Malicious RTF — malware analysis report

Static analysis result for SHA-256 8e5c48a5b8930509…

MALICIOUS

RTF

53.2 KB Created: 2022-05-17 02:21:00 First seen: 2022-05-17
MD5: 0ca5b5379802562be6ac8e5c967c7356 SHA-1: a312d04e216308e44392a8a3d8ee1422e2e84792 SHA-256: 8e5c48a5b89305090cfb4e3048141594579f1e5c32df9f7ca4a4ab9e7f426a7f
202 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains embedded OLE objects, specifically identified as Microsoft Equation Editor, which is a known vector for exploiting vulnerabilities. The presence of RTF_EQUATION_EDITOR and RTF_OBJCLASS_EQUATION heuristics strongly suggests an exploit targeting this component. While no scripts were extracted, the structure indicates a likely attempt to execute arbitrary code via the embedded object, leading to a malicious payload delivery.

Heuristics 6

  • Ole10Native stream in RTF OLE object high CVE related RTF_OLE10NATIVE_STREAM
    RTF contains an embedded OLE object with an Ole10Native stream. This is a strong payload-container signal and is related to Word/OLE exploit delivery, but it is not specific enough on its own to assign a CVE.
  • Equation Editor CLSID critical RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • Equation Editor object class critical RTF_OBJCLASS_EQUATION
    Object class 'equation.3' references Equation Editor
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00004922.bin
484c40f226cb4f4c3616404da72dec801a7197580651a6cff81c5f4d615a3d67
rtf-objdata-decoded RTF \objdata at offset 0x4922 7392 bytes