Malicious RTF — malware analysis report

Static analysis result for SHA-256 fdd95d571b70dfc1…

MALICIOUS

RTF

705.7 KB Created: 2018-02-07 19:26:00 First seen: 2018-02-19
MD5: 02640462c27a1578060b59bd9b410512 SHA-1: f7c8c4fb562e55085a4fabc09d622dc2894560f7 SHA-256: fdd95d571b70dfc19e9988c7525c95e496ce79d1aef4262a913cde2f2f2935a2
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Xls.Malware.Valyria-6934880-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Valyria-6934880-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000029ea.bin rtf-objdata-decoded RTF \objdata at offset 0x29EA 22587 bytes
SHA-256: eeb991cca1666b4e422e01006a3fb704ee64ffe130df4889ba6de6f949c799cb
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_01_off0001358e.bin rtf-objdata-decoded RTF \objdata at offset 0x1358E 22587 bytes
SHA-256: 5ba1eedc8604c3aedb9af2a2bf8ec157d1908ce7185cbc525b2c1462b3c0a0cb
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_02_off000240a9.bin rtf-objdata-decoded RTF \objdata at offset 0x240A9 22587 bytes
SHA-256: 7bac17651f855cc0292d4c981438f56e6ef5fce43bc16f45811b27f5d07c6ef7
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_03_off00034bc6.bin rtf-objdata-decoded RTF \objdata at offset 0x34BC6 22587 bytes
SHA-256: 52af0da331a6fa3386b205466ef3747b35d1a7bfc7fb039d2b8d24158819c4c1
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_04_off0004572d.bin rtf-objdata-decoded RTF \objdata at offset 0x4572D 22587 bytes
SHA-256: 808b508ca64553dfcc057841f0521a4d6d64ed39c3ca003c782a4d9cb163aa28
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_05_off0005624a.bin rtf-objdata-decoded RTF \objdata at offset 0x5624A 22587 bytes
SHA-256: e87c497f5b0479f09e5c9b0013402c3dbe6057af1aa14d01e3a0bfd6676bb0a7
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_06_off00066d67.bin rtf-objdata-decoded RTF \objdata at offset 0x66D67 22587 bytes
SHA-256: a9a97c4b0925b084c1b170d2af4b7e5f40f5d57d59605cba3c80c7e2c1bb7cf6
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_07_off00077884.bin rtf-objdata-decoded RTF \objdata at offset 0x77884 22587 bytes
SHA-256: 035fd27c3397fcd22868870934e2efa1a2856e5c67fcb63237c9c828e0c39218
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_08_off000883a1.bin rtf-objdata-decoded RTF \objdata at offset 0x883A1 22587 bytes
SHA-256: 5d43b83f4b1db7ab37006a86efbe71364c935e00b3c00b8b31d65d34d225cb37
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely
objdata_09_off00098ebe.bin rtf-objdata-decoded RTF \objdata at offset 0x98EBE 22587 bytes
SHA-256: c2449d9808523221863337b6f233c1d7ed724a3e74111643453d7fdb8355fca1
Detection
ClamAV: Xls.Malware.Valyria-6934880-0
Obfuscation or payload: unlikely