Malicious RTF — malware analysis report

Static analysis result for SHA-256 9703c55e7eaefa0f…

MALICIOUS

RTF

921.4 KB Created: 2018-03-12 23:09:00 First seen: 2018-06-25
MD5: 545c705ec16ae70355113d0ee3aea3c1 SHA-1: 74d4467c25bfb7389061539bb819bf2251d5d330 SHA-256: 9703c55e7eaefa0f0b54a2ea5bb9cbf78e6fdad64619dae60bbc390ae1732e82
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Xls.Downloader.Generic-6750544-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Generic-6750544-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 11 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c51.bin rtf-objdata-decoded RTF \objdata at offset 0x2C51 28731 bytes
SHA-256: 39c816ab217e075f0d78a729fb5e2d751d7c16913b55336e86085ac54cbc972a
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_01_off00016c98.bin rtf-objdata-decoded RTF \objdata at offset 0x16C98 28731 bytes
SHA-256: cafcc22710482bd47c70528299e39d435d049e57627ae97d23bd629e11ad38f6
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_02_off0002acdf.bin rtf-objdata-decoded RTF \objdata at offset 0x2ACDF 28731 bytes
SHA-256: 56cdfa96917b9cb3122f23403cd628627ab2da3ac7f5309889ebf90e864f2257
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_04_off00052d6d.bin rtf-objdata-decoded RTF \objdata at offset 0x52D6D 28731 bytes
SHA-256: a0042fb1943a4e67a7b47c22e316bd59f32af983af1c490c475ec43c6d775a6e
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_06_off0007adfb.bin rtf-objdata-decoded RTF \objdata at offset 0x7ADFB 28731 bytes
SHA-256: eb137a200baac9dfdefc66e40a6aab0a4029e6df319a96518bbc0054e4a41514
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_08_off000a2e89.bin rtf-objdata-decoded RTF \objdata at offset 0xA2E89 28731 bytes
SHA-256: 88e423437478a921e548d5b76b79e9e67c90f206bc7fa0163203e8b437af8154
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_09_off000b6ed0.bin rtf-objdata-decoded RTF \objdata at offset 0xB6ED0 28731 bytes
SHA-256: 06a2a21a806b96e8d1093bf041dfad04fb2ee90d4382a333e4bfe991cde1a476
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_10_off000caf17.bin rtf-objdata-decoded RTF \objdata at offset 0xCAF17 28731 bytes
SHA-256: e9548f4716856722d56bd11fdf51ca4cc71c75232b9d2ddb7dc6b1759839e1f7
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely