Malicious RTF — malware analysis report

Static analysis result for SHA-256 666afd2e63c364ac…

MALICIOUS

RTF

813.8 KB Created: 2018-03-31 13:56:00 First seen: 2018-04-23
MD5: 7845c0747d5d7b542ae63a2f7cde17da SHA-1: e2eb06b1e7f35129b69cac0c51d8416bb209c38a SHA-256: 666afd2e63c364acb3fb331abc4209dcdc9e3b7182e5e89aa9f8d85976f70e7e
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c9c.bin rtf-objdata-decoded RTF \objdata at offset 0x2C9C 26683 bytes
SHA-256: c44a0026d177538de42d62d7135197f2f001ee774217c6f6cab5f491f2dd1e7d
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00016266.bin rtf-objdata-decoded RTF \objdata at offset 0x16266 26683 bytes
SHA-256: f784631f4a17e57a7f5e507e6c8dd37494f5af6d431072a324b1b9c146d3a61b
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off0002978b.bin rtf-objdata-decoded RTF \objdata at offset 0x2978B 26683 bytes
SHA-256: 3d8575f52f2a52c50d2fae17c771fdc4bf4107e2c38ee02a5d8c3e10b950c5f2
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003ccae.bin rtf-objdata-decoded RTF \objdata at offset 0x3CCAE 26683 bytes
SHA-256: dfa33b2a22f89be842cb4fb432fdb4f67fd9ed758a94fc39c4c76ca1df9c0257
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off000501d1.bin rtf-objdata-decoded RTF \objdata at offset 0x501D1 26683 bytes
SHA-256: 378e492455a94f2dcaac6de682eed49c5321c99a11d740376b5eba0ea670e94c
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off000636f4.bin rtf-objdata-decoded RTF \objdata at offset 0x636F4 26683 bytes
SHA-256: 578c65e90d99be6d8df3e64eeea152c1496289dbb47d196fe5eb35c9d14ce44d
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off00076c37.bin rtf-objdata-decoded RTF \objdata at offset 0x76C37 26683 bytes
SHA-256: 70079439991ef88af441501671fba9e5affdb692d0f23b1978f44eb47f130480
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008a15a.bin rtf-objdata-decoded RTF \objdata at offset 0x8A15A 26683 bytes
SHA-256: f31afa256307ab47766a602027b98f6368b8e13be2c489c0ee4cef82c77a568e
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off0009d67d.bin rtf-objdata-decoded RTF \objdata at offset 0x9D67D 26683 bytes
SHA-256: c892c2a397dce810a067a90a6b8f2f1524b7ee13ebacefe795539988ddaa08da
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b0ba0.bin rtf-objdata-decoded RTF \objdata at offset 0xB0BA0 26683 bytes
SHA-256: abe36f302092a2fd65f3fb66765fea6936796f6b8dadce880879edb3fa0ba428
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely