Uninstantiated RTF/Flash exploit-builder template

RTF_EXPLOIT_TEMPLATE_ARTIFACT

← All detection heuristics · RTF

high RTF_EXPLOIT_TEMPLATE_ARTIFACT

What it means

RTF contains public exploit-builder placeholders around a Flash ActiveX object.

Why it fires

Markers such as swf_random, b64_payload, platform_id and security-research vendor strings identify an uninstantiated lab or toolkit template. It is security-relevant but does not by itself prove exploitation of a specific CVE.

Other RTF heuristics

RTF_EQUATION_EDITOR RTF_OBJCLASS_EQUATION RTF_MZ_HEX RTF_DDEAUTO_REGSVR32_SCRIPTLET RTF_MACOS_ZSH_LOADER RTF_PACKAGE_AUTOLINK_DELIVERY RTF_OBJAUTLINK RTF_INCLUDE_REMOTE RTF_EXCESSIVE_HEX RTF_PACKAGE_OLE RTF_OBFUSCATION RTF_PHP_IRC_BOT_SOURCE RTF_OBJCLASS_PACKAGE RTF_REMOTE_TEMPLATE RTF_OBJUPDATE_LOOSE_HEX_PAYLOAD RTF_OBJUPDATE RTF_PFRAGMENTS_RELATED RTF_OBJEMB RTF_WORD_COMPATIBILITY_PACKAGE RTF_OBJDATA RTF_OLEPRES_STREAM RTF_OLE10NATIVE_STREAM