Malicious RTF — malware analysis report

Static analysis result for SHA-256 e7e4d99940df20c5…

MALICIOUS

RTF

66.5 KB Created: 2020-12-30 01:20:00 First seen: 2021-01-23
MD5: eed158a07bb7964798372f5e1ab13f0c SHA-1: 57ef30a766b635ba3cf0dd8b810936d7b7a77665 SHA-256: e7e4d99940df20c5ee0201d3ab3984191b69d868252121fa4258517fb2bb4ba3
182 Risk Score

Heuristics 5

  • Equation Editor CLSID critical CVE likely RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • CVE-2018-0798 — Equation Editor Matrix record overflow critical CVE exact CVE_2018_0798
    RTF contains hex-encoded MTEF Matrix record exploit signature (NOP-sled 0x60 + padding 0x61 + return address 0x0BFB). CVE-2018-0798 exploits a stack buffer overflow in EQNEDT32.EXE's Matrix record parser and affected Equation Editor broadly, including builds patched for CVE-2017-11882. Widely used by APT groups (Conimes, KeyBoy, Emissary Panda, Rancor).
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000a2e1.bin rtf-objdata-decoded RTF \objdata at offset 0xA2E1 1378 bytes
SHA-256: 3ead9f475f28de2d6d57d51cf75d6b7ef24c06c59fe6cdd849b416624c1662f5
objdata_01_off0000adb5.bin rtf-objdata-decoded RTF \objdata at offset 0xADB5 11820 bytes
SHA-256: bb954d415912bd276ee27fd7ceccc8be1781d7cd28bb1969cf14f42eca05abeb