Malicious RTF — malware analysis report

Static analysis result for SHA-256 6c1ddbd1f2a724d6…

MALICIOUS

RTF

917.9 KB Created: 2018-05-07 First seen: 2018-07-14
MD5: b2ae8dc45a5c035add11227093476c9d SHA-1: 2e9a6e0390841a01d64ed5f0291075a88b06688e SHA-256: 6c1ddbd1f2a724d6fbdc75ee47ded3b0c07982b563bb2cc76859f1437dc15425
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c0d.bin rtf-objdata-decoded RTF \objdata at offset 0x2C0D 33339 bytes
SHA-256: b1f11b7696ea7187b7f23044124172ee027597b34eebccaf796db72d86337fb0
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018aeb.bin rtf-objdata-decoded RTF \objdata at offset 0x18AEB 33339 bytes
SHA-256: 03da8b550209b76ab5b22bfe828a25d0ff000746d7f1ef22dc2c4759507244b0
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002e9c9.bin rtf-objdata-decoded RTF \objdata at offset 0x2E9C9 33339 bytes
SHA-256: ecfc9994fdba4630574e88e088f84d704244016ed21d0d41ee478fda2a8d9dcc
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off000448a7.bin rtf-objdata-decoded RTF \objdata at offset 0x448A7 33339 bytes
SHA-256: 3eeaa69a91c6576a8275124f32292d8c54cafed51d8ecae81810a3f3a0a12ef9
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a785.bin rtf-objdata-decoded RTF \objdata at offset 0x5A785 33339 bytes
SHA-256: aa59e1a784b54116c905363c5f5816c0a8ded15efdae5c06cc6c28fc1e6eefbc
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000706ad.bin rtf-objdata-decoded RTF \objdata at offset 0x706AD 33339 bytes
SHA-256: 981638c7b240d35cb118b6a7e55ac79bb4492c9569f1c36d0f9bf8331de45d37
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0008658b.bin rtf-objdata-decoded RTF \objdata at offset 0x8658B 33339 bytes
SHA-256: b1c198037571244ca7ea068e5c35e90d8261b490696526e073492016104569b3
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0009c469.bin rtf-objdata-decoded RTF \objdata at offset 0x9C469 33339 bytes
SHA-256: 0744d8152e1e2fae0a4485eb8c2883a981d20dac30aff6e777aa20cc4f9b747e
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b2347.bin rtf-objdata-decoded RTF \objdata at offset 0xB2347 33339 bytes
SHA-256: 37480f2e313998452e8826c33f88b746971ace6a81bd0b4021a577bd3ff8374e
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c8225.bin rtf-objdata-decoded RTF \objdata at offset 0xC8225 33339 bytes
SHA-256: 45e0013f7da04de2a4ba41f0e726f96d6a183c797c5aaa21716794f9de6192b4
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely