Malicious RTF — malware analysis report

Static analysis result for SHA-256 b01d5e71c15c35cf…

MALICIOUS

RTF

233.6 KB First seen: 2019-02-26
MD5: f5340841ce0f2b8b2cc7b780ccb8ff42 SHA-1: 50a2cc306e81517462b7dfc1268512bfc2753009 SHA-256: b01d5e71c15c35cf045ca504826ab5d5be8e668f371e8b43016d883c8ee856f8
120 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The RTF document contains embedded OLE object data and triggers an exploit for CVE-2017-11882, a known vulnerability in Microsoft Equation Editor. This vulnerability allows for the execution of arbitrary code, indicating a likely exploitation attempt to compromise the system.

Heuristics 3

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000003c.bin rtf-objdata-decoded RTF \objdata at offset 0x3C 3627 bytes
SHA-256: a02c292a395940b8148779c76db09a208dc3fd8be7048956c9a0f078e676896b