Malicious RTF — malware analysis report

Static analysis result for SHA-256 c8e1630cb3e2fc63…

MALICIOUS

RTF

918.5 KB Created: 2018-05-07 02:37:00 First seen: 2018-07-14
MD5: 5fdd42eb4999b5be57f7494bedcab7d0 SHA-1: be598977da7cb31d921b0d1dd63531f01443a262 SHA-256: c8e1630cb3e2fc633f93321b5089bec7398be1c1b3e8e6624ffb26a29dbac126
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c19.bin rtf-objdata-decoded RTF \objdata at offset 0x2C19 33339 bytes
SHA-256: dfd2e11fe75bb4f8c35324ea44909ae7ae97eade014fcceabde8e9b9f4ec00c9
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018b35.bin rtf-objdata-decoded RTF \objdata at offset 0x18B35 33339 bytes
SHA-256: 47c83bfc9d5ef4a8bcb2c0a365997d48a7a31c9c604b974de18c95a28279b6bd
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002ea51.bin rtf-objdata-decoded RTF \objdata at offset 0x2EA51 33339 bytes
SHA-256: c2f83be21d6945276eabd4ba7f1e3a98b7731c647f33ae4fc58d2e9b2a931280
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off0004496d.bin rtf-objdata-decoded RTF \objdata at offset 0x4496D 33339 bytes
SHA-256: b21aff092913cd399533344f4f6b79be974b99022371057a010119e120f6a763
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a889.bin rtf-objdata-decoded RTF \objdata at offset 0x5A889 33339 bytes
SHA-256: 9c40e505c5f8819a4ddfb7719850eae4a5bf8076f394404f66283dfa3582dd1b
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000707f1.bin rtf-objdata-decoded RTF \objdata at offset 0x707F1 33339 bytes
SHA-256: 4cd496761e877c5a2bed86191581ac4c67f0430ae13cd3665678eb7906773c5d
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0008670d.bin rtf-objdata-decoded RTF \objdata at offset 0x8670D 33339 bytes
SHA-256: 81348c6ae14f91719d73632b41d452cb3094fe19ef7ec4cc06c0cdae007b352d
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0009c629.bin rtf-objdata-decoded RTF \objdata at offset 0x9C629 33339 bytes
SHA-256: b8bd9963b1672c6ac47b1a3d598282ee844032cd575b8a704830f2892f6c1317
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b2545.bin rtf-objdata-decoded RTF \objdata at offset 0xB2545 33339 bytes
SHA-256: 1e9fb6c32c79c6ed2cc9b25b6d8ef05e25fbc5b0da13f932a8536543b6dadedf
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c8461.bin rtf-objdata-decoded RTF \objdata at offset 0xC8461 33339 bytes
SHA-256: 3b8567151fdfce88c58976703875c6ab8b53562380bc30151d107289c72f9436
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely