Malicious RTF — malware analysis report

Static analysis result for SHA-256 8023830b424814ac…

MALICIOUS

RTF

899.6 KB Created: 2018-03-31 16:48:00 First seen: 2018-04-12
MD5: cfa76c4452423b8bebcf10b9692fab18 SHA-1: d6675fe736470e91a820c44f4e142d288c53e3c7 SHA-256: 8023830b424814ac071b9cc6047bed8773fa9f03b8828bb2e5e6fbc8405d99a7
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 11 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 11

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c4e.bin rtf-objdata-decoded RTF \objdata at offset 0x2C4E 27707 bytes
SHA-256: 7938e6689e2676cf302ffa42b1306f5a06dd770b6e621ee1a90d140026b06901
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00016485.bin rtf-objdata-decoded RTF \objdata at offset 0x16485 27707 bytes
SHA-256: cfa60449bbe19ce33b465d67cead2811801cfd5a0722af69c4969b5a3b3b59b6
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00029cbc.bin rtf-objdata-decoded RTF \objdata at offset 0x29CBC 27707 bytes
SHA-256: 118716a6b72ef0f8a7e59ef089567dc5d9d0ce7def40ba46a2c7408803a8a35a
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003d4f3.bin rtf-objdata-decoded RTF \objdata at offset 0x3D4F3 27707 bytes
SHA-256: 48ce7f66853e57934219772ad8a19e8b3f40b2c59680e7858afa6831f306b78a
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off00050d2a.bin rtf-objdata-decoded RTF \objdata at offset 0x50D2A 27707 bytes
SHA-256: 9da06b97f8fe186436b95700ccf5e3066c9d8513df07d09b7683a042288f3414
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off00064561.bin rtf-objdata-decoded RTF \objdata at offset 0x64561 27707 bytes
SHA-256: 3be60a9c40f353747e30b9e9482fcb70b9def69cb3413ab489e2d127ca4b219a
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off00077d98.bin rtf-objdata-decoded RTF \objdata at offset 0x77D98 27707 bytes
SHA-256: 2699c9b45748edeecdf1b392ffe09fc2c22b8c31540d7a04332ef441e0f1cd7b
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008b62d.bin rtf-objdata-decoded RTF \objdata at offset 0x8B62D 27707 bytes
SHA-256: 5e4955701571f99a0d9dc3d93ec87dcfcdf64ae7f8bcc07638aab360403bbbef
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off0009efbd.bin rtf-objdata-decoded RTF \objdata at offset 0x9EFBD 27707 bytes
SHA-256: 1bd6bdfca6d59233e16648d032c578a102573ba5e041ebe0560e76fe81fcce2b
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b27f4.bin rtf-objdata-decoded RTF \objdata at offset 0xB27F4 27707 bytes
SHA-256: e7a7b8cceb04e088f380f1e245fc09a669faaa4d8c5f0db9be9339cf65190b4d
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_10_off000c602b.bin rtf-objdata-decoded RTF \objdata at offset 0xC602B 27707 bytes
SHA-256: 339eaa1186bcdb1a1ed85f75f79a07087c8cba4cee2eee9c4e83967d21432777
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely