Doc.Dropper.Agent-6547889-0 — RTF malware analysis

Static analysis result for SHA-256 fc4ebeaaed5e7080…

MALICIOUS

RTF

756.8 KB Created: 2018-04-22 04:18:00 First seen: 2018-07-18
MD5: 512301b4f2efd32eaf60a8cdf52b809e SHA-1: e1f2ef714e19b450793a754b54e66166b4f123a1 SHA-256: fc4ebeaaed5e70806b7025ff2aff6df3ab54405d80bf6731f38cc1dd3a3981eb
262 Risk Score

Malware Insights

Doc.Dropper.Agent-6547889-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, indicating an attempt to activate them. The critical heuristic firing for CVE-2017-8759 confirms exploitation of this vulnerability via MSXML SAX OLE activation. ClamAV detection as 'Doc.Dropper.Agent-6547889-0' further supports its malicious nature as a dropper. The embedded OLE object is likely used to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6547889-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6547889-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c44.bin rtf-objdata-decoded RTF \objdata at offset 0x2C44 21051 bytes
SHA-256: 2a5be55e87fb11d128006e80d670b5c02b4c564009a7dbd9d44ca166d2fc1f05
Detection
ClamAV: Doc.Dropper.Agent-6547889-0
Obfuscation or payload: unlikely
objdata_01_off00012bb6.bin rtf-objdata-decoded RTF \objdata at offset 0x12BB6 21051 bytes
SHA-256: 1bbc1a730e5b2645c3ad310e8613b75040d87992eeff942c734e854ab79852e4
Detection
ClamAV: Doc.Dropper.Agent-6547889-0
Obfuscation or payload: unlikely
objdata_02_off00022b28.bin rtf-objdata-decoded RTF \objdata at offset 0x22B28 21051 bytes
SHA-256: d9bf0c38377e6db0b7d350ebf04ab2a6ca121271ba0a1c21806bdf8791b147d2
Detection
ClamAV: Doc.Dropper.Agent-6547889-0
Obfuscation or payload: unlikely
objdata_03_off00032a9a.bin rtf-objdata-decoded RTF \objdata at offset 0x32A9A 21051 bytes
SHA-256: d923197838db6e55f30b89c5e2e6064a62e708ad3525ff7acc9cf0ee4fde4469
Detection
ClamAV: Doc.Dropper.Agent-6547889-0
Obfuscation or payload: unlikely
objdata_04_off00042a0c.bin rtf-objdata-decoded RTF \objdata at offset 0x42A0C 21051 bytes
SHA-256: a3578899e818ef93cd14dfd8a18005d983a269eaf379cbb79df40da0164750c1
Detection
ClamAV: Doc.Dropper.Agent-6547889-0
Obfuscation or payload: unlikely
objdata_05_off00052985.bin rtf-objdata-decoded RTF \objdata at offset 0x52985 21051 bytes
SHA-256: 5626611b33c1b58f9e40c68c0bd4ca4aedbef6b0381b3ae437a15c35a6fbce46
Detection
ClamAV: Doc.Dropper.Agent-6547889-0
Obfuscation or payload: unlikely
objdata_06_off000628f7.bin rtf-objdata-decoded RTF \objdata at offset 0x628F7 21051 bytes
SHA-256: 34e2e12bd246cab73dea4f48510f1d2c96f83b817ec058a086eb057ad789603c
Detection
ClamAV: Doc.Dropper.Agent-6547889-0
Obfuscation or payload: unlikely
objdata_07_off00072869.bin rtf-objdata-decoded RTF \objdata at offset 0x72869 21051 bytes
SHA-256: 959b8116969f3aaa6ff6770a521a09d95549a4d6e60a36c785e0ac18a9e47fba
Detection
ClamAV: Doc.Dropper.Agent-6547889-0
Obfuscation or payload: unlikely
objdata_08_off000827db.bin rtf-objdata-decoded RTF \objdata at offset 0x827DB 21051 bytes
SHA-256: e01c8eb5c4056eaa81f88734834657cc6a73f41d856918cd61a8091dbcf6a45d
Detection
ClamAV: Doc.Dropper.Agent-6547889-0
Obfuscation or payload: unlikely
objdata_09_off0009274d.bin rtf-objdata-decoded RTF \objdata at offset 0x9274D 21051 bytes
SHA-256: 9f94a92f6309c4d57e9f3bda32480a5094fb2d87c66da2fd0bbb1216e9ce8725
Detection
ClamAV: Doc.Dropper.Agent-6547889-0
Obfuscation or payload: unlikely