Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 ce67249d953f8a40…

MALICIOUS

RTF / .DOC

1.94 MB
MD5: d972e9f59cb2a6f810cf82d528f27262 SHA-1: 037f0a45d1be10893697c3c99f195b6029bfb239 SHA-256: ce67249d953f8a408d4857f63b2dea664447d94b8bf862c1d8d1713d3a8ab050
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The critical RTF_EQUATION_EDITOR heuristic indicates the file exploits a known vulnerability in the Equation Editor component. The RTF_OBJUPDATE heuristic suggests that the embedded OLE object is automatically activated upon opening. The presence of embedded OLE objects and objdata sections further supports the exploitation of these components. While no specific URLs or scripts were directly extracted, the exploitation pattern strongly suggests the download and execution of a secondary payload.

Heuristics 4

  • Split hex Equation Editor ProgID + OLE object critical RTF_EQUATION_EDITOR
    RTF embeds the Equation.3 ProgID as hex bytes near OLE object activation and splits the byte stream with whitespace or an ignorable RTF group. This is an Equation Editor OLE activation surface commonly used by CVE-2017-11882 / CVE-2018-0802 exploit documents.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000df9.bin
fdbee466045736ec8716d1a8cfeeeba965409765f22443b8e684e0b3cb5457d2
rtf-objdata-decoded RTF \objdata at offset 0xDF9 33304 bytes
objdata_01_off0001b8bd.bin
b2241a9ba6e0dcd3ee0b712296cc82769651d12e97b7d1a1b0a107b8712fa589
rtf-objdata-decoded RTF \objdata at offset 0x1B8BD 456499 bytes