Malicious RTF — malware analysis report

Static analysis result for SHA-256 c59f837a48622112…

MALICIOUS

RTF

737.2 KB Created: 2018-05-02 20:59:00 First seen: 2019-08-04
MD5: b31159db905d87586db00863bd20382f SHA-1: 382f37805cd0b8b42e29aea3e22fc668553a36e3 SHA-256: c59f837a48622112654b96c40b52313d00e0a75df94bd60c2de63cfafb4d7060
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c10.bin rtf-objdata-decoded RTF \objdata at offset 0x2C10 24123 bytes
SHA-256: 8dc7cdf4aedf8fc0a16cbe3c73acb878d79b557a9ef9835807199b742dfd8ce7
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off000142a4.bin rtf-objdata-decoded RTF \objdata at offset 0x142A4 24123 bytes
SHA-256: ee930e3c5b210d65a43b72af1259abb36dd1e7be3f6c8b7af66443fff119bb7e
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00025938.bin rtf-objdata-decoded RTF \objdata at offset 0x25938 24123 bytes
SHA-256: 6e8616fa2467ae7d689b639896df44a3351ac53611d5ac3dcdd4a2bc6f78f6c2
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00036fcc.bin rtf-objdata-decoded RTF \objdata at offset 0x36FCC 24123 bytes
SHA-256: 2ed45e164b8e92fc14be92054a5957477e2cfa0955ea81821678e4fef3fff2d1
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00048660.bin rtf-objdata-decoded RTF \objdata at offset 0x48660 24123 bytes
SHA-256: 0b1b9fd0c81aa8904023a78e7d5d51a06020b74680e82e34c6c42024fe3b2c40
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off00059d3e.bin rtf-objdata-decoded RTF \objdata at offset 0x59D3E 24123 bytes
SHA-256: a2d406b2325e64fd80dd81bf4d2b09dca9600ef66bdee6aab32c9f7cc4f521e9
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006b3d2.bin rtf-objdata-decoded RTF \objdata at offset 0x6B3D2 24123 bytes
SHA-256: 536029214bfc76174fc1d76b845cbe96f6e5d9d5dd31ce4962aef0b6fc89f7cb
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007ca66.bin rtf-objdata-decoded RTF \objdata at offset 0x7CA66 24123 bytes
SHA-256: 30a431ea662abe6602dce6433630037fdfde92689ee159faec9d3a17f51a0639
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off0008e0fa.bin rtf-objdata-decoded RTF \objdata at offset 0x8E0FA 24123 bytes
SHA-256: e80e0706d11a240743559040ecb2de52dca2c9b8cd0a18e8bb8ea04b5f3901bd
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off0009f78e.bin rtf-objdata-decoded RTF \objdata at offset 0x9F78E 24123 bytes
SHA-256: a496ffac537424dc8b695cfdd33093255bd831bfbe4b2a6791fab40825595413
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely