Malicious RTF — malware analysis report

Static analysis result for SHA-256 ec76289ea3883475…

MALICIOUS

RTF

841.4 KB Created: 2018-03-22 First seen: 2018-03-30
MD5: 13b40a0ab93b784ef29a01f3edb3dd6a SHA-1: daad1c312b0fc835a9942ad00a98fa104ea7ec3b SHA-256: ec76289ea388347501f2e95c2caaa0cbaea0c670eea9449dc42f6ceeaf462468
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Xls.Downloader.Generic-6750544-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Generic-6750544-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c40.bin rtf-objdata-decoded RTF \objdata at offset 0x2C40 28731 bytes
SHA-256: e594f063f08a9173eb7854003c8897b39e10ddc580d3ce1a59a1fc8544ada45b
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_01_off00016c81.bin rtf-objdata-decoded RTF \objdata at offset 0x16C81 28731 bytes
SHA-256: e4f44646e88905bb6e2f0923ac350ebaa0c8457e7d5afad7c0ef1d2619119244
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_02_off0002acc2.bin rtf-objdata-decoded RTF \objdata at offset 0x2ACC2 28731 bytes
SHA-256: 0297311fed0913d3b6f571afe0dd89f9bd97b495bd442035f38f65b544650f92
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_03_off0003ed03.bin rtf-objdata-decoded RTF \objdata at offset 0x3ED03 28731 bytes
SHA-256: f403be176d28c5e17fe8b32cc1637205d39c847fd373fd88b0479aa0bf03b2a1
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_04_off00052d44.bin rtf-objdata-decoded RTF \objdata at offset 0x52D44 28731 bytes
SHA-256: 51f0652d629c4ceccf19c6690ea4423c451e4732caa8877f0556915350a0c5e0
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_05_off00066dcf.bin rtf-objdata-decoded RTF \objdata at offset 0x66DCF 28731 bytes
SHA-256: f0cb283ae7b9415b24daa415bdbc0bf51377a5b727426404c148bf49a4cb2e64
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_06_off0007ae10.bin rtf-objdata-decoded RTF \objdata at offset 0x7AE10 28731 bytes
SHA-256: 7dfc6e32435b81bdedfe76a82c1488b814e7fb4db6b37df2e8aef806b817cdee
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_07_off0008ee51.bin rtf-objdata-decoded RTF \objdata at offset 0x8EE51 28731 bytes
SHA-256: 4ac4d9ae4990f3b9f30e6a2c70bd8d53450f91f36f6bbba73c851439252ea1fb
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_08_off000a2e92.bin rtf-objdata-decoded RTF \objdata at offset 0xA2E92 28731 bytes
SHA-256: a07836369400048324d0a930a4d8d9ae27f2b30b43b8b489430b0ac75b14ce50
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely
objdata_09_off000b6ed3.bin rtf-objdata-decoded RTF \objdata at offset 0xB6ED3 28731 bytes
SHA-256: 6a389aba856042bcbcaad475a9527379e0c6f9f3ab65faa71d097ebaa9a73cfb
Detection
ClamAV: Xls.Downloader.Generic-6750544-0
Obfuscation or payload: unlikely