Malicious RTF — malware analysis report

Static analysis result for SHA-256 f1b58fd2bc8695ef…

MALICIOUS

RTF

737.1 KB Created: 2018-04-27 01:27:00 First seen: 2018-06-21
MD5: 7740cde53f28464f220fc6d7baebdf26 SHA-1: a1fb18de3bb3ecbd46d81c02a9ae664034c9e6a3 SHA-256: f1b58fd2bc8695effcabe8df9389eaa8c1f51cf4ec38737e4fbc777874b6e752
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c1c.bin rtf-objdata-decoded RTF \objdata at offset 0x2C1C 24123 bytes
SHA-256: 5932ec13d6cb7068482ca7d50c113ceb71d6e04704d6e58707d2381910b366ad
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off000142a6.bin rtf-objdata-decoded RTF \objdata at offset 0x142A6 24123 bytes
SHA-256: 0557096db17b7339f563271ffb78c4712f127c5732d35d626a17fe2561a87d4f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00025930.bin rtf-objdata-decoded RTF \objdata at offset 0x25930 24123 bytes
SHA-256: 423ed45e1fc9d271d9a1a995aea6bfb7086a8a851885c31624826dd33d24c1f3
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00036fba.bin rtf-objdata-decoded RTF \objdata at offset 0x36FBA 24123 bytes
SHA-256: 29d883796628cd9f0c42d98556d1786975391a7b0846628d3ce6f613873027be
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00048644.bin rtf-objdata-decoded RTF \objdata at offset 0x48644 24123 bytes
SHA-256: 0315e690dea1d7577cf541e115307b16b40401b1afbe6970279123dabc539f22
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off00059d1a.bin rtf-objdata-decoded RTF \objdata at offset 0x59D1A 24123 bytes
SHA-256: 36b17f4158f97c338ae22b498c6120004f1decef9423561442710035dc63df70
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006b3a4.bin rtf-objdata-decoded RTF \objdata at offset 0x6B3A4 24123 bytes
SHA-256: 1513d778d8de8a36c5ec37cb7e9f37222ffc9b91027ad08db3b3bc550adf3fed
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007ca2e.bin rtf-objdata-decoded RTF \objdata at offset 0x7CA2E 24123 bytes
SHA-256: 7c5d7fa1ff686d7056a4b752985bb1f3662623b9f4d44cf71d8451ca4a52b08e
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off0008e0b8.bin rtf-objdata-decoded RTF \objdata at offset 0x8E0B8 24123 bytes
SHA-256: cc43173f44a42cbcab7b79699a1d1e0d27a076c2ae2bb591943330a110dba79a
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off0009f742.bin rtf-objdata-decoded RTF \objdata at offset 0x9F742 24123 bytes
SHA-256: c8aaf8b37956882640023554b841ca4ba722e0bca3a2e7358008dd6adde158ff
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely