Xls.Malware.Valyria-6934880-0 — RTF malware analysis

Static analysis result for SHA-256 8c4e3d3da1a0195e…

MALICIOUS

RTF

737.2 KB Created: 2018-02-07 20:06:00 First seen: 2018-02-19
MD5: fef2e48585db70ca52197375a23cce57 SHA-1: 880e3f5bc862738a55e4516cd10f50103bd690ed SHA-256: 8c4e3d3da1a0195edafe7ff3eb541c3026e373c8add26a10e1fc2fc97614d08f
262 Risk Score

Malware Insights

Xls.Malware.Valyria-6934880-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and uses \objupdate to force their activation. Critical heuristics indicate exploitation of CVE-2017-8759, a known vulnerability in MSXML that allows for OLE object activation. ClamAV detections confirm this is a malicious Excel variant, likely Valyria, which typically downloads and executes further stages. The embedded OLE objects are the primary mechanism for this execution.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Xls.Malware.Valyria-6934880-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Valyria-6934880-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c26.bin rtf-objdata-decoded RTF \objdata at offset 0x2C26 22587 bytes
SHA-256: ebcc3ca2ef64b6d97220989e1b020b1b295f6fe46ce302b5b40e2814a10e9808
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_01_off0001383e.bin rtf-objdata-decoded RTF \objdata at offset 0x1383E 22587 bytes
SHA-256: 473806b219f2c3fad0278a263197edfb5bc2b375020bf55713a07a63a384bc40
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_02_off000243cb.bin rtf-objdata-decoded RTF \objdata at offset 0x243CB 22587 bytes
SHA-256: 84b4c8192f73bee7bcfc1ec993461923032b6912c642352378a892a55f3a3fe6
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_03_off00034f5a.bin rtf-objdata-decoded RTF \objdata at offset 0x34F5A 22587 bytes
SHA-256: dff246474e6b395f8676aacb46805b1f3520c3f2fcff0c4f716b6dbad438b50a
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_04_off00045ae9.bin rtf-objdata-decoded RTF \objdata at offset 0x45AE9 22587 bytes
SHA-256: f0aebf3c2407b18e30ba8d82db86b9d75de198c27fa85c2ffe3c59f6e3ec03ec
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_05_off00056678.bin rtf-objdata-decoded RTF \objdata at offset 0x56678 22587 bytes
SHA-256: dacec17690aaf9feabe07f8e20379a0823ab613295a5f6f5fa660689181fab6e
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_06_off00067207.bin rtf-objdata-decoded RTF \objdata at offset 0x67207 22587 bytes
SHA-256: 70e30497283efbcaed6eec24d6fd77f69ffd996189a7b3644649aa92b2fc2ecc
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_07_off00077d96.bin rtf-objdata-decoded RTF \objdata at offset 0x77D96 22587 bytes
SHA-256: 8dff5c6de1f28b79d063f5d047faa6571cded2ab9d21f3fcdbb5fb776ddcc81e
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_08_off00088925.bin rtf-objdata-decoded RTF \objdata at offset 0x88925 22587 bytes
SHA-256: 0bfbc2a845e17f0bb6ea527b6e8effdfb2041d4bb63254e0f3c54b82cb3f5bed
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_09_off000994b4.bin rtf-objdata-decoded RTF \objdata at offset 0x994B4 22587 bytes
SHA-256: 42c75c6efbab88926c610daee39c2b9cffa847f11e6ea4e33aa68fe81119732d
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely