Malicious RTF — malware analysis report

Static analysis result for SHA-256 b9d38a08e7b88894…

MALICIOUS

RTF

776.0 KB Created: 2017-11-10 20:59:00 First seen: 2017-12-24
MD5: feca1d7334250fb9c7aa68b251c2553f SHA-1: 5ac145b53ff39b9e08478cc511d9cadaacbc70f2 SHA-256: b9d38a08e7b888940ad0bafb6032dfe45d4b6cab2f09a734f46d05d718eda57e
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002a81.bin rtf-objdata-decoded RTF \objdata at offset 0x2A81 26171 bytes
SHA-256: 0bf5347b34b910eb459129f1a7998170e24adf2106b8ca329e9ede08ad48da78
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off000150d0.bin rtf-objdata-decoded RTF \objdata at offset 0x150D0 26171 bytes
SHA-256: 39f7c0064d9847888ca31dd8a9f026d9bb15544a5546e1bfa85f9802be2a1c2d
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00027721.bin rtf-objdata-decoded RTF \objdata at offset 0x27721 26171 bytes
SHA-256: bda37f0e55580094fe786b3e304f9684d28b70bdfc28676605cb199e0c047a26
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off00039d72.bin rtf-objdata-decoded RTF \objdata at offset 0x39D72 26171 bytes
SHA-256: f5bd4dc51176e63e075001880c4c6e6b1fe74424e3cf95a0c0a8aeb9279607e3
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off0004c3c3.bin rtf-objdata-decoded RTF \objdata at offset 0x4C3C3 26171 bytes
SHA-256: 9f4418f76741f376470eb0a0cf31a5f620c630f3afe63d487f11d560558275be
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off0005ea14.bin rtf-objdata-decoded RTF \objdata at offset 0x5EA14 26171 bytes
SHA-256: ef786e1bf4c4cc1eb386e95a2cf156d288c29e91f2f32f40dfa88b5730512967
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off00071065.bin rtf-objdata-decoded RTF \objdata at offset 0x71065 26171 bytes
SHA-256: 782e85d65e4c4f3690e4f647844e23a8d93ebe58cfe70d7601175b52dcf03aee
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off000836b6.bin rtf-objdata-decoded RTF \objdata at offset 0x836B6 26171 bytes
SHA-256: dff78588f8a25dfc4382de9cc87cdacdbd25670e8676ce7ef1fad99c9f2aa7a8
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off00095d07.bin rtf-objdata-decoded RTF \objdata at offset 0x95D07 26171 bytes
SHA-256: afbdce01637bc8888827f9e7c7d275b480edb29e8f11e35f195cba18a8e9ff57
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000a8358.bin rtf-objdata-decoded RTF \objdata at offset 0xA8358 26171 bytes
SHA-256: c68064ce4fbcffc176d35b931ee461b583a21e9233899c5b126530e63e6c06c6
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely