Malicious RTF — malware analysis report

Static analysis result for SHA-256 cf0107e13ae5dad6…

MALICIOUS

RTF

841.5 KB Created: 2018-03-12 22:07:00 First seen: 2018-06-21
MD5: 0854f0f744d3797e38cc07304db68764 SHA-1: 748bf3a7bb840b1f6a3b26ad7de6b46cb8413016 SHA-256: cf0107e13ae5dad6475a7fb9e93dbce830fa2ded1a402db4df6fd6aba8a45a28
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Xls.Downloader.Generic-6750544-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Generic-6750544-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c49.bin rtf-objdata-decoded RTF \objdata at offset 0x2C49 28731 bytes
SHA-256: af3681469bfbd3cc86e58162cafa704a3302820aaa4f91ac90b6f1f18cb6aa8c
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_01_off00016ca8.bin rtf-objdata-decoded RTF \objdata at offset 0x16CA8 28731 bytes
SHA-256: 082413d8505614bfaa39cc527efe85c887365e5973ba91e1aaecd3e4d5667046
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_02_off0002ad07.bin rtf-objdata-decoded RTF \objdata at offset 0x2AD07 28731 bytes
SHA-256: c8c54d03472cb035bbd9a149af579dce5e6636f92fbe2b9481f581931c6373bd
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_03_off0003ed66.bin rtf-objdata-decoded RTF \objdata at offset 0x3ED66 28731 bytes
SHA-256: a17bf6d0d3de91032c6c5bf02f95bf614ec025749e7752b0b1a585b1e61fabe7
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_04_off00052dc5.bin rtf-objdata-decoded RTF \objdata at offset 0x52DC5 28731 bytes
SHA-256: 4fa6bb56e855da5be775d045433b9c24af6b6e8c6b091a9762fead5aa2d50049
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_05_off00066e24.bin rtf-objdata-decoded RTF \objdata at offset 0x66E24 28731 bytes
SHA-256: 13e5d3555fa0e76ee824db64762bbec19782fe60032b726515f98647021a18ab
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_06_off0007ae83.bin rtf-objdata-decoded RTF \objdata at offset 0x7AE83 28731 bytes
SHA-256: bf461a41fcc368832fc322c6ba9eb589c8da5c5486ae9deeb5231bcb447c3bdd
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_07_off0008eee2.bin rtf-objdata-decoded RTF \objdata at offset 0x8EEE2 28731 bytes
SHA-256: 295764d55bdf978761e87c8fa12368acee3811268bdbeb43675febe8f2998a01
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_08_off000a2f41.bin rtf-objdata-decoded RTF \objdata at offset 0xA2F41 28731 bytes
SHA-256: e918944f20d7b8e1733dd72ebda9a4d7eaba28aacc5bdaed34cfafadf1b6ded6
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_09_off000b6fa0.bin rtf-objdata-decoded RTF \objdata at offset 0xB6FA0 28731 bytes
SHA-256: 7a33bf125344dde91cb9e801d4fe0f5cc9ef86ffec57854f2c83682852059dd2
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely