Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 178398809f19bf5d…

MALICIOUS

RTF / .DOC

15.3 KB
MD5: ce903a2fd638b5e937312439cf849682 SHA-1: d69ff14d79fc1d0d5345ed3235ccf53d739e3a5d SHA-256: 178398809f19bf5d549dacae50b149b3b1cd22e124a44fed4ed58ef5cbb1fb33
240 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The sample is an RTF document that contains embedded OLE object data, specifically triggering heuristics for CVE-2017-11882 related to the Equation Editor. This indicates exploitation for client execution. The presence of ".objupdate" suggests that the embedded object is designed to be activated automatically, likely to download and execute a secondary payload. No specific family could be identified, but the exploit vector is clear.

Heuristics 5

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • Equation Editor CLSID critical RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • ClamAV: Rtf.Exploit.CVE_2017_11882-6584355-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Exploit.CVE_2017_11882-6584355-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001ab1.bin
f55dd6e628304743e4da6705047f4e6c0513a4be3283b989be8d5d2501684b95
rtf-objdata-decoded RTF \objdata at offset 0x1AB1 4199 bytes