Malicious RTF — malware analysis report

Static analysis result for SHA-256 fb3b60b718d32c99…

MALICIOUS

RTF

821.4 KB Created: 2018-03-31 17:01:00 First seen: 2018-04-12
MD5: ec9cbda30e21f9eff5ccd70d9b299017 SHA-1: 3da00c9755e75686a0a4ee78b465f926a2324e72 SHA-256: fb3b60b718d32c99e8a1397a186ce1fa09a9427142151dff69202c48b38034c2
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and uses \objupdate to force activation, indicating an attempt to exploit vulnerabilities. Specifically, the CVE-2017-8759 heuristic firing points to exploitation of MSXML SAX OLE activation. This suggests the file is designed to download and execute a secondary payload, likely delivered via a spearphishing attachment.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.m In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002cbb.bin rtf-objdata-decoded RTF \objdata at offset 0x2CBB 27707 bytes
SHA-256: 5e926bef41d7051a3b7afd7b3f78fbfbf85e49013fbf2512b8c7ef67f135abbc
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off000164ec.bin rtf-objdata-decoded RTF \objdata at offset 0x164EC 27707 bytes
SHA-256: 3c15b57d863832fcf0f037b65044e70d2729a49d53c4982eec9cb4cc490b136e
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00029d1d.bin rtf-objdata-decoded RTF \objdata at offset 0x29D1D 27707 bytes
SHA-256: 513b550072e8d60181ee922d8078b4f4202a0343d61d7e77a48b57a486669a6b
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off0003d54e.bin rtf-objdata-decoded RTF \objdata at offset 0x3D54E 27707 bytes
SHA-256: faf6ea9ab896ceaee64f0cca372d5b503ad60ff4703cc58290f21994b5bb6c42
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off00050d7f.bin rtf-objdata-decoded RTF \objdata at offset 0x50D7F 27707 bytes
SHA-256: e3a2b651a35fa0ae30dd8aa47fd4967e6df886b5886ad39098ee3c0727221602
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off000645fa.bin rtf-objdata-decoded RTF \objdata at offset 0x645FA 27707 bytes
SHA-256: 334dab1bb428ac02c4f31ab6e34bccc35f88dc946b37af89d3d2272369b0aa9f
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off00077e2b.bin rtf-objdata-decoded RTF \objdata at offset 0x77E2B 27707 bytes
SHA-256: 88aa5c2f23189ff083f6e7b324ecf943659ecff35295dfda8493c0ccc3427faa
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off0008b65c.bin rtf-objdata-decoded RTF \objdata at offset 0x8B65C 27707 bytes
SHA-256: 8aaf1185b0b73f1630b29a496020925e2e817c10286064943252ffb9e35f6abc
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off0009ee8d.bin rtf-objdata-decoded RTF \objdata at offset 0x9EE8D 27707 bytes
SHA-256: a6aa240092157a99ffc79799997786b0a5d60938c0577090df925370fada995f
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off000b26be.bin rtf-objdata-decoded RTF \objdata at offset 0xB26BE 27707 bytes
SHA-256: 579a151312a61d7a6830586d05237c42bfa2e22570ca6800a55ab50ac0c6c6ec
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely