Xls.Dropper.Agent-7670065-0 — RTF malware analysis

Static analysis result for SHA-256 e6b88bb1df2d2c4b…

MALICIOUS

RTF

1.07 MB Created: 2020-03-30 06:29:00 First seen: 2020-07-24
MD5: 61767aeffc3b4f629eaa233162f0e2eb SHA-1: 81cb0db2fd10fac619b314beb5914a1c47db5b76 SHA-256: e6b88bb1df2d2c4bbda37e4391d1bb6a94757ce6e5ae9920a3217e67d78d8700
282 Risk Score

Malware Insights

Xls.Dropper.Agent-7670065-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and uses \objupdate to force activation, indicating an attempt to exploit vulnerabilities. The critical finding of CVE-2017-8759 confirms exploitation for client execution. ClamAV detection as 'Xls.Dropper.Agent-7670065-0' suggests a dropper functionality, likely to download and execute a secondary payload.

Heuristics 8

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Xls.Dropper.Agent-7670065-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.Agent-7670065-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • Large hex data blocks in OLE object high RTF_EXCESSIVE_HEX
    RTF contains ~1058KB of hex-encoded data inside \objdata sections — may hide a payload
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • OLE object data medium RTF_OBJDATA
    RTF contains 13 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 13

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002cb7.bin rtf-objdata-decoded RTF \objdata at offset 0x2CB7 39470 bytes
SHA-256: bf164cd793371274953c73c5d20ca2e241fef7d4a8e82267e9f4dc24685bed82
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_01_off00016f86.bin rtf-objdata-decoded RTF \objdata at offset 0x16F86 39470 bytes
SHA-256: d7254cf13f0333fe371afd4ea81391741f30b08d6204909ec54cb204acb2ed69
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_02_off0002b35c.bin rtf-objdata-decoded RTF \objdata at offset 0x2B35C 39470 bytes
SHA-256: 27c5b1ed11aea1a88b9c894ff6809635b0b7ccb1b220c37c39635a495052cd25
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_03_off0003f732.bin rtf-objdata-decoded RTF \objdata at offset 0x3F732 39470 bytes
SHA-256: bdc6ce986f20645c3ba39c51743afef322682c030cfcc98518821e33306ba72a
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_04_off00053b08.bin rtf-objdata-decoded RTF \objdata at offset 0x53B08 39470 bytes
SHA-256: 227f788792a18347682a82814ad2618c524d1dc96085b35443091fa7338915b9
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_05_off00067ede.bin rtf-objdata-decoded RTF \objdata at offset 0x67EDE 39470 bytes
SHA-256: 64e3b61b978cf3cc9fe67238ce6e01b1ab5d3036a9432cd59e086291c5452e81
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_06_off0007c2b4.bin rtf-objdata-decoded RTF \objdata at offset 0x7C2B4 39470 bytes
SHA-256: 084658ed1b025044a725c6cefe0d3834df5808f414ed247fe23b6a44b9b539c8
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_07_off0009068a.bin rtf-objdata-decoded RTF \objdata at offset 0x9068A 39470 bytes
SHA-256: 8ccd7c11450bc3387a8bb09c43fd69b88902c90ad0f0b381502f19874ace094e
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_08_off000a4a60.bin rtf-objdata-decoded RTF \objdata at offset 0xA4A60 39470 bytes
SHA-256: b47048f52dac200d9c0a4f3f6b92abee90ae783727b4f30a00f5fa12c7b1e7e4
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_09_off000b8e36.bin rtf-objdata-decoded RTF \objdata at offset 0xB8E36 39470 bytes
SHA-256: b1d118b853b5d19f4018fc074a666297053f225783d2fda7077a129340d3d5bb
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_10_off000cd20c.bin rtf-objdata-decoded RTF \objdata at offset 0xCD20C 39470 bytes
SHA-256: 9391dc96e49dc5d46f72e8d159dabc7d4e455196509291937f0b330821af9ed3
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_11_off000e15e2.bin rtf-objdata-decoded RTF \objdata at offset 0xE15E2 39470 bytes
SHA-256: 2f94dc3942aa9d1f9586b5ac62f79243cd8d2f5a07e15409453ce19301d04199
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
objdata_12_off000f59b8.bin rtf-objdata-decoded RTF \objdata at offset 0xF59B8 39470 bytes
SHA-256: 80cd1b617f22d0640136a21539a66ca7e54b3e4caff869fd7c93f55fb006aced
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.