Malicious RTF — malware analysis report

Static analysis result for SHA-256 85fdd09eb5196133…

MALICIOUS

RTF

821.3 KB Created: 2018-03-31 16:54:00 First seen: 2018-04-23
MD5: 862a4f0a49f5694ab1faf8c1de3a9fa6 SHA-1: a85a351dbab8444973793f51a7395ab4b550970e SHA-256: 85fdd09eb51961339527380feec027e0376bca8f46ebb731ff211f3d1f8f1b21
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c4e.bin rtf-objdata-decoded RTF \objdata at offset 0x2C4E 27707 bytes
SHA-256: 12374707411b289ed4507ab590815b239e0e9f742ba851f1ae9c5e736df5bf2d
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00016485.bin rtf-objdata-decoded RTF \objdata at offset 0x16485 27707 bytes
SHA-256: 860fef6535b1addfd6ece240518ac2c0c855c0b79b5364310b2a48935ddef01a
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00029cbc.bin rtf-objdata-decoded RTF \objdata at offset 0x29CBC 27707 bytes
SHA-256: 066d537cdefcb043888d850c79278668a4784bf115f0a427f2ac18810da59ea2
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003d4f3.bin rtf-objdata-decoded RTF \objdata at offset 0x3D4F3 27707 bytes
SHA-256: a158e061b5cd720063ed632a4394222d4c7e2ea67dc6fbd36c79c50f01f14298
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off00050d2a.bin rtf-objdata-decoded RTF \objdata at offset 0x50D2A 27707 bytes
SHA-256: 57001f602238e8863a94fa9a389da7914059f703448e2d32a0addbfa9fdfc0ed
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off000645ad.bin rtf-objdata-decoded RTF \objdata at offset 0x645AD 27707 bytes
SHA-256: b26f0bd8a754848fd13af9c7bae7a69f140a3dccb3f23182b63c1ba412bfcb61
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off00077de4.bin rtf-objdata-decoded RTF \objdata at offset 0x77DE4 27707 bytes
SHA-256: 23e987b90d1687e39a3a41d264ae18d7f2166566ac3fd237380c4356fe034499
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008b61b.bin rtf-objdata-decoded RTF \objdata at offset 0x8B61B 27707 bytes
SHA-256: fc658e78392429a58d460f6ad0555f7572f371edf607104cb74acb02bb578fea
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off0009ee52.bin rtf-objdata-decoded RTF \objdata at offset 0x9EE52 27707 bytes
SHA-256: 8416924824258d6201985fd00176cf6553cd11cd1b98314fbc70c193a02ec1d7
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b2689.bin rtf-objdata-decoded RTF \objdata at offset 0xB2689 27707 bytes
SHA-256: 4fbf714baa89eca9e148b2f73b71bc0e621d68e1f4022b434d4dfb8888319788
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely