Malicious RTF — malware analysis report

Static analysis result for SHA-256 e52209deae6a135d…

MALICIOUS

RTF

12.2 KB First seen: 2019-01-12
MD5: 10af6f0f8d6c056701a31b7478bfef05 SHA-1: 2b74e29a67e830727caaf2a7f36082b5e9de13ba SHA-256: e52209deae6a135df670312b26c2833ecc8e1e166a265808d9fe5f01904c5d57
120 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The sample is an RTF document identified by ClamAV as Doc.Exploit.CVE_2017_11882-6934206-0, indicating exploitation of the Equation Editor vulnerability (CVE-2017-11882). The presence of OLE object data and the \objupdate heuristic further support this. This exploit is typically delivered via spearphishing attachments.

Heuristics 3

  • ClamAV: Doc.Exploit.CVE_2017_11882-6934206-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Exploit.CVE_2017_11882-6934206-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000003c.bin rtf-objdata-decoded RTF \objdata at offset 0x3C 4140 bytes
SHA-256: 26d657775d36eb5e85caf13f50dabf0927e92289e9cdf1d8274a6e27bb02158b