Malicious RTF — malware analysis report

Static analysis result for SHA-256 84c42991df4d83a2…

MALICIOUS

RTF

717.0 KB Created: 2018-05-02 20:17:00 First seen: 2018-11-05
MD5: a2f4d5558e1daffdbc93720f5537299d SHA-1: 375489915a154855b000fc5050208019f1906082 SHA-256: 84c42991df4d83a254f26c9efa48082f3d8714feaf58a24b6caaf992f5a71583
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c1c.bin rtf-objdata-decoded RTF \objdata at offset 0x2C1C 23099 bytes
SHA-256: 4b7047a67beb3ebf802c77483589b0c487e3d12e56126ab3888c13ced7767770
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00013a9d.bin rtf-objdata-decoded RTF \objdata at offset 0x13A9D 23099 bytes
SHA-256: 58606696cf965655f84a406842a3d50817c1697c8a26d6c7f801e11c7614ed44
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002491e.bin rtf-objdata-decoded RTF \objdata at offset 0x2491E 23099 bytes
SHA-256: dbca487c666f04ce8686c94d93ac65c3f43986af425986e78bc97974738c8356
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off0003579f.bin rtf-objdata-decoded RTF \objdata at offset 0x3579F 23099 bytes
SHA-256: 2dcd6c08eb599418ee5e9f9db139d229d367c7477298a26fa01130ecc96d1c78
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00046620.bin rtf-objdata-decoded RTF \objdata at offset 0x46620 23099 bytes
SHA-256: 9b85b3c3cd4dc20d904132951760f3f42c19d4eeec9bfe763ae3fe2b03c945ca
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000574ed.bin rtf-objdata-decoded RTF \objdata at offset 0x574ED 23099 bytes
SHA-256: c9ecaea6a57bb4a0bab9b48b8259d24931da89f252a60f851fbb579b572b3c77
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006836e.bin rtf-objdata-decoded RTF \objdata at offset 0x6836E 23099 bytes
SHA-256: 2f8db81bf1c67a5c14d9cf3432f0e437cda24f3716e021e79ce8f485f5d57bba
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off000791ef.bin rtf-objdata-decoded RTF \objdata at offset 0x791EF 23099 bytes
SHA-256: 68aec30f644f4e071ede47560b84bfcda430dc9146995901a6783134a15098f9
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off0008a070.bin rtf-objdata-decoded RTF \objdata at offset 0x8A070 23099 bytes
SHA-256: bda07fe1d53118cead9b5283de90b1dd418b687abb055c8d6584780b8ed90eb1
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off0009aef1.bin rtf-objdata-decoded RTF \objdata at offset 0x9AEF1 23099 bytes
SHA-256: 588c9a83e6093eed14459c9d17ffa4117a36979e5a1a5068843aaf9ffdec681f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely