Malicious RTF — malware analysis report

Static analysis result for SHA-256 8576a5f00e5d047c…

MALICIOUS

RTF

737.3 KB Created: 2018-04-27 01:48:00 First seen: 2018-06-30
MD5: 91f469fc89ea81cb59d930501d693c3c SHA-1: 22babf34c34cb8ba9e0328da74507dbf7c7c0010 SHA-256: 8576a5f00e5d047ce1df38c18c85586f157887523d534a623d0ae7e3ea9714dd
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and utilizes \objupdate to force their activation. The critical heuristic firing for CVE-2017-8759 indicates exploitation of MSXML SAX OLE activation, a known vulnerability used to execute arbitrary code. ClamAV detections further confirm the malicious nature, identifying it as a dropper. The embedded URL is likely part of the exploit chain.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.mi In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c89.bin rtf-objdata-decoded RTF \objdata at offset 0x2C89 24123 bytes
SHA-256: 94befad4946cf343bfa3e1f3174c0ac71da0178ca59419a00a7cdcf72aa75c17
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00014316.bin rtf-objdata-decoded RTF \objdata at offset 0x14316 24123 bytes
SHA-256: 977b1469ba0d306f22fb88d504a8c5d84aa8ddd6a77c321a6ec78e6c4ad630f2
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off000259a3.bin rtf-objdata-decoded RTF \objdata at offset 0x259A3 24123 bytes
SHA-256: 836e94ba20de6fa9a701f57cfc462e97c24b99600cdbc30eaf83ac488a981ee6
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00037030.bin rtf-objdata-decoded RTF \objdata at offset 0x37030 24123 bytes
SHA-256: b46551617c33dc5dc3d21a49ea304c94d2c021e788d895855e92971ce1030335
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off000486bd.bin rtf-objdata-decoded RTF \objdata at offset 0x486BD 24123 bytes
SHA-256: 1cd45130c2132361706af60225c502557cdd24b257c3032aff2c3e452f652e98
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off00059d9e.bin rtf-objdata-decoded RTF \objdata at offset 0x59D9E 24123 bytes
SHA-256: 7e14b11025b6d51e9105bf8da396368e0e8839e6e0ed63a374021b1ba3a92d83
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006b42b.bin rtf-objdata-decoded RTF \objdata at offset 0x6B42B 24123 bytes
SHA-256: dc63adcccd08529eaf02e8e81f2be440de0acc0d2bb32460621809bee707310d
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007cab8.bin rtf-objdata-decoded RTF \objdata at offset 0x7CAB8 24123 bytes
SHA-256: 6f649b23f6b19f2cb6bc2f3e266907a7f039851bdfdf1573350d8bcd422710a6
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off0008e145.bin rtf-objdata-decoded RTF \objdata at offset 0x8E145 24123 bytes
SHA-256: ed1b82fd219e0dd303e82547ef458babfa9fb1cb3f371a148bea593b6c40ea59
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off0009f7d2.bin rtf-objdata-decoded RTF \objdata at offset 0x9F7D2 24123 bytes
SHA-256: 971c8d9e7c6f2135ab7bdf9da6c8e25d5e291d61f11bbe11319f0393367d6e1b
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely