Malicious RTF — malware analysis report

Static analysis result for SHA-256 5fdd029c1c733a08…

MALICIOUS

RTF

750.6 KB Created: 2018-04-27 First seen: 2019-05-31
MD5: 415b292dc523219af9ecd87021d7bc4c SHA-1: 36206af8a5e73ea2bad53971479484d5ec31f52f SHA-256: 5fdd029c1c733a084e5e1f2dda54bb4a9d01c878215ffa894ac36cc33cccd75b
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c3f.bin rtf-objdata-decoded RTF \objdata at offset 0x2C3F 24123 bytes
SHA-256: 90f3cc96343d299157d961090086a5ae354a32a8cb1273780050722138efa52e
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00014836.bin rtf-objdata-decoded RTF \objdata at offset 0x14836 24123 bytes
SHA-256: 177cc75148bcd83fc02e3d9cb2d703250d2c64758191ec6c23f3152da9f565a8
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002642d.bin rtf-objdata-decoded RTF \objdata at offset 0x2642D 24123 bytes
SHA-256: 8690599ca8024a8302e33db0ffe0d1933ee981064a49fc6b9efc0681b481ebd5
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00038034.bin rtf-objdata-decoded RTF \objdata at offset 0x38034 24123 bytes
SHA-256: 04751325ab1b457c961f24209a6f3d66d2a9875740986e0dffd9078d237676e3
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00049c2b.bin rtf-objdata-decoded RTF \objdata at offset 0x49C2B 24123 bytes
SHA-256: 1b08831129feaea5fc3f70b1ab10931676350a994fbb851ded0f497f40a7ed6b
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off0005b86c.bin rtf-objdata-decoded RTF \objdata at offset 0x5B86C 24123 bytes
SHA-256: c951d2ed784104167dfbda9840760d47bfd72a6bc9024c9848ade8d762d33058
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006d463.bin rtf-objdata-decoded RTF \objdata at offset 0x6D463 24123 bytes
SHA-256: 683fbf8d600d190f856e793b58552331baacf7c5abd194c56d0d1d8f896fdcd3
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007f05a.bin rtf-objdata-decoded RTF \objdata at offset 0x7F05A 24123 bytes
SHA-256: 802c51083edb2cc9abc16b27b3936013bbc830165795bcbf468e978544de4f13
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off00090c61.bin rtf-objdata-decoded RTF \objdata at offset 0x90C61 24123 bytes
SHA-256: 8df3d13acaf7db8841ddebae71f9cc5dfdd0e9cd586fec5403e12b33bb348191
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000a2858.bin rtf-objdata-decoded RTF \objdata at offset 0xA2858 24123 bytes
SHA-256: b78f0c5f07eb8f210c73af98357a586beff799f57098c14b64aada212fa568f7
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely