Malicious RTF — malware analysis report

Static analysis result for SHA-256 bb51ff5aef5eceaf…

MALICIOUS

RTF

86.6 KB
MD5: bd1a37df328bc84e7666450a0ec6770f SHA-1: 5ff0ffdf9d346f66560da020be216e533257042b SHA-256: bb51ff5aef5eceaf609972ca71ed8029c7de290f34b39bab7647b92bddb8be94
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The critical heuristic firing indicates exploitation of CVE-2017-11882, a known vulnerability in Microsoft Equation Editor. This vulnerability allows for arbitrary code execution when a specially crafted RTF document is opened. The presence of OLE object data further supports the exploitation of embedded objects within the RTF file.

Heuristics 3

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000238d.bin
c34d152f31eeb505349e9b42b99449211bb76908d2a0a879575ac897cbc9aaff
rtf-objdata-decoded RTF \objdata at offset 0x238D 3631 bytes