Malicious RTF — malware analysis report

Static analysis result for SHA-256 734f4f280b00829a…

MALICIOUS

RTF

722.8 KB Created: 2018-04-27 01:19:00 First seen: 2019-04-18
MD5: 9ee8f249c8013264550fbc16fba90408 SHA-1: 4cd127e1f15ec8739bffbd85ce3ba1ed4511ce54 SHA-256: 734f4f280b00829a07b5736fb29c837a36deff4d8d5bd1145e31d9e17a0aba69
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, indicating an attempt to exploit vulnerabilities. Specifically, the "CVE_2017_8759" heuristic firing strongly suggests exploitation of MSXML SAX OLE activation. This technique is commonly used by droppers to download and execute further malicious content, as indicated by the ClamAV detection of "Doc.Dropper.Agent-6412232-1". The embedded URL, though benign, is part of the RTF structure.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c29.bin rtf-objdata-decoded RTF \objdata at offset 0x2C29 22075 bytes
SHA-256: 4d377e5fbb4844661c63f8325615306d201e909629a5e76e05a3adb1d34a9552
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off0001343a.bin rtf-objdata-decoded RTF \objdata at offset 0x1343A 22075 bytes
SHA-256: 42512fa8ab98c33d11ac027a3130b592a50944c8b810f0e59fe8a91fbcbfa636
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00023bbf.bin rtf-objdata-decoded RTF \objdata at offset 0x23BBF 22075 bytes
SHA-256: ed075493b11bd9839cba95267f7dc42cca86787ff7c715dc0a6b936f42da69d3
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00034346.bin rtf-objdata-decoded RTF \objdata at offset 0x34346 22075 bytes
SHA-256: e3c31fb88075a18e28c3eb66d681f3d3cc55409352a7d7433058fe0ec02bdd30
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00044b33.bin rtf-objdata-decoded RTF \objdata at offset 0x44B33 22075 bytes
SHA-256: f0e53e5b6625d5d5c470e4b248084a9ba6e7d6f447f4484426cbd08235f1febe
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off00055344.bin rtf-objdata-decoded RTF \objdata at offset 0x55344 22075 bytes
SHA-256: 9c5afed83497ae1440a89a15c676fcb37af7c538a740723cb7d397b4a7fb48c5
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off00076250.bin rtf-objdata-decoded RTF \objdata at offset 0x76250 22075 bytes
SHA-256: 738f03c22add8262a4abca8b388c4a6ea98952547768a97ce85dcf7003a4df0d
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off0009715e.bin rtf-objdata-decoded RTF \objdata at offset 0x9715E 22075 bytes
SHA-256: 93ff574701cdc8c96192ed0f341cea8c836470eb0a949dacddbf8e01dc4df7af
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely