Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 b8326e87ace7c4c0…

MALICIOUS

RTF / .DOC

526.6 KB
MD5: c3d808231dbc140e01acc6fdf08db1a8 SHA-1: 43c432950a91411f97c31cd6dfbdc001b59f60fe SHA-256: b8326e87ace7c4c00814b1334029ab7fcef750f3af7ba380e3cc306d45317d27
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains an embedded OLE object that decodes to a PE file, indicating a likely exploit targeting the Equation Editor. The ".objupdate" heuristic suggests that the OLE object is activated automatically upon opening the document, leading to the execution of the embedded payload. The extracted artifact is a suspicious PE file, likely the second-stage payload.

Heuristics 4

  • Decoded Equation Editor payload + PE critical RTF_EQUATION_EDITOR
    RTF decodes to an Equation Editor ProgID adjacent to OLE activation and the same decoded object stream contains embedded PE bytes. This matches the Equation Editor exploit surface used by CVE-2017-11882 / CVE-2018-0802 documents, while requiring payload evidence to avoid flagging benign Equation references.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000044.bin
ed6c9cbc7f258d57784021eb19c5a077addf92549a959f8a30a9c164347de74e
rtf-objdata-decoded RTF \objdata at offset 0x44 269495 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.