Malicious RTF — malware analysis report

Static analysis result for SHA-256 74c577ddec97a6fc…

MALICIOUS

RTF

8.4 KB Authoring application: Riched20 6.3.9600
MD5: 305d7db0d320b0a37551f21871b9f67a SHA-1: 634f61907e14b5bcf7d4921ffcde4bde2045715c SHA-256: 74c577ddec97a6fcf4ff0b9aa95abb029b625850cf3fc9c33a7905271899a0f1
322 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains an embedded OLE object specifically identified as Equation Editor, which is known to be vulnerable to CVE-2017-11882. The heuristic firings confirm the presence of the exploit, indicating the file is designed to execute arbitrary code upon opening. No document body or script content was extracted, but the exploit itself is sufficient evidence of malicious intent.

Heuristics 8

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • Equation Editor CLSID critical RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • Equation Editor object class critical RTF_OBJCLASS_EQUATION
    Object class 'equation.3' references Equation Editor
  • ClamAV: Rtf.Exploit.CVE_2017_11882-6584355-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Exploit.CVE_2017_11882-6584355-1
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://urlz.fr/7yDu

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000100.bin
e15190b566dbe06995ed1efa4fb51049a1b6ca43d8cb9be5eb711f2a03d3e2c6
rtf-objdata-decoded RTF \objdata at offset 0x100 3546 bytes