Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 d164bebad32990ad…

MALICIOUS

RTF / .DOC

4.7 KB First seen: 2022-03-10
MD5: 976c8320d86bd9989697b16e9acde266 SHA-1: aa9d4348dab38027eca3d85121d43d8bcffd0b19 SHA-256: d164bebad32990adaef86446eb1dcdff56f21dd54a9722517bd17deecc4800a2
121 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1559.002 Component Object Model

The RTF document contains embedded OLE object data, specifically targeting the Equation Editor component. The presence of RTF_EQUATION_EDITOR and RTF_OBJUPDATE heuristics indicates that the file is designed to exploit a known vulnerability in the Equation Editor to achieve arbitrary code execution upon opening. No document body text or scripts were extracted, but the heuristics strongly suggest a classic exploit delivery mechanism.

Heuristics 3

  • Split hex Equation Editor ProgID + OLE object critical RTF_EQUATION_EDITOR
    RTF embeds the Equation.3 ProgID as hex bytes near OLE object activation and splits the byte stream with whitespace or an ignorable RTF group. This is an Equation Editor OLE activation surface commonly used by CVE-2017-11882 / CVE-2018-0802 exploit documents.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000000cf.bin
425738620de34ac43804d64a60d62742e443e4688c555f40d23199e399ac7147
rtf-objdata-decoded RTF \objdata at offset 0xCF 2161 bytes