Malicious RTF — malware analysis report

Static analysis result for SHA-256 56014824ff939636…

MALICIOUS

RTF

737.3 KB Created: 2018-05-02 20:21:00 First seen: 2019-01-12
MD5: ef9d35e496dacb96de1eb8a8a7765d2d SHA-1: 5a3f8dccc8a0d1f256225a7d1720809f729d5537 SHA-256: 56014824ff93963645be9a34b35482829ff291eab1afa7baada25b18b4a3f68b
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c16.bin rtf-objdata-decoded RTF \objdata at offset 0x2C16 24123 bytes
SHA-256: 927312d4df8fdee65b8eff7384d283d5c5caa3a4d2be413d2d0e4b1517017fc4
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off000142b1.bin rtf-objdata-decoded RTF \objdata at offset 0x142B1 24123 bytes
SHA-256: e40381d122eb4f0dd4e906e7d87af2f82bfa4fa23480d19aff2d3573c9756580
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002594c.bin rtf-objdata-decoded RTF \objdata at offset 0x2594C 24123 bytes
SHA-256: 88b915efe4eaaa6f70e1721bd423d60001863a37a663e619baad6bf44cc06b61
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00036fe7.bin rtf-objdata-decoded RTF \objdata at offset 0x36FE7 24123 bytes
SHA-256: 07f4846c78669b3cdf1b4f1ef52726c140f7f562a26a44ddf71095e239654795
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00048682.bin rtf-objdata-decoded RTF \objdata at offset 0x48682 24123 bytes
SHA-256: 9d059619351ae8f0e2beafa0b72aa05c66af529bb6533f88e7661a7be42f1e0c
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off00059d67.bin rtf-objdata-decoded RTF \objdata at offset 0x59D67 24123 bytes
SHA-256: 6555aa32d07c03ccef6cbbcf4ad5ea4f91034d8b7a5763ed027ee50b761778c1
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006b402.bin rtf-objdata-decoded RTF \objdata at offset 0x6B402 24123 bytes
SHA-256: 4a6962402e9008908c5e0d24b096615299c2cc95f745839275508e02ad1226c7
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007ca9d.bin rtf-objdata-decoded RTF \objdata at offset 0x7CA9D 24123 bytes
SHA-256: 74075f5eed0216ae8c63f610f02f1bd9ef12287bdd29d5116d72d593b596e340
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off0008e138.bin rtf-objdata-decoded RTF \objdata at offset 0x8E138 24123 bytes
SHA-256: 7a8e7637891ef89b9562f720a769952ed91100dd6f9c738ac5b15a52087b6116
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off0009f7d3.bin rtf-objdata-decoded RTF \objdata at offset 0x9F7D3 24123 bytes
SHA-256: 1a26b5fefb58f0a1d30b2884549352deed55f507e99b283e99e1357605a547a0
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely