Malicious RTF — malware analysis report

Static analysis result for SHA-256 c6853a9265a96366…

MALICIOUS

RTF

737.2 KB Created: 2018-04-27 First seen: 2019-05-10
MD5: ec24eeddebd13cd2911068dfa65a9e29 SHA-1: a9377b22345af61dd8e6b222f5c797d8df4589e0 SHA-256: c6853a9265a96366c867db1240aed4c4bbbd72dbc6bcf0bafa797ead7e20f543
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c14.bin rtf-objdata-decoded RTF \objdata at offset 0x2C14 24123 bytes
SHA-256: 1cd4a4bbde633a87f64ed4a03a6fb37b46cab50e05fc3eb336a706366ce07632
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off000142ac.bin rtf-objdata-decoded RTF \objdata at offset 0x142AC 24123 bytes
SHA-256: 9825cdbee9dc43e904614692a03f650ca62d76b759beeb66f7cd4476eb72b629
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00025944.bin rtf-objdata-decoded RTF \objdata at offset 0x25944 24123 bytes
SHA-256: e9621dba2cef7be8562bcafe926c80783ee66db2a6687a60d95ef21257df3028
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00036fdc.bin rtf-objdata-decoded RTF \objdata at offset 0x36FDC 24123 bytes
SHA-256: 15e2540ea93b39fbb2f7e16bff83c958a279f7d4e94795250754e6ab6ca80e91
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00048674.bin rtf-objdata-decoded RTF \objdata at offset 0x48674 24123 bytes
SHA-256: 0da735202b74780fdd1b429f8e94f5fed3c5d76e16f823e6eecfed3be9cec79b
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off00059d58.bin rtf-objdata-decoded RTF \objdata at offset 0x59D58 24123 bytes
SHA-256: ec4e1cad743467eb4a0524da06844eed7dd81497561edef92a0a28f15bacdbe9
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006b3f0.bin rtf-objdata-decoded RTF \objdata at offset 0x6B3F0 24123 bytes
SHA-256: df63dbe902f4206345d1c7f60d7c347c073fa1838a93b8a779fcde5b9c6af5db
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007ca88.bin rtf-objdata-decoded RTF \objdata at offset 0x7CA88 24123 bytes
SHA-256: c0cd82145bb4df487d16529976a0ebe38753298be0313ecc05e391916ecd8168
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off0008e120.bin rtf-objdata-decoded RTF \objdata at offset 0x8E120 24123 bytes
SHA-256: 56f5109ee3cb98af0596554b210dee15ddaa01604515981a8cd1eb4786040122
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off0009f7b8.bin rtf-objdata-decoded RTF \objdata at offset 0x9F7B8 24123 bytes
SHA-256: 0e747ddc9ba12ee135ef1de99d33f5092eb3ee948ef5dd24f2c9cffeba84bef0
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely