Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 22cbdd366f415e23…

MALICIOUS

RTF / .DOC

13.7 KB
MD5: dbb53a8dae4f27476b4f30dd484d5ed1 SHA-1: acfcae2d1cc9c1a30394eb52afb449f998ae3101 SHA-256: 22cbdd366f415e2358fd19df497523820f9f0c2465147baac55673c38841f279
240 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1027 Obfuscated Files or Information

The RTF file contains embedded OLE objects, specifically triggering critical heuristics for Equation Editor CLSID and Ole10Native stream. This strongly indicates exploitation of CVE-2018-0802, a known vulnerability in Microsoft Equation Editor. The ClamAV detection ID further confirms this exploit. The primary attack pattern is exploitation for client execution via a vulnerable OLE object.

Heuristics 6

  • Ole10Native stream in RTF OLE object high CVE related RTF_OLE10NATIVE_STREAM
    RTF contains an embedded OLE object with an Ole10Native stream. This is a strong payload-container signal and is related to Word/OLE exploit delivery, but it is not specific enough on its own to assign a CVE.
  • Equation Editor CLSID critical RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • ClamAV: Rtf.Exploit.CVE_2018_0802-6825822-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Exploit.CVE_2018_0802-6825822-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000015b4.bin
95c66f61dd735759305263bbebdab434021e2ee56872d16b0c21556ae73f8817
rtf-objdata-decoded RTF \objdata at offset 0x15B4 4161 bytes