Malicious RTF — malware analysis report

Static analysis result for SHA-256 fde827e292ea3613…

MALICIOUS

RTF

737.1 KB Created: 2018-04-27 01:32:00 First seen: 2019-11-20
MD5: 411e91cab228c3ae34df4aafe8632b6a SHA-1: 7583142406a9416ff28fcef74e61e80941327a28 SHA-256: fde827e292ea3613e8122083ec7590762f5c2aa5e6ba574d067c6a8305a57ae4
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c1c.bin rtf-objdata-decoded RTF \objdata at offset 0x2C1C 24123 bytes
SHA-256: 6608145167fd8233dc7889c57bbee12220988227dcbb3cf4641b0c51eaee2c15
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off000142a6.bin rtf-objdata-decoded RTF \objdata at offset 0x142A6 24123 bytes
SHA-256: 18f3e5c8159142f7415b3f762cc560d348328bcde8fcb3b393393936cfb40505
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00025930.bin rtf-objdata-decoded RTF \objdata at offset 0x25930 24123 bytes
SHA-256: c25e0ddf2f4ae50c90b9c2cffbace6e02085ce75e720d5f4877a0935f7bc2deb
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off00036fba.bin rtf-objdata-decoded RTF \objdata at offset 0x36FBA 24123 bytes
SHA-256: cac9f2244bf3fdc6e4b3c9506c6efa029e7bb2a35870ae26a81d312c152bcd17
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00048644.bin rtf-objdata-decoded RTF \objdata at offset 0x48644 24123 bytes
SHA-256: cde0d9c360c205a93fd804e0f58c4f11883940ec17a77a5377ded2b5d7b26f97
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off00059d1a.bin rtf-objdata-decoded RTF \objdata at offset 0x59D1A 24123 bytes
SHA-256: 5234a609ba97cc7dcfce5e216d248809cbf7ede3df9d174b933c3c6ec82b45ae
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006b3a4.bin rtf-objdata-decoded RTF \objdata at offset 0x6B3A4 24123 bytes
SHA-256: b6b941160a6f228b84179c9991fc4ff4443181e6ab3901c5cbdc0639898ee226
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007ca2e.bin rtf-objdata-decoded RTF \objdata at offset 0x7CA2E 24123 bytes
SHA-256: bab491882c1d718810f4597f2fbf48dd4b940c60910ac6b0b06468830a10e858
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off0008e0b8.bin rtf-objdata-decoded RTF \objdata at offset 0x8E0B8 24123 bytes
SHA-256: 3067f84a512c3c60b618cab88ec778b9bc13f082c497ca8543505ef81e873945
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off0009f742.bin rtf-objdata-decoded RTF \objdata at offset 0x9F742 24123 bytes
SHA-256: 5bc35d9b5e12ae9be57deb2bd97bd7e06ed4d0f3c50e8b5a756ffccba64b656e
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely