Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 f7458364746ae267…

MALICIOUS

RTF / .DOC

2.12 MB
MD5: ff4334f2f881fea64848de11caeef108 SHA-1: 7bfcc314ff732c6a9516181863af4d3e126799d1 SHA-256: f7458364746ae2673daf1ad8dba756719ea412ba537ac55c2b22aaf44215b2a4
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The critical RTF_EQUATION_EDITOR heuristic indicates the file exploits a known vulnerability in the Equation Editor component. The presence of OLE object data and the ".objupdate" directive further suggest that embedded objects are being activated to execute malicious code. The document body contains obfuscated JavaScript-like code which likely attempts to download and execute a second-stage payload, although its exact function is obscured.

Heuristics 4

  • Split hex Equation Editor ProgID + OLE object critical RTF_EQUATION_EDITOR
    RTF embeds the Equation.3 ProgID as hex bytes near OLE object activation and splits the byte stream with whitespace or an ignorable RTF group. This is an Equation Editor OLE activation surface commonly used by CVE-2017-11882 / CVE-2018-0802 exploit documents.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000ded.bin
9a1e72f6e17023047ffb685307553e711480eda203f0b178546a1c1d5dc2c8a6
rtf-objdata-decoded RTF \objdata at offset 0xDED 56904 bytes
objdata_01_off000329d7.bin
975d3a2f2f8b7195d4eb809b2a138db9dd3913fc730826171b11bd21fa93d9f8
rtf-objdata-decoded RTF \objdata at offset 0x329D7 478829 bytes