Malicious RTF — malware analysis report

Static analysis result for SHA-256 57d5cfdb3feabe56…

MALICIOUS

RTF

868.1 KB Created: 2018-02-24 17:34:00 First seen: 2018-06-14
MD5: be5c9f8e4e4e9dbaf848715da45cc4f5 SHA-1: 09327ab882c9f7da4c46b9e4af3a5d9be05de997 SHA-256: 57d5cfdb3feabe56c9a81aaad0c3501aa147e5a9c2d274b14f80c6a3f3cc3d50
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Xls.Downloader.Generic-6750544-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Generic-6750544-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002cfa.bin rtf-objdata-decoded RTF \objdata at offset 0x2CFA 27707 bytes
SHA-256: c3c036891fb34bf49722934f15b26b6fd75c2821d66fc80fa09b23494e38963a
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_01_off00017288.bin rtf-objdata-decoded RTF \objdata at offset 0x17288 27707 bytes
SHA-256: c2d10b5ddbc069dcddfccaa2685c15c670281cb22c3f5dbf57c02304a7eada2b
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_02_off0002be95.bin rtf-objdata-decoded RTF \objdata at offset 0x2BE95 27707 bytes
SHA-256: 87d77dafa9aa93d73c9ee130f82707c0524e1133552bd862553cb3fe26c42589
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_03_off00040aa0.bin rtf-objdata-decoded RTF \objdata at offset 0x40AA0 27707 bytes
SHA-256: b8b8510b21c96ad919c45b232b5cb641faa6e9f1500d53e50b6e2906b5775ca5
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_04_off000556ab.bin rtf-objdata-decoded RTF \objdata at offset 0x556AB 27707 bytes
SHA-256: f54a50cc5271746f1db8693606516c5729e3e3cee8d9e0faf4f999bd23f8675c
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_05_off0006a477.bin rtf-objdata-decoded RTF \objdata at offset 0x6A477 27707 bytes
SHA-256: b4a05a220c9911a688e75c70efc825e9567b3d6c906a5a06c20ca7a29abaa8a7
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_06_off0007e980.bin rtf-objdata-decoded RTF \objdata at offset 0x7E980 27707 bytes
SHA-256: 62918024b4c7c8b7fe4ea65966f07c994da885fba310c548da169f1ab9fee290
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_07_off0009358b.bin rtf-objdata-decoded RTF \objdata at offset 0x9358B 27707 bytes
SHA-256: d501a21fec3b6e5b009069e3b039c3d1c77f5b37fd75261c461d1bb5b8fd7d77
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_08_off000a8196.bin rtf-objdata-decoded RTF \objdata at offset 0xA8196 27707 bytes
SHA-256: 4b91282160ef900bd0e4788f4e718266448d6ae43ad47cce7a0c32204b82651e
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_09_off000bcda1.bin rtf-objdata-decoded RTF \objdata at offset 0xBCDA1 27707 bytes
SHA-256: 3d5967163a6d933798359d9a7e0fdeb5f20332e22a883219f9295c2972f95ed8
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely