Malicious RTF — malware analysis report

Static analysis result for SHA-256 59f1b3d226f368a9…

MALICIOUS

RTF

228.2 KB Created: 2021-02-12 04:30:00
MD5: 590eee9776ca3142a2771eb6f5cd2504 SHA-1: 9f7e4d575fdd7d6e646ad3825a80889847666960 SHA-256: 59f1b3d226f368a968cd90244e7c248c20580c47759ae6b7b31a01ebbc5b9d46
262 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The file is an RTF document that contains embedded OLE object data, specifically identified as an Equation Editor exploit. This strongly suggests exploitation of the CVE-2017-11882 vulnerability, which allows for arbitrary code execution. The document body content appears benign, but the critical heuristics point to a malicious exploit rather than legitimate content.

Heuristics 7

  • Equation Editor CLSID critical RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • Equation Editor object class critical RTF_OBJCLASS_EQUATION
    Object class 'equation.3' references Equation Editor
  • ClamAV: Doc.Exploit.Cve_2017_11882-7570663-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Exploit.Cve_2017_11882-7570663-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000118.bin
4a6084b8db35bdfc44984eb7da4d5252b9ea47c5e92c9bc040b892f0a3e5ef0d
rtf-objdata-decoded RTF \objdata at offset 0x118 2768 bytes