Malicious RTF — malware analysis report

Static analysis result for SHA-256 f148e0d084ae6519…

MALICIOUS

RTF

11.0 KB First seen: 2020-05-14
MD5: ddc2ea361d2a373ec8571fc7b59860fa SHA-1: d9c4e7b321e9823466c8e3e8c3aef699ac3962ca SHA-256: f148e0d084ae6519242c2ded3cba014db197a7a21600ac4c57c8671e38fdfa75
180 Risk Score

Heuristics 4

  • Equation Editor CLSID critical CVE likely RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000f5e.bin rtf-objdata-decoded RTF \objdata at offset 0xF5E 3637 bytes
SHA-256: b74e0916d97b5a52f7635f6d2395084efbe0f714ef5b85b09c99cd0ce250c68e