Malware Insights
The file is an RTF document containing an embedded OLE object that leverages the Equation Editor vulnerability (CVE-2017-11882). The heuristic 'CVE_2017_11882_ACTIVATION_RELATED' specifically indicates this exploit. The embedded object is activated via \objupdate, forcing the execution of the exploit. The decoded object's class is 'equatIoN.3', which is a strong indicator of this specific vulnerability being targeted. The primary attack pattern is the exploitation of this known vulnerability to achieve arbitrary code execution, likely leading to the download of a secondary payload.
Heuristics 6
-
Obfuscated Equation Editor ProgID + activation critical RTF_EQUATION_EDITORRTF decodes to an Equation.3 ProgID from top-level \objdata hex after nested RTF junk groups are ignored, and the document also contains \objemb plus \objupdate activation. This is an obfuscated Equation Editor exploit surface associated with CVE-2017-11882 / CVE-2018-0802 families, but no exact malformed MTEF CVE primitive was recovered from this object.
-
Equation Editor activation — CVE-2017-11882 related high CVE_2017_11882_ACTIVATION_RELATEDRTF decodes to an Equation.3 ProgID and requests OLE activation with \objemb plus \objupdate. This reaches the legacy Equation Editor attack surface used by CVE-2017-11882/CVE-2018-0802 documents, but the malformed MTEF/native payload needed for stronger attribution was not recovered.
-
ClamAV: Rtf.Malware.Agent-9913102-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Rtf.Malware.Agent-9913102-0
-
\objupdate forces OLE activation high RTF_OBJUPDATERTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
-
OLE object data medium RTF_OBJDATARTF contains 2 \objdata section(s) — embedded OLE objects
-
Embedded OLE object medium RTF_OBJEMBRTF contains \objemb — embedded OLE object
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
objdata_00_off00000ce8.bina6b82912d18ffafff7dbcf4f8aee3085f5b01b8fdd39bab3008f95f9b48e9ff3 |
rtf-objdata-decoded | RTF \objdata at offset 0xCE8 | 1570 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.