Malicious RTF — malware analysis report

Static analysis result for SHA-256 f7fd959aba06811d…

MALICIOUS

RTF

918.5 KB Created: 2018-05-10 15:31:00 First seen: 2018-06-14
MD5: 4037f4b612bee8377a8b6c5d854fd9d1 SHA-1: e2986e6376a9d806b305967fce5047b38dee7b12 SHA-256: f7fd959aba06811db16e1f2846f844af05bedd51d9e35848e4097b6692a3a57a
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c18.bin rtf-objdata-decoded RTF \objdata at offset 0x2C18 33339 bytes
SHA-256: 856e189de8c5dc5cf0cfe8f2e7e4e1e2ed757973d927a505060d0f4ea5661bb1
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off00018b30.bin rtf-objdata-decoded RTF \objdata at offset 0x18B30 33339 bytes
SHA-256: 5b4a06c8d11f1da83aa7ac63edc28e5244b38cb7d6ccb22c41ab1dab39e66c9a
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off0002ea48.bin rtf-objdata-decoded RTF \objdata at offset 0x2EA48 33339 bytes
SHA-256: 92683a6fe930240f5af17cf858d10f9e47556259c0881d026ed2214c2ebc762f
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00044960.bin rtf-objdata-decoded RTF \objdata at offset 0x44960 33339 bytes
SHA-256: 18fb85d15806e3fc8fadcee5c4b998b736576f5b96603554202b1bf2c5dd6c32
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off0005a878.bin rtf-objdata-decoded RTF \objdata at offset 0x5A878 33339 bytes
SHA-256: 8fc36057f87aa39fedfd693d2d0ac332d0a748b75a99359330061d40930814db
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off000707da.bin rtf-objdata-decoded RTF \objdata at offset 0x707DA 33339 bytes
SHA-256: 27141037290ebd292ec09ff4261f24270119f45cea35b36cf45fc12a416095d9
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off000866f2.bin rtf-objdata-decoded RTF \objdata at offset 0x866F2 33339 bytes
SHA-256: cf2553b89b7647ffc843a3f96d6ad58aa9ebafa71467ea8205bff6bdea68ed10
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0009c60a.bin rtf-objdata-decoded RTF \objdata at offset 0x9C60A 33339 bytes
SHA-256: f22e49ff5aa33ceacb0e2ac719310ce09b466d44685a9fbbff1152712ad4c4f1
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off000b2522.bin rtf-objdata-decoded RTF \objdata at offset 0xB2522 33339 bytes
SHA-256: 4ee31483e961998ec12b8c52e4d50c1ce746d549477999a9b0d58aca672ec163
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000c843a.bin rtf-objdata-decoded RTF \objdata at offset 0xC843A 33339 bytes
SHA-256: e9ff86889208c70dfc46b89b4eea83b5a2229b09d27f998fd101c4a3792cedfd
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely