Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 68aba7620daebc67…

MALICIOUS

RTF / .DOC

30.8 KB First seen: 2022-11-16
MD5: bc0385fdb53417ef55af5973c0c8c8ea SHA-1: 04c0c1259b1a4a0747ef530e9b7f0d5c1444d44a SHA-256: 68aba7620daebc67b67069557da35c0393e5c7e14b68807ff09bef96a0e6541f
200 Risk Score

Malware Insights

MITRE ATT&CK
T1204 User Execution: Malicious Link T1059 Command and Scripting Interpreter

The sample is an RTF document containing an embedded OLE object that exploits the Equation Editor vulnerability (CVE-2017-11882). The document body contains a lure instructing the user to 'Enable editing', which is a common technique to bypass macro security settings. The exploitation of CVE-2017-11882 is highly indicative of malicious intent, likely to download and execute a secondary payload.

Heuristics 6

  • Equation Editor activation — CVE-2017-11882 related high CVE related CVE_2017_11882_ACTIVATION_RELATED
    RTF decodes to an Equation.3 ProgID and requests OLE activation with \objemb plus \objupdate. This reaches the legacy Equation Editor attack surface used by CVE-2017-11882/CVE-2018-0802 documents, but the malformed MTEF/native payload needed for stronger attribution was not recovered.
  • Split hex Equation Editor ProgID + OLE object critical RTF_EQUATION_EDITOR
    RTF embeds the Equation.3 ProgID as hex bytes near OLE object activation and splits the byte stream with whitespace or an ignorable RTF group. This is an Equation Editor OLE activation surface commonly used by CVE-2017-11882 / CVE-2018-0802 exploit documents.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Macro/content-enable lure medium SE_ENABLE_LURE
    Document instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00005a38.bin
61dced11e809bfe7337e3c4ff8fbe66b97f7ddacf6ca6c4f8e50d59800a7a888
rtf-objdata-decoded RTF \objdata at offset 0x5A38 1846 bytes