Malicious RTF — malware analysis report

Static analysis result for SHA-256 7443736166802879…

MALICIOUS

RTF

72.2 KB
MD5: c6b3b80bb35e81998fa487ab4a6b4edb SHA-1: 732eab9109454e05b1248c0454a6e01fd88ba073 SHA-256: 74437361668028794c6191bb27c7720803eda4a82cbfe8e33d367baca26ca420
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The sample is an RTF document containing an embedded OLE object. Static analysis identified a critical heuristic firing for CVE-2017-11882, indicating exploitation of a vulnerability in Microsoft Equation Editor. This vulnerability is commonly used to achieve arbitrary code execution.

Heuristics 3

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000013e.bin
b42a1ef93996947e98347a7702a02ed03c62a5deaddd3043ab6b5686b413e26a
rtf-objdata-decoded RTF \objdata at offset 0x13E 3631 bytes