Malicious RTF — malware analysis report

Static analysis result for SHA-256 dc277e5cc805f6ac…

MALICIOUS

RTF

86.7 KB
MD5: e01dd6d0d7f883bb00f8ba465b8866a8 SHA-1: 9d8eaf03d9a58a5498e6e119b0aade51828315c2 SHA-256: dc277e5cc805f6aca73b49ab0d72ef2f671ee6dd76776028326b738a91d2ef7a
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The RTF file contains an embedded OLE object that triggers the CVE-2017-11882 vulnerability in Microsoft Equation Editor. This vulnerability allows for the execution of arbitrary code, indicating a likely exploit attempt to compromise the system.

Heuristics 3

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000023b0.bin
92a4b8d2dffcc8b7a39d3afb0a8b57cd17b4087aefe63441a2a98c12453c6af6
rtf-objdata-decoded RTF \objdata at offset 0x23B0 3631 bytes