Malicious RTF — malware analysis report

Static analysis result for SHA-256 6524e7012ea70e5f…

MALICIOUS

RTF

10.1 KB
MD5: 373cb701b632ae6397bf97b0b3f6336b SHA-1: 7d2f9ffc4d2ed00919bcd19a017427af50fa461e SHA-256: 6524e7012ea70e5f91d1151ed9ecc2c3d700d12fe27e71d3fc148ea71098a42f
120 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains an embedded OLE object with a split Equation Editor ProgID, indicating exploitation of a known vulnerability. The \objupdate directive forces OLE activation, likely leading to the execution of a second-stage payload. The specific nature of the payload could not be determined from the provided evidence.

Heuristics 3

  • Split hex Equation Editor ProgID + OLE object critical RTF_EQUATION_EDITOR
    RTF embeds the Equation.3 ProgID as hex bytes near OLE object activation and splits the byte stream with whitespace or an ignorable RTF group. This is an Equation Editor OLE activation surface commonly used by CVE-2017-11882 / CVE-2018-0802 exploit documents.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001605.bin
6cb8dd8132b1f39d018e03813deffc4c2ef21dc5416a9fe6313a88674690121a
rtf-objdata-decoded RTF \objdata at offset 0x1605 1709 bytes