Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 a6d1856378b61d3f…

MALICIOUS

RTF / .DOC

504.2 KB First seen: 2022-05-24
MD5: 46803c88c7c5095b1de759fe9141dc9a SHA-1: 4e9462335d9dfceab31eae49a476b3c92fee1066 SHA-256: a6d1856378b61d3f608a1d9a611bd00cbbb6d94be1e0a4bb3533f3f89a4e0a64
182 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment T1059.003 Windows Command Shell

The sample is an RTF document that contains OLE object data. Heuristics indicate a critical vulnerability related to CVE-2017-11882, specifically involving the Equation Editor. This suggests the document is designed to exploit this vulnerability to execute arbitrary code. The presence of OLE object data and the specific CVE points to a common delivery mechanism for secondary payloads.

Heuristics 5

  • Equation Editor OLE1 native payload — CVE-2017-11882 related critical CVE related CVE_2017_11882_RELATED
    RTF decodes to an OLE1 Equation.3 embedded object whose native data is large and payload-like, and \objupdate requests automatic activation. This is the delivery shape used by Equation Editor RCE documents such as CVE-2017-11882/CVE-2018-0802, but the malformed MTEF record needed for exact attribution was not recovered.
  • Split hex Equation Editor ProgID + OLE object critical RTF_EQUATION_EDITOR
    RTF embeds the Equation.3 ProgID as hex bytes near OLE object activation and splits the byte stream with whitespace or an ignorable RTF group. This is an Equation Editor OLE activation surface commonly used by CVE-2017-11882 / CVE-2018-0802 exploit documents.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001555.bin
db80019737ad6fde7fcb11dd4f6a4ec1c787a0d8c25ffd5e8ad2c04e7bb9e472
rtf-objdata-decoded RTF \objdata at offset 0x1555 255147 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.