Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 b80f646b11b61cb3…

MALICIOUS

RTF / .DOC

50.6 KB
MD5: def7f323a9c899eeff2daec6c685436d SHA-1: 19759534b1d50232576ece5e49e567bd158267d1 SHA-256: b80f646b11b61cb3d989da0858fec2bad99b5006f5d3f0e6a3a2bd86d8a8ac6f
220 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.001 Malicious Link: Malicious Link T1566 Phishing T1566.001 Phishing: Spearphishing Attachment T1059 Command and Scripting Interpreter T1059.003 Command and Scripting Interpreter: Windows Command Shell

The file is an RTF document containing OLE object data and specifically triggers heuristics related to Equation Editor exploits, including CVE_2018_0802. This indicates the document is designed to exploit a vulnerability in the Equation Editor component to achieve arbitrary code execution upon opening. No scripts were extracted, but the presence of the exploit is sufficient to classify the attack pattern.

Heuristics 5

  • Ole10Native stream in RTF OLE object high CVE related RTF_OLE10NATIVE_STREAM
    RTF contains an embedded OLE object with an Ole10Native stream. This is a strong payload-container signal and is related to Word/OLE exploit delivery, but it is not specific enough on its own to assign a CVE.
  • Equation Editor CLSID critical RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • ClamAV: Rtf.Exploit.CVE_2018_0802-6825822-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Exploit.CVE_2018_0802-6825822-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000000b6.bin
c7e6c7bd1acf7a94007e1cff1aba62d824516a44b9830053f39ea7876db59165
rtf-objdata-decoded RTF \objdata at offset 0xB6 16691 bytes