Malicious RTF — malware analysis report

Static analysis result for SHA-256 ff870fbe4f8bdf41…

MALICIOUS

RTF

750.7 KB Created: 2018-05-02 19:49:00 First seen: 2019-08-04
MD5: 9a5fa7aa46489573736c3951e0845b10 SHA-1: f77568aec3db309ad399f0e8763532eb41c2cc80 SHA-256: ff870fbe4f8bdf4152f835fca16151f5c9b9b1ee72adf39cfe4d7093e530ae3b
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains multiple embedded OLE objects and triggers an ".objupdate" command, which is indicative of exploiting vulnerabilities like CVE-2017-8759 for client execution. ClamAV detections further confirm its malicious nature, flagging it as Doc.Macro.Obfuscation. The primary attack vector is likely spearphishing attachment, with the embedded OLE object serving as the mechanism to download and execute a secondary payload.

Heuristics 6

  • CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759
    RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
  • ClamAV: Doc.Dropper.Agent-6412232-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6412232-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c47.bin rtf-objdata-decoded RTF \objdata at offset 0x2C47 24123 bytes
SHA-256: b2718ddd29bfa5e4d3fadcf3830c90836e855120093e815a94e1873113beeea3
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_01_off0001483e.bin rtf-objdata-decoded RTF \objdata at offset 0x1483E 24123 bytes
SHA-256: 990ddbf9599bc5d1c5bfc90ec7f9067519fb91d59a01a9c594af8bc1baed9ab9
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_02_off00026435.bin rtf-objdata-decoded RTF \objdata at offset 0x26435 24123 bytes
SHA-256: 5fd30b79d680b97a266a69a671a86b1dc161db246c67d79aec5c7939428d5dfa
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_03_off0003802c.bin rtf-objdata-decoded RTF \objdata at offset 0x3802C 24123 bytes
SHA-256: 5d326bd7d2d106b0ff614d79fad27b659bd6c37f6651456c70a28b5ad1eb7d2e
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_04_off00049c23.bin rtf-objdata-decoded RTF \objdata at offset 0x49C23 24123 bytes
SHA-256: 9b3bcbdd415890251a390dcea16c120adff05fc30ccb7b1af38572126775dcf6
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_05_off0005b864.bin rtf-objdata-decoded RTF \objdata at offset 0x5B864 24123 bytes
SHA-256: b1c2f823c0a77cb1f98c19e22ddddf9c24152bf072df0345de1b16f97e70e3d8
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_06_off0006d45b.bin rtf-objdata-decoded RTF \objdata at offset 0x6D45B 24123 bytes
SHA-256: 3e9b4ee4318a097362810ba26827c10ea7092c5edcf443c6ab26db141bafeb07
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_07_off0007f052.bin rtf-objdata-decoded RTF \objdata at offset 0x7F052 24123 bytes
SHA-256: b16da9cfd6c7fb33aa9347281afc6478c5ea44ddfe2589a55d737d50f6573326
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_08_off00090c49.bin rtf-objdata-decoded RTF \objdata at offset 0x90C49 24123 bytes
SHA-256: a64d07206deff8a9daf527430422a850ccc12d64203a5c83dfc8499df9519f51
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely
objdata_09_off000a2840.bin rtf-objdata-decoded RTF \objdata at offset 0xA2840 24123 bytes
SHA-256: ecf01ba4f195e25358190ec5ed2bfc29dd2028e01db8ecaddcc6f3e6cb62bd6e
Detection
ClamAV: Doc.Dropper.Agent-6412232-1
Obfuscation or payload: unlikely