Malicious RTF — malware analysis report

Static analysis result for SHA-256 8d30cf1a162bbf5a…

MALICIOUS

RTF

161.6 KB
MD5: f6783d4f3a195cd526864f0fd8ee746c SHA-1: a30f4acab04bb2676225916326fb069f3f3789ec SHA-256: 8d30cf1a162bbf5a00538ccff15002f9bea3810da10c71953ede7b0dff92aae2
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The critical heuristic firing indicates exploitation of CVE-2017-11882, a known vulnerability in Microsoft Equation Editor. This vulnerability allows for arbitrary code execution when a specially crafted RTF document is opened. The presence of OLE object data further supports the embedding of malicious content.

Heuristics 3

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000233e.bin
455793db487ee16455025444313cba61d5918c7e27c0a58c5e51ca1f2186041e
rtf-objdata-decoded RTF \objdata at offset 0x233E 28445 bytes