Malicious RTF — malware analysis report

Static analysis result for SHA-256 34144d4af482bd2f…

MALICIOUS

RTF

178.5 KB First seen: 2024-06-26
MD5: 2af6dfccbd42b4b421436d545211a3be SHA-1: 7ca50038be6f52bcc197caa71140eee4c6bb4cb9 SHA-256: 34144d4af482bd2f2677c1efe327fe2dc11ece53d79be696f5d7a79f2c9707f2
140 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1204.002 Malicious File

The RTF document contains an embedded OLE object that leverages the Equation Editor vulnerability (RTF_EQUATION_EDITOR). This technique is commonly used to achieve arbitrary code execution, typically to download and execute a second-stage payload. The presence of RTF_OBJDATA and RTF_OBJUPDATE heuristics further supports the exploitation of embedded objects for malicious purposes.

Heuristics 4

  • Equation Editor CLSID critical RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001b6e.bin
a0c3e8a79ff96ecf1a89e16e2d80a827bb094799b3b05f505d64cf0211fff452
rtf-objdata-decoded RTF \objdata at offset 0x1B6E 4184 bytes