Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 6736025e22592236…

MALICIOUS

RTF / .DOC

309.6 KB
MD5: 7c072f448b120f1535e8a5a893cd3fd9 SHA-1: ce9ff47e8638d97b1aff8813ef5e98e2fcf3c8e0 SHA-256: 6736025e2259223612a583d30d083c61c9acb1d16ca02c9c75d67e3a8c5f2727
182 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The sample is an RTF document containing a decoded Equation Editor payload, strongly indicating exploitation of CVE-2017-11882. This vulnerability allows for the execution of arbitrary code, which in this case is likely a second-stage payload. The presence of OLE object data and a high-entropy carved artifact further supports this analysis.

Heuristics 5

  • Equation Editor OLE1 native payload — CVE-2017-11882 related critical CVE related CVE_2017_11882_RELATED
    RTF decodes to an OLE1 Equation.3 embedded object whose native data is large and payload-like, and \objupdate requests automatic activation. This is the delivery shape used by Equation Editor RCE documents such as CVE-2017-11882/CVE-2018-0802, but the malformed MTEF record needed for exact attribution was not recovered.
  • Decoded Equation Editor payload + PE critical RTF_EQUATION_EDITOR
    RTF decodes to an Equation Editor ProgID adjacent to OLE activation and the same decoded object stream contains embedded PE bytes. This matches the Equation Editor exploit surface used by CVE-2017-11882 / CVE-2018-0802 documents, while requiring payload evidence to avoid flagging benign Equation references.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000b60.bin
598867dce21b0ea09387bb1e157b7e9ade5ad691fe8b19e46d9fd6dbba3c2609
rtf-objdata-decoded RTF \objdata at offset 0xB60 156853 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.