Malicious RTF — malware analysis report

Static analysis result for SHA-256 641762ef58019062…

MALICIOUS

RTF

875.0 KB Created: 2018-02-24 17:24:00 First seen: 2018-03-30
MD5: af2debbbd35a475c7ab8677869318514 SHA-1: 19c9afc4a4f217d337e7a66beeb6af7c8c45f8cb SHA-256: 641762ef580190629e32e4018fc2c049462d71bc87b072003d656d90ae779cc5
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Xls.Downloader.Generic-6750544-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Generic-6750544-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003649.bin rtf-objdata-decoded RTF \objdata at offset 0x3649 27707 bytes
SHA-256: 2722d44b9b62eed17ab2c3ebe7509f7e35ec35cb5be9b3593e45f62cde309485
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_01_off00018248.bin rtf-objdata-decoded RTF \objdata at offset 0x18248 27707 bytes
SHA-256: 7c9b1b5a8ae82245598e6a41479e78f13a47bee379f6b6ac8fb28b181cf64475
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_02_off0002ce47.bin rtf-objdata-decoded RTF \objdata at offset 0x2CE47 27707 bytes
SHA-256: f403757ed427e17b59917881ebf6fca1fecb1d66a712dceb6bb7453938851d4e
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_03_off00041a46.bin rtf-objdata-decoded RTF \objdata at offset 0x41A46 27707 bytes
SHA-256: 9ce2066776f25ce5ab4fcce08679e19c220755d8f4021317cbdee237446a1c49
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_04_off00056645.bin rtf-objdata-decoded RTF \objdata at offset 0x56645 27707 bytes
SHA-256: be9e7c628398771bce2db6b780d7f793ac649cbf40af656e1314efd0eca32ae8
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_05_off0006b244.bin rtf-objdata-decoded RTF \objdata at offset 0x6B244 27707 bytes
SHA-256: abe24de48c24ee9e924f2f6bfcc24bf7d4dc1e8c0106b91ada4ee9cb3884fa59
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_06_off0007fe43.bin rtf-objdata-decoded RTF \objdata at offset 0x7FE43 27707 bytes
SHA-256: 1f8e87a2223af7958f43ecda78ae8c75baf8ea704c47e814050dc80bdaac1747
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_07_off00094a42.bin rtf-objdata-decoded RTF \objdata at offset 0x94A42 27707 bytes
SHA-256: 6b135f787d8fecce94ca8a25025eb58338e144152640a8bbcc5bc8926a46568e
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_08_off000a9641.bin rtf-objdata-decoded RTF \objdata at offset 0xA9641 27707 bytes
SHA-256: 0c2f99c48cfd45d256fe8c934419b5b1354d9002cd6475ec7cfc945a239561d1
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_09_off000be240.bin rtf-objdata-decoded RTF \objdata at offset 0xBE240 27707 bytes
SHA-256: 297a3c19a99186aef882d0220890eb1d130b44ffc56e20a85972ed0cafec6d26
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely