Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 ea13d9b4eeb50863…

MALICIOUS

RTF / .DOC

8.2 KB
MD5: e73c023c85349202dc11653d381fbca8 SHA-1: 897bce437c44ee5aca116e198b1b7a3d73995674 SHA-256: ea13d9b4eeb50863243709393c454bb05040360e23978ae94530b5b0063ac09f
220 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 Command and Scripting Interpreter T1071.001 Application Layer Compromise T1566.001 Phishing: Spearphishing Attachment T1071.002 Application Layer Attack T1195 Exploit Public-Facing Application

The file exhibits multiple indicators of an Equation Editor exploit, primarily through the presence of the Equation Editor CLSID and the CVE-2017-11882 heuristic. The use of extit{objdata}, extit{objautlink}, and extit{objupdate} controls further strengthens this assessment. The extit{objupdate} control word is a key indicator of Equation Editor exploits, forcing immediate OLE object instantiation upon document opening, bypassing user interaction. The file likely attempts to download and execute a secondary payload via a mechanism triggered by the Equation Editor vulnerability. The high confidence reflects the well-documented nature of this exploit and the clear evidence of its presence within the sample.

Heuristics 5

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • Equation Editor CLSID critical RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • Automatically linked OLE object high RTF_OBJAUTLINK
    RTF contains \objautlink — an automatically linked OLE object surface that can be updated or activated when Word opens the document.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000041.bin
c3f417e10a4922caebb1fb7fd05f2afbdb89d18dc14ab3cd579551b68edec88e
rtf-objdata-decoded RTF \objdata at offset 0x41 4136 bytes