Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 cc0c6582b95cd95e…

MALICIOUS

RTF / .DOC

232.1 KB
MD5: ea5ed5dc56aa31e19f864f124f17fa62 SHA-1: 5aa06a109edc80c2928e668c3c6a0e3671b08182 SHA-256: cc0c6582b95cd95e6a720652d3d97b88268e2d037d7e0170b41105f7c109d0b8
220 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.003 Windows Command Shell

The RTF document contains embedded OLE objects, specifically triggering critical heuristics for Equation Editor and CVE-2017-11882. This indicates the file is designed to exploit a known vulnerability in Microsoft Equation Editor to achieve arbitrary code execution. The presence of ".objupdate" further suggests that the embedded object is intended to be activated automatically upon opening the document.

Heuristics 5

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • Equation Editor CLSID critical RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • Automatically linked OLE object high RTF_OBJAUTLINK
    RTF contains \objautlink — an automatically linked OLE object surface that can be updated or activated when Word opens the document.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000012d8.bin
d71e7db76b25b281e793c4f8359630f10802c3c8a938502ec1b736b07e639b9d
rtf-objdata-decoded RTF \objdata at offset 0x12D8 3662 bytes