Malicious RTF — malware analysis report

Static analysis result for SHA-256 fedff1f00f3bfa87…

MALICIOUS

RTF

225.8 KB Created: 2019-08-06 01:42:00 First seen: 2026-06-10
MD5: 0e798d12542685a1c40c20f0093eaba4 SHA-1: 55f0475ee33d5cc3d135eb9f0528aab11e40895d SHA-256: fedff1f00f3bfa875fa8cde90e1c46926cc5e8f7e0bb629e5e0d17a5d4bc2f54
262 Risk Score

Heuristics 7

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • ClamAV: Rtf.Dropper.Agent-7351583-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Dropper.Agent-7351583-0
  • Equation Editor shellcode downloads a second-stage payload critical OLE_MTEF_SHELLCODE_DOWNLOAD_URL
    The shellcode reached by the Equation Editor overflow resolves download/exec APIs (URLDownloadToFile / ShellExecute / WinExec) and fetches a second-stage payload. The download URL was recovered from the Equation Native stream — directly when the shellcode is plaintext, or by emulating its self-decoding stub. An integer-encoded host (e.g. http://000030000706151) is normalised to its dotted-quad form and both spellings are surfaced as IOCs.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 3 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://camexpertangkor.com/http/emfnbk.exe In RTF body
    • http://000030000706151In RTF body
    • http://192.3.140.105Decoded from obfuscated IP host (000030000706151)
    • http://schemas.microsoft.com/office/word/2003/wordmlIn RTF body

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00007a02.bin rtf-objdata-decoded RTF \objdata at offset 0x7A02 15892 bytes
SHA-256: c5ec0675b951d80abace6d53eeea459f9af0b5a5670a6a9ef8a1d3b1ac0f6718