Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 c9cc8f608f95c151…

MALICIOUS

RTF / .DOC

25.5 KB
MD5: 0ffb5711e7f7ed0dd5daf7de9252a19a SHA-1: 501d4e4d4a20bb7d5ef382896eee7b66cf15b3ca SHA-256: c9cc8f608f95c151e67e36bbf5a935514cfefccb0e275124190c28c6ec679368
120 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.001 PowerShell

The sample is an RTF document that contains OLE object data and triggers an objupdate event, indicating it attempts to activate embedded content. The critical heuristic firing for RTF_EQUATION_EDITOR strongly suggests exploitation of the Equation Editor vulnerability (CVE-2017-11882). This vulnerability allows for arbitrary code execution, which is likely used here to download and execute a second-stage payload. No specific family could be identified.

Heuristics 3

  • Split hex Equation Editor ProgID + OLE object critical RTF_EQUATION_EDITOR
    RTF embeds the Equation.3 ProgID as hex bytes near OLE object activation and splits the byte stream with whitespace or an ignorable RTF group. This is an Equation Editor OLE activation surface commonly used by CVE-2017-11882 / CVE-2018-0802 exploit documents.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001f5c.bin
785da2c0831dda5a9df9da46281444967146d36b2ea10dff4487aba58d9e2ca9
rtf-objdata-decoded RTF \objdata at offset 0x1F5C 1721 bytes