Malicious RTF — malware analysis report

Static analysis result for SHA-256 6f2b3ec34a5c2b6b…

MALICIOUS

RTF

996.2 KB Created: 2018-03-31 17:09:00 First seen: 2018-04-23
MD5: a5161cd7a30aff3cea81a1e5fab6b8d4 SHA-1: 5b9653ab3f37af51fa8b9bba574214253475ea0d SHA-256: 6f2b3ec34a5c2b6b449a6a3c5a5bc513202902e697a854516701ed44acc8001f
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 12 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 12

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c64.bin rtf-objdata-decoded RTF \objdata at offset 0x2C64 27707 bytes
SHA-256: a72a96bdb9026dacbb29b5967d063d28952938154bd9cbeb278e627a1d10a76e
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00015fb6.bin rtf-objdata-decoded RTF \objdata at offset 0x15FB6 27707 bytes
SHA-256: 3cd79ba0593a38c8d145e17c3ebc1cb234fec805a3323ecb93db3413e893f23b
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00029308.bin rtf-objdata-decoded RTF \objdata at offset 0x29308 27707 bytes
SHA-256: 2ca1a5b118ec989f885e3dfd0c099a730aa3dffdc45342da860de04dca540b8f
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003c661.bin rtf-objdata-decoded RTF \objdata at offset 0x3C661 27707 bytes
SHA-256: 76422da7e35781b5bb44d2ff6c281898c654bdc9d793768e44f1240e139065c9
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off0004f9b3.bin rtf-objdata-decoded RTF \objdata at offset 0x4F9B3 27707 bytes
SHA-256: b172353a365b144ebb5e7625d233e2fdd6623a8d50d2c2b707a08f758a03854b
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off00062d05.bin rtf-objdata-decoded RTF \objdata at offset 0x62D05 27707 bytes
SHA-256: c69a1c0a6f6e770e3fabdf9923681f96b3c65220ff5cd304b3525155980ee6ec
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off0007605e.bin rtf-objdata-decoded RTF \objdata at offset 0x7605E 27707 bytes
SHA-256: bb7eb8262033afbf489aa82de3992005ad66779b65624795323bfe4fc4fc0ca0
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off000893b0.bin rtf-objdata-decoded RTF \objdata at offset 0x893B0 27707 bytes
SHA-256: c05b8dc5b0271e149526942d1a5329472fd429aeae31234facbd220091dcc866
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off0009c702.bin rtf-objdata-decoded RTF \objdata at offset 0x9C702 27707 bytes
SHA-256: 90ed5122faca6f74a266aa800e30266066d4ece179c8c1cda0d54af3ca21cff2
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000afa5b.bin rtf-objdata-decoded RTF \objdata at offset 0xAFA5B 27707 bytes
SHA-256: b345348d9510282028c9b3e9eb1188a93910cf9774315b8ed732a4c9af311c09
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_10_off000c2dad.bin rtf-objdata-decoded RTF \objdata at offset 0xC2DAD 27707 bytes
SHA-256: 18dc30d67a89def7981c52f14e7104d40d2954b000a3646e86e3daa7eb1883ee
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_11_off000d60ff.bin rtf-objdata-decoded RTF \objdata at offset 0xD60FF 27707 bytes
SHA-256: b20f3b22a45f7c2d25b6448d73ae68e07b03fda1a39a2fd37ae9009336b7c629
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely