Malicious RTF — malware analysis report

Static analysis result for SHA-256 8a05a96e0e4ca126…

MALICIOUS

RTF

841.3 KB Created: 2018-03-12 22:02:00 First seen: 2018-06-14
MD5: bbf0c048330e3d157f6dc738c8bace80 SHA-1: 0b4ecc4fb011807f57f208fee174d6b46c9ecc26 SHA-256: 8a05a96e0e4ca126cf90fd9b27b3c1e51b6731b2acd435e9ec020129cf624e52
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Xls.Downloader.Generic-6750544-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Generic-6750544-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c44.bin rtf-objdata-decoded RTF \objdata at offset 0x2C44 28731 bytes
SHA-256: 5bb95fcf50b3e67713e530c734533e43782f9fd87d2d22a8ae76c2ee11b7fc2b
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_01_off00016c84.bin rtf-objdata-decoded RTF \objdata at offset 0x16C84 28731 bytes
SHA-256: 0caae0b80507f3f1f0f29559a2b99876eb0a7363fdb5ae3eb238184c3a5fc215
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_02_off0002acc4.bin rtf-objdata-decoded RTF \objdata at offset 0x2ACC4 28731 bytes
SHA-256: d2ae796d279f4a11ba3b3b859f5c90e2422e30a1e3b94ed88a5360134b2c8e95
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_03_off0003ed04.bin rtf-objdata-decoded RTF \objdata at offset 0x3ED04 28731 bytes
SHA-256: 133c2661f72a7775168af1ccc0128f095693a9db09d36e2985456a60739cf306
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_04_off00052d44.bin rtf-objdata-decoded RTF \objdata at offset 0x52D44 28731 bytes
SHA-256: dae4d06113e488ab9e6662f2c9bbfaf1aa494860c9b757092b0aa3c04dc48f5c
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_05_off00066d84.bin rtf-objdata-decoded RTF \objdata at offset 0x66D84 28731 bytes
SHA-256: ca14b4c286ee424d1e4aefee900ce1f6e785740677383c63f7eaf5a331a3e0bd
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_06_off0007adc4.bin rtf-objdata-decoded RTF \objdata at offset 0x7ADC4 28731 bytes
SHA-256: 57445bb0b0acd9a6e00990859d24d6f746cf4648367acb88448846e0f33d8fd2
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_07_off0008ee04.bin rtf-objdata-decoded RTF \objdata at offset 0x8EE04 28731 bytes
SHA-256: b8803864058cb191893ad765af2800588115eef1838b98d6aa5715a59a1951b8
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_08_off000a2e44.bin rtf-objdata-decoded RTF \objdata at offset 0xA2E44 28731 bytes
SHA-256: 15900a78394cf9e647997c563e1af8303b6653ddb85bd6aab3eb7efabb55ff65
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_09_off000b6e84.bin rtf-objdata-decoded RTF \objdata at offset 0xB6E84 28731 bytes
SHA-256: 4e6056bed46e25b262e6c8f831ba61882eb7f18da84612b89fd2082ad74edca3
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely