Malicious RTF — malware analysis report

Static analysis result for SHA-256 dd42a92f1b553cda…

MALICIOUS

RTF

737.1 KB Created: 2018-05-02 20:13:00 First seen: 2019-09-30
MD5: d1546942574cbe9eb7509067de97236a SHA-1: 9d4954347141b3d992acb9d95ed0fb9ba11e129d SHA-256: dd42a92f1b553cda7925ed20da489094cee8d76b04223124d501f6ecfcbe6261
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c17.bin rtf-objdata-decoded RTF \objdata at offset 0x2C17 24123 bytes
SHA-256: 4e5425dba42173c1d6be14e4a0928fcd55e1c480b390d119757d7e55b0c405a7
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off0001429d.bin rtf-objdata-decoded RTF \objdata at offset 0x1429D 24123 bytes
SHA-256: 965e6868873fc86a1915903b5cd433df709a9ace601737f12e204d825d1add7d
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00025923.bin rtf-objdata-decoded RTF \objdata at offset 0x25923 24123 bytes
SHA-256: efd169297357bcbe32073f6868a18b027b138e69f1974ca6d218fdd91298edb0
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00036fa9.bin rtf-objdata-decoded RTF \objdata at offset 0x36FA9 24123 bytes
SHA-256: 41c4c0209e0c3c13bddc2a60caf47cb827c79f0df431df7f7c58bc689c0d488f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0004862f.bin rtf-objdata-decoded RTF \objdata at offset 0x4862F 24123 bytes
SHA-256: a9434a7e255c4367d31f26984cf122355ca1eaab3e24849ef6a2bc70881e38f9
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off00059cff.bin rtf-objdata-decoded RTF \objdata at offset 0x59CFF 24123 bytes
SHA-256: 7e9e5b2f7b9a03895d2fdc52f6632b983d01342453fe5bcfa7014e0950f7b2fb
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006b385.bin rtf-objdata-decoded RTF \objdata at offset 0x6B385 24123 bytes
SHA-256: 9f3ae2a0fa35d7d85f63ad9a7a501541590dc93e74649f83a4629d856ca440e0
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007ca0b.bin rtf-objdata-decoded RTF \objdata at offset 0x7CA0B 24123 bytes
SHA-256: ebc232bc24960fe7acf06bb8025279beca825bc363ecb998a7351ea2383d5c73
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off0008e091.bin rtf-objdata-decoded RTF \objdata at offset 0x8E091 24123 bytes
SHA-256: 610dcb62ca4503d7feab6e6bcafd19883693772f0a35e94e917ca3a27bd01ba1
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off0009f717.bin rtf-objdata-decoded RTF \objdata at offset 0x9F717 24123 bytes
SHA-256: 12a0e30625ba5a00d50147a794c3d18d02358ae2f7d16ac7efcfb90b9a86dcb8
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely