Malicious RTF — malware analysis report

Static analysis result for SHA-256 ee4cf851fa456a15…

MALICIOUS

RTF

918.5 KB Created: 2018-05-07 01:58:00 First seen: 2018-07-23
MD5: 667926c15c1a70cd56521d24e75532c7 SHA-1: bba3dee18c870054bd651f21f416ebf13f5b6512 SHA-256: ee4cf851fa456a15f289dcb8a97122b4dfe7419d0618205ec03fd03b2e033e11
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 9

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c0a.bin rtf-objdata-decoded RTF \objdata at offset 0x2C0A 33339 bytes
SHA-256: cfc391b642f4756b20f3c7bb7f26e972f76ed8bd4125ae3d84588a532bd380d6
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018b22.bin rtf-objdata-decoded RTF \objdata at offset 0x18B22 33339 bytes
SHA-256: 20440e2efa0534625023ea477f1e59e963475daf1ce7637b44c5d9bba8564438
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002ea3a.bin rtf-objdata-decoded RTF \objdata at offset 0x2EA3A 33339 bytes
SHA-256: 15f989fd2e1c0617b5917e0a3c7c59a6c9d149a89c19dc755426dfccec485715
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00044952.bin rtf-objdata-decoded RTF \objdata at offset 0x44952 33339 bytes
SHA-256: a29742e9dcdeacea6e0a93fff580d9cd2278a6d52ccbd6a9be0378e07a734d12
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a86a.bin rtf-objdata-decoded RTF \objdata at offset 0x5A86A 33339 bytes
SHA-256: 9f8504a172ace13cf00d0d76d8237e8efa9e9b12d07b0d6d20cb4b663f343703
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000707cc.bin rtf-objdata-decoded RTF \objdata at offset 0x707CC 33339 bytes
SHA-256: ca222c8ef6c1baf79edf85d00c5d708984bdb8a86bcdf8eccb69f7e9e5adf2c0
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0009c5fc.bin rtf-objdata-decoded RTF \objdata at offset 0x9C5FC 33339 bytes
SHA-256: 42e05886f71da17689a7426782735a409341f5cf16f75b29070b04131c9a2877
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b2514.bin rtf-objdata-decoded RTF \objdata at offset 0xB2514 33339 bytes
SHA-256: e8ef1bc5f8df2b7e1018594a448f69c3c91384e6ddef12e853160a0dbc650b4e
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c842c.bin rtf-objdata-decoded RTF \objdata at offset 0xC842C 33339 bytes
SHA-256: 73371ea85f14849ad20b6f5a4ac421c32c63a02088d6fbd06df85137f58553f5
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely