Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 cec8ba389a443ab1…

MALICIOUS

RTF / .DOC

707.9 KB
MD5: 8c9963b5e261c52e7f2bd611d5e7e8bc SHA-1: baab597d38a05fbe18bf05959a8ff93d0ecf03d8 SHA-256: cec8ba389a443ab1736b2ae402abde117845cf9a4548fcd0882ecfd75d4aa2b7
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains an embedded OLE object that leverages the Equation Editor vulnerability (CVE-2017-11882). This vulnerability is used to decode and execute a Portable Executable (PE) file, which likely acts as a downloader for further malicious payloads. The ".objupdate" heuristic indicates that the OLE object is designed to be activated automatically, facilitating the exploit.

Heuristics 4

  • Decoded Equation Editor payload + PE critical RTF_EQUATION_EDITOR
    RTF decodes to an Equation Editor ProgID adjacent to OLE activation and the same decoded object stream contains embedded PE bytes. This matches the Equation Editor exploit surface used by CVE-2017-11882 / CVE-2018-0802 documents, while requiring payload evidence to avoid flagging benign Equation references.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000042.bin
1b595b4003534e3575dce522e8bbe80604edc6daebf25c0ee7f1ee1f5e5c3b94
rtf-objdata-decoded RTF \objdata at offset 0x42 362301 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.