Malicious RTF — malware analysis report

Static analysis result for SHA-256 5885ea86add67e7a…

MALICIOUS

RTF

675.4 KB Created: 2017-11-02 10:40:00 First seen: 2018-01-23
MD5: d815780e215877b04f76e83131354cd0 SHA-1: d48469c77aeb753b9c139eeb258a2f70010d5eb5 SHA-256: 5885ea86add67e7a149634e8c9ae4da63e35b431c5210256a570b56387ee1f8a
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002a89.bin rtf-objdata-decoded RTF \objdata at offset 0x2A89 21057 bytes
SHA-256: 562bd49916f3a3447869ce6ac718c66c8741028153af1a6cf26935dc8a006aad
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00012898.bin rtf-objdata-decoded RTF \objdata at offset 0x12898 21057 bytes
SHA-256: a63f72d7ab81a3aca27b3276a9877573ad9755c6a510c1d938f93d8d73630124
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off000226a9.bin rtf-objdata-decoded RTF \objdata at offset 0x226A9 21057 bytes
SHA-256: fd449076500e9039a89e1911843f27758d6507f2d1cded94dfb6092d72e07ec4
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off000324ba.bin rtf-objdata-decoded RTF \objdata at offset 0x324BA 21057 bytes
SHA-256: 7ab736225c2ec46073273d3ba53af46fa6bca253531a185198e6293cebcbb9b9
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off000422cb.bin rtf-objdata-decoded RTF \objdata at offset 0x422CB 21057 bytes
SHA-256: ed5a1289b0e50cfab13b66858156cabc3d76fc6f281b57199ef544c94bdfe834
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off000520dc.bin rtf-objdata-decoded RTF \objdata at offset 0x520DC 21057 bytes
SHA-256: 57a2d8c030b9f4d2c031703ece08d36d0f0e8332c3dc036f48377c872eb04dca
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off00061eed.bin rtf-objdata-decoded RTF \objdata at offset 0x61EED 21057 bytes
SHA-256: b4ca5966a2569672ba5d560007655a9fb5b76771334698f266e68bd55f15fbfd
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off00071cfe.bin rtf-objdata-decoded RTF \objdata at offset 0x71CFE 21057 bytes
SHA-256: 94fa84f85f5d642b6edd8691390abd581c27b06daf68b264fe644057151a9042
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off00081b0f.bin rtf-objdata-decoded RTF \objdata at offset 0x81B0F 21057 bytes
SHA-256: 087986c0eebe595e0b2e081b7f71d7fb44bf8a6d8d1cfe9e08f132fd483c8eae
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off00091920.bin rtf-objdata-decoded RTF \objdata at offset 0x91920 21057 bytes
SHA-256: 4857b1d1660bf3b2afddcc50ff1b760f499627690ce235a96220ee860dff4a4e
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely