Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 e22a9d5b7d075a05…

MALICIOUS

RTF / .DOC

379.3 KB
MD5: 5de8ae67614305518a61c5e509c7c713 SHA-1: 4a8c000d24e679c0e2c73572021083128fe443a1 SHA-256: e22a9d5b7d075a05dad238770a98a58a032e332a21163200f7ce1cde9d15a813
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains an embedded OLE object with decoded Equation Editor payload, indicating exploitation of CVE-2017-11882. The ".objupdate" heuristic suggests the object is designed to activate automatically upon opening. The extracted PE file from the object data is the likely second-stage payload. No scripts were extracted, and the document body was not available for analysis.

Heuristics 4

  • Decoded Equation Editor payload + PE critical RTF_EQUATION_EDITOR
    RTF decodes to an Equation Editor ProgID adjacent to OLE activation and the same decoded object stream contains embedded PE bytes. This matches the Equation Editor exploit surface used by CVE-2017-11882 / CVE-2018-0802 documents, while requiring payload evidence to avoid flagging benign Equation references.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000040.bin
b588dbaeb00c3adbedcf43b7b724b91264b93a79f243ed7bcc6b7d370dff96ce
rtf-objdata-decoded RTF \objdata at offset 0x40 194037 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.