Malicious RTF — malware analysis report

Static analysis result for SHA-256 ca82b92f9d0928ba…

MALICIOUS

RTF

918.5 KB Created: 2018-05-10 15:48:00 First seen: 2019-05-16
MD5: b969e3d84699403c9dd470578ffedef6 SHA-1: 7136c0af877e082a9ee899de347e8cee4eed3157 SHA-256: ca82b92f9d0928ba364dbb2bea0afb283afa46ecab62d575e2284d6962d5a20a
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c1d.bin rtf-objdata-decoded RTF \objdata at offset 0x2C1D 33339 bytes
SHA-256: 6ace55a2c666a32e55cba9f80cfe8d7264b799b6237a2e1ccd3245bebbc39738
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018b39.bin rtf-objdata-decoded RTF \objdata at offset 0x18B39 33339 bytes
SHA-256: 493e35c0cd4ecdbe0f2c220587d4d80e99704f65f83c5b6e84edc49029942fa3
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002ea55.bin rtf-objdata-decoded RTF \objdata at offset 0x2EA55 33339 bytes
SHA-256: d8352a80a339981524a39b017d83b8d5708e9c3f9e4bfacafcd54bbc004313bb
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00044971.bin rtf-objdata-decoded RTF \objdata at offset 0x44971 33339 bytes
SHA-256: b15380d89b14fe61f8bbdbb380902d027a00c22cbc6e67e36a76d03c235b7855
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a88d.bin rtf-objdata-decoded RTF \objdata at offset 0x5A88D 33339 bytes
SHA-256: 3fcaecb8b832958259bff5438aaa261c539a53cced91831c1a1b9389a695a666
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000707f5.bin rtf-objdata-decoded RTF \objdata at offset 0x707F5 33339 bytes
SHA-256: a8c2ed084059f417eebf5073f9b68c389759ead67766ee48a2492a36dde676a9
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off00086711.bin rtf-objdata-decoded RTF \objdata at offset 0x86711 33339 bytes
SHA-256: ac99f145723470f270c0b5508ab62c8f1844e44ec81eefeea24f60063f127cd8
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0009c62d.bin rtf-objdata-decoded RTF \objdata at offset 0x9C62D 33339 bytes
SHA-256: 267e441a7495c0f3657f8e68eb8c105da81efa7436d936688d1c29d79f0533d5
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b2549.bin rtf-objdata-decoded RTF \objdata at offset 0xB2549 33339 bytes
SHA-256: b07d38cf079767e00741669a44930a77819c07409a38ab945a837d7b442a5c54
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c8465.bin rtf-objdata-decoded RTF \objdata at offset 0xC8465 33339 bytes
SHA-256: 15adbcc723e193567f08f0b27a06d8a6b6fec45d7e451fb99d9f88a31d7baef2
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely