Malicious RTF — malware analysis report

Static analysis result for SHA-256 56e48d2f715b1d28…

MALICIOUS

RTF

918.5 KB Created: 2018-05-10 16:14:00 First seen: 2020-02-04
MD5: d2690aa924d764cd7500da31b078c70a SHA-1: cdb33560086525c4792ab1cfae34376260eb9e11 SHA-256: 56e48d2f715b1d28478c4b37dae0bf94f79078e45a69048b3dd24057c292db07
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c1d.bin rtf-objdata-decoded RTF \objdata at offset 0x2C1D 33339 bytes
SHA-256: 87bb7ec268a7b61647a2b4c4bb567c8f2b4e5989c5eb36169a90fb525775df19
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018b39.bin rtf-objdata-decoded RTF \objdata at offset 0x18B39 33339 bytes
SHA-256: 3f687cf0563de0c49dc09d2ad13d47a21880b92983b5a0c809d668638b9d5397
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002ea55.bin rtf-objdata-decoded RTF \objdata at offset 0x2EA55 33339 bytes
SHA-256: 21a495b6294d25f6dc45c3c55b97bdb06f4d2e1f1a975de01a0cc32642c4cfd8
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00044971.bin rtf-objdata-decoded RTF \objdata at offset 0x44971 33339 bytes
SHA-256: 64114fdc788a04982847a00fda62757903ca84518280f12f5bbe5dd18172d50a
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a88d.bin rtf-objdata-decoded RTF \objdata at offset 0x5A88D 33339 bytes
SHA-256: 3ed0318a1aeabc1ac53fc9c5c01ee05f322673043f1c079d0e62735cc1ab8d60
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000707f5.bin rtf-objdata-decoded RTF \objdata at offset 0x707F5 33339 bytes
SHA-256: a7b4ccb2e43a69b7f2be920077d02b6298b9eced520a3f6f04e7f4200dab55d4
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off00086711.bin rtf-objdata-decoded RTF \objdata at offset 0x86711 33339 bytes
SHA-256: 069ff41cc9cdf1e4be5d0b24cf49ce5dfc91040fdb366c794731030111a4d926
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0009c62d.bin rtf-objdata-decoded RTF \objdata at offset 0x9C62D 33339 bytes
SHA-256: ea8df64f9c73f8be58ccba4d6352d0d4071c5ff461eb5a888585a6758e95c096
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b2549.bin rtf-objdata-decoded RTF \objdata at offset 0xB2549 33339 bytes
SHA-256: 1e4c77f18e53e16239c19e2eff189ef96237cbca948e76a192f605de1408bbbd
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c8465.bin rtf-objdata-decoded RTF \objdata at offset 0xC8465 33339 bytes
SHA-256: e6865375f27fb54aa695fe09b2678c0225b6c8d31cd00502a5a8f669a6f54260
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely