Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 ceddfb89930dabc4…

MALICIOUS

RTF / .DOC

21.2 KB
MD5: 843e4ae0a3ae157bc67d9ea48902d388 SHA-1: d25e5af6e503a8b487dbb3f0543780573a019cf9 SHA-256: ceddfb89930dabc4aa8b0f6dabbcc2ba978070022cf5710e088e6aa92df3924b
180 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.001 PowerShell

The RTF file contains embedded OLE object data and specifically triggers the Equation Editor vulnerability (CVE-2017-11882). This indicates the file is designed to exploit this known vulnerability for arbitrary code execution. No document body text was available for further context, but the heuristics strongly suggest a malicious exploit document.

Heuristics 5

  • Equation Editor activation — CVE-2017-11882 related high CVE related CVE_2017_11882_ACTIVATION_RELATED
    RTF decodes to an Equation.3 ProgID and requests OLE activation with \objemb plus \objupdate. This reaches the legacy Equation Editor attack surface used by CVE-2017-11882/CVE-2018-0802 documents, but the malformed MTEF/native payload needed for stronger attribution was not recovered.
  • Split hex Equation Editor ProgID + OLE object critical RTF_EQUATION_EDITOR
    RTF embeds the Equation.3 ProgID as hex bytes near OLE object activation and splits the byte stream with whitespace or an ignorable RTF group. This is an Equation Editor OLE activation surface commonly used by CVE-2017-11882 / CVE-2018-0802 exploit documents.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001068.bin
bda22a73b84d9ea092e38752f57350237bfef2cc1369387beda0f03b393e3a3c
rtf-objdata-decoded RTF \objdata at offset 0x1068 1697 bytes