Malicious RTF — malware analysis report

Static analysis result for SHA-256 7b154c924d5d23d1…

MALICIOUS

RTF

918.5 KB Created: 2018-05-07 02:32:00 First seen: 2018-07-27
MD5: 0b6daa26b4f679b5611d319dd553fbbc SHA-1: d79faf0da83304e417af1fadc680c2edc60a56de SHA-256: 7b154c924d5d23d13a322dd2a10654dcaefa2423339862da279dbd8cc9a0377f
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 9

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c14.bin rtf-objdata-decoded RTF \objdata at offset 0x2C14 33339 bytes
SHA-256: 21d4b0c36433ac3cd8161ba5b301a1db96060a90ab9f41247e8287e231126156
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018b2c.bin rtf-objdata-decoded RTF \objdata at offset 0x18B2C 33339 bytes
SHA-256: 7f7fc77c65eeb36c4d341f33d1ddbeab46c8f2d577a292b24ffae6c9a6bd010d
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002ea44.bin rtf-objdata-decoded RTF \objdata at offset 0x2EA44 33339 bytes
SHA-256: 5573d30faec24d8ccfd82d5574dc4f12062aaa91b8f92b2511fb2cd854b91c4d
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off0004495c.bin rtf-objdata-decoded RTF \objdata at offset 0x4495C 33339 bytes
SHA-256: 2c654f1db8fe6cd7b1f508f52ec793cbb5911463980dc3d84608f190b627a62f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a874.bin rtf-objdata-decoded RTF \objdata at offset 0x5A874 33339 bytes
SHA-256: 3a5fa955423c5000df01f30c241425acd2840c2e7821d1c7198abf2dc986cbfb
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000707d6.bin rtf-objdata-decoded RTF \objdata at offset 0x707D6 33339 bytes
SHA-256: eb68cf77e4194f326dd010cdd3133c060ad56ddf9175ca295bd5ee867e9c6d35
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off000866ee.bin rtf-objdata-decoded RTF \objdata at offset 0x866EE 33339 bytes
SHA-256: 0737cc5beda36991f4aacf79ee9fed4624343e25cd9c10f8eeb8ac08cb88393a
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b251e.bin rtf-objdata-decoded RTF \objdata at offset 0xB251E 33339 bytes
SHA-256: ed26be56cb0bf9d47d465af072f257959e3c5c8d8f9c8a4caa433b5a3f1d65b8
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c8436.bin rtf-objdata-decoded RTF \objdata at offset 0xC8436 33339 bytes
SHA-256: 561b38eb68883d26859488c00d16914188742217ef0da34b2cd83dc486c19122
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely