Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 189b37d77c00cc2f…

MALICIOUS

RTF / .DOC

156.1 KB
MD5: 2c8bbf2131d5f1ba00e0106c7cc567bd SHA-1: 38c7d8b2c54c3a69ed87ebe5252d57d327456807 SHA-256: 189b37d77c00cc2f6dacecc01592158ca4c1d0165ba6cdff063ff14e2c3a283a
120 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The RTF file contains embedded OLE object data and specifically triggers heuristics for the Equation Editor vulnerability and OLE object activation. This indicates the file is designed to exploit CVE-2017-11882 or a similar vulnerability to achieve code execution. The embedded object data, though not directly readable, is the likely vector for delivering the exploit payload.

Heuristics 3

  • Split hex Equation Editor ProgID + OLE object critical RTF_EQUATION_EDITOR
    RTF embeds the Equation.3 ProgID as hex bytes near OLE object activation and splits the byte stream with whitespace or an ignorable RTF group. This is an Equation Editor OLE activation surface commonly used by CVE-2017-11882 / CVE-2018-0802 exploit documents.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000044.bin
a7ea072c01cd72e5c3a4685d14349ec8a3731b1610bc893076681531160d5e3c
rtf-objdata-decoded RTF \objdata at offset 0x44 50509 bytes