Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 3fd36b9e8ffcffec…

MALICIOUS

RTF / .DOC

97.2 KB
MD5: 36c73a4536eb68c04b0fa019d16fe149 SHA-1: c861aad2e5519fc14eccbbf46052ff2593ef3e51 SHA-256: 3fd36b9e8ffcffec6f18c3c698c9cd69ec01bb08aa2b56df07f395386e10c1f0
220 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.001 PowerShell

The file is an RTF document containing embedded OLE objects, specifically triggering heuristics related to the Equation Editor vulnerability (CVE-2017-11882). This indicates the document is designed to exploit this vulnerability for initial code execution. The ClamAV signature further confirms this specific exploit. No scripts were extracted, but the exploit itself is the primary attack vector.

Heuristics 5

  • Ole10Native stream in RTF OLE object high CVE related RTF_OLE10NATIVE_STREAM
    RTF contains an embedded OLE object with an Ole10Native stream. This is a strong payload-container signal and is related to Word/OLE exploit delivery, but it is not specific enough on its own to assign a CVE.
  • Equation Editor CLSID critical RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • ClamAV: Rtf.Exploit.CVE_2017_11882-6584355-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Exploit.CVE_2017_11882-6584355-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000000af.bin
e07171d3bd91bf60808d4a135f18379b6cab5ae5196a873fa25ac75813118974
rtf-objdata-decoded RTF \objdata at offset 0xAF 33462 bytes