Malicious RTF — malware analysis report

Static analysis result for SHA-256 e7f44f441d092b53…

MALICIOUS

RTF

918.5 KB Created: 2018-05-07 First seen: 2018-07-14
MD5: 5647270ac9078fa9ab9136485c9afe9c SHA-1: 37e870b82500a3692a237624ef90f9f861020b4d SHA-256: e7f44f441d092b5300418a3a49ee15fa7611ea6047f35b8d7b5548cb9a9796ab
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002bff.bin rtf-objdata-decoded RTF \objdata at offset 0x2BFF 33339 bytes
SHA-256: 103bc35b52bf9fa0ecfef33acc8b675910bb2bf5ffbad6fe6ad7f8e56e1f91b1
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018b17.bin rtf-objdata-decoded RTF \objdata at offset 0x18B17 33339 bytes
SHA-256: 187622f272a5881d2cdb871d946363e93a44f093992ed6b11bc1989f23024b88
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002ea2f.bin rtf-objdata-decoded RTF \objdata at offset 0x2EA2F 33339 bytes
SHA-256: 2fe82e564f18fefe40b0d53c5f3ab471c6e8008bdd5c654c1fa9603b2f152ffe
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00044947.bin rtf-objdata-decoded RTF \objdata at offset 0x44947 33339 bytes
SHA-256: fbf7b721d240ebf5044b5943ea3a309ba2433c25494074fbbad54ec63e03c298
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a85f.bin rtf-objdata-decoded RTF \objdata at offset 0x5A85F 33339 bytes
SHA-256: 94b9828cdcf4def31e053c8a22cd3c3eb9daecf4e5a2b1b90889919ca7691b89
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000707c1.bin rtf-objdata-decoded RTF \objdata at offset 0x707C1 33339 bytes
SHA-256: 7e1c201df0acb2794d9fd416a1356f7c22461a06d69138a160c6b5c6ba1a4f7f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off000866d9.bin rtf-objdata-decoded RTF \objdata at offset 0x866D9 33339 bytes
SHA-256: a329be620a8f4905630ca9def98a1662c3c733e293a78b9644e978d22fd12d3f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0009c5f1.bin rtf-objdata-decoded RTF \objdata at offset 0x9C5F1 33339 bytes
SHA-256: 3d52711f59a46290dbcf345583a57b328bf95c8a048886749c7645058e73f93a
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b2509.bin rtf-objdata-decoded RTF \objdata at offset 0xB2509 33339 bytes
SHA-256: 7a5038bc69c1504885aa49d4aac40c78d53554e703d886c1fd3622cce0020f02
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c8421.bin rtf-objdata-decoded RTF \objdata at offset 0xC8421 33339 bytes
SHA-256: b9edb9873301e6535839487d5d0a0a9c71660a679e4fa6429f04277eef64092b
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely