Malicious RTF — malware analysis report

Static analysis result for SHA-256 e76f44c18318a50c…

MALICIOUS

RTF

977.5 KB Created: 2018-03-31 16:42:00 First seen: 2018-04-12
MD5: a9298d47c5621b9be12878e2a22f7622 SHA-1: 2eae8dd83bb1dfa47880513e1fe3e9ddd2c52134 SHA-256: e76f44c18318a50ca93f6745af546d6a3571cd00bc2f73085f04fc53c27e8cea
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 12 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 12

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c4f.bin rtf-objdata-decoded RTF \objdata at offset 0x2C4F 27707 bytes
SHA-256: b820528ec89dd8b048136ae0486f00c2acee00a1f4ef7b41a2afd683191f264d
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off00016486.bin rtf-objdata-decoded RTF \objdata at offset 0x16486 27707 bytes
SHA-256: abdbd5e81fc18be21239fcf8a21bdc7c2f95d1767b443e319afb79d90ee49e46
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00029cbd.bin rtf-objdata-decoded RTF \objdata at offset 0x29CBD 27707 bytes
SHA-256: cc90243ede5cb8045fdc6665a15dd6c9d07fbb81c50b67d3036ac397338a5b8c
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003d4f4.bin rtf-objdata-decoded RTF \objdata at offset 0x3D4F4 27707 bytes
SHA-256: 4152e34c1f0fd8837313ed9af8d23f66b88d1688ae86877414a11c99449806ef
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off00050d77.bin rtf-objdata-decoded RTF \objdata at offset 0x50D77 27707 bytes
SHA-256: d3a4bd7f2d0e673d0f6936aa4c2e81b7f21fec80346c5c5963ed68fbe4131261
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off000645ae.bin rtf-objdata-decoded RTF \objdata at offset 0x645AE 27707 bytes
SHA-256: 1f30406e812991f802354fecc355e8b26a4a8be930ec005f9a84b6bee13c0224
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off00077de5.bin rtf-objdata-decoded RTF \objdata at offset 0x77DE5 27707 bytes
SHA-256: 945be8acd6e4546ee81f2c1284349ef56620dd82208dc7cb7e9c26c425a8d849
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008b61c.bin rtf-objdata-decoded RTF \objdata at offset 0x8B61C 27707 bytes
SHA-256: d9a4b2f12bf4b92bbf821f64dbda3fd0c68229e9111c2df7bd7470d9f78c0bc2
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off0009ee9f.bin rtf-objdata-decoded RTF \objdata at offset 0x9EE9F 27707 bytes
SHA-256: b046dd939b923b220f91657164590332f3afd01a7c55bb295b843b1c984b30df
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b26d6.bin rtf-objdata-decoded RTF \objdata at offset 0xB26D6 27707 bytes
SHA-256: 5ed756f091b9792398b2ecc2a5580fdf211b13c942f2c299de4fa54c6a8bc18d
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_10_off000c5f0d.bin rtf-objdata-decoded RTF \objdata at offset 0xC5F0D 27707 bytes
SHA-256: 3612bc0fac089970b9816d21c4b180c4172a1b7d6f94e4bc47992a91a0c554d0
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_11_off000d9744.bin rtf-objdata-decoded RTF \objdata at offset 0xD9744 27707 bytes
SHA-256: 9df7ffe74bf275156801cd98a16339f552cae69325a5457c825cf6cb387088c5
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely