Malicious RTF — malware analysis report

Static analysis result for SHA-256 af20f3799d73fb3d…

MALICIOUS

RTF

818.9 KB Created: 2018-03-31 16:53:00 First seen: 2018-04-12
MD5: 4147b9d3f947f2b4a26b44cbadc4a317 SHA-1: 950d31a45bf098e04ddd0946abc5c74fe9d0602d SHA-256: af20f3799d73fb3d7476bc04890a98c4322b70a902c55c8d4d80696114ef9ada
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, indicating an attempt to activate these objects. The critical heuristic firing for CVE-2017-8759 confirms exploitation of this vulnerability, which is commonly used to download and execute arbitrary code. The embedded URL is suspicious and likely part of the exploit chain.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002cba.bin rtf-objdata-decoded RTF \objdata at offset 0x2CBA 28219 bytes
SHA-256: 9213c1165a1c02635f0bfcacee241f52fd481ccd104b49e0d7c914c6f4e18aef
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off000163f3.bin rtf-objdata-decoded RTF \objdata at offset 0x163F3 28219 bytes
SHA-256: 4fbfc6bd88f98d7f9f8fd775d0fe83619dcb5e925764c22db8d9d85ebb9881fe
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00029b2c.bin rtf-objdata-decoded RTF \objdata at offset 0x29B2C 28219 bytes
SHA-256: eb8d75d9c467b4bfe24576368a3484f5eacb53c7867561db56b9977f12f04608
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003d265.bin rtf-objdata-decoded RTF \objdata at offset 0x3D265 28219 bytes
SHA-256: c58722fd925274e2163a8d2568bc1cd16ce734ad0d00f5b0602228ed5081bbde
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off0005099e.bin rtf-objdata-decoded RTF \objdata at offset 0x5099E 28219 bytes
SHA-256: 5494a29ec21c3229d7b32851b372406e9407dc9257cb4a9941a54f202fd82fb6
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off00064121.bin rtf-objdata-decoded RTF \objdata at offset 0x64121 28219 bytes
SHA-256: e6a005d60470ad217383d04a9245c7fe6bb03d0a5455be8b1d0c9fb682c1c448
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off0007785a.bin rtf-objdata-decoded RTF \objdata at offset 0x7785A 28219 bytes
SHA-256: 13de9bfd4580e3d4312123a32fb540d5dc83bddcc1980bdc17e39290ee191b0c
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008af93.bin rtf-objdata-decoded RTF \objdata at offset 0x8AF93 28219 bytes
SHA-256: 2d00ec7afb8173b1c685bfc19bff42254791140b031e50b1992cec33d0ba99e9
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off0009e6cc.bin rtf-objdata-decoded RTF \objdata at offset 0x9E6CC 28219 bytes
SHA-256: 84ecc0cd7a7d54934af55f944ff2d65314db1e6707603512ebf4fde5a29a895d
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b1e05.bin rtf-objdata-decoded RTF \objdata at offset 0xB1E05 28219 bytes
SHA-256: 5046d2481d8b4d89bacdc9fe250896bb8a2335c8d95fac60c59ae817681731fa
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely