150d6.bin rtf-objdata-decoded RTF \objdata at offset 0x150D6 26171 bytes
SHA-256: b51cfd26b6327b919506fb95aec2c4830b48cbc646d78f78f0536b960012552a
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00027727.bin rtf-objdata-decoded RTF \objdata at offset 0x27727 26171 bytes
SHA-256: 51a754c61ade3a49ce4f65a87830e9c1b66913513dc1f0adad63ea92196baf19
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off00039d78.bin rtf-objdata-decoded RTF \objdata at offset 0x39D78 26171 bytes
SHA-256: 3634ae8d98fb3c5653f119273acdf3a429c595eb41ac610ff58aed389120dd49
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off0004c3c9.bin rtf-objdata-decoded RTF \objdata at offset 0x4C3C9 26171 bytes
SHA-256: 2b8b79a829fba1eb70b3e360e1400e793cb82a5f2aea5c0773e97ff2b5c6e0ca
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off0005ea1a.bin rtf-objdata-decoded RTF \objdata at offset 0x5EA1A 26171 bytes
SHA-256: 3d08d98314e4b1e9ee00c2bb170b5d38c6fc733edc3304566d487fa3017045e6
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off0007106b.bin rtf-objdata-decoded RTF \objdata at offset 0x7106B 26171 bytes
SHA-256: 2f36c839d9eed9b47d5919162bbd61391034bdaec4b024fcb5936b938fcc9fed
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off000836bc.bin rtf-objdata-decoded RTF \objdata at offset 0x836BC 26171 bytes
SHA-256: d1fc139c3adafd534f9a5d92381e925ade2671cf0a13cec9894eec340ac65133
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off00095d0d.bin rtf-objdata-decoded RTF \objdata at offset 0x95D0D 26171 bytes
SHA-256: 4c68c0a8d6963c729f1be1c02416ea00b4ae644c7a3fdbd55ad6a94d6762d76c
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000a835e.bin rtf-objdata-decoded RTF \objdata at offset 0xA835E 26171 bytes
SHA-256: 8c9817445c75edb5d5680ab4676eed203a758494361ceda6d9f85ca38e573293
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely