Malicious RTF — malware analysis report

Static analysis result for SHA-256 4e19e29e93248ee8…

MALICIOUS

RTF

87.6 KB
MD5: 24a9b043f1de4aad0ca07bb94c179a70 SHA-1: 349090c60d37436555cd23c06627b596641cb34d SHA-256: 4e19e29e93248ee8958c65bb7c7b8c025106e4b6c5ac21c3723d2ddcb76a91a7
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The sample is an RTF document that contains an embedded OLE object. Static analysis identified a critical heuristic firing for CVE-2017-11882, indicating exploitation of a vulnerability in Microsoft Equation Editor. This vulnerability allows for arbitrary code execution when the document is opened.

Heuristics 3

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002356.bin
59865a2b0e1b2bb6ecbd833783465f617ec1bfaa5d5e1f83df3e3b2639e4f05d
rtf-objdata-decoded RTF \objdata at offset 0x2356 3631 bytes