INCLUDETEXT/INCLUDEPICTURE remote URL

RTF_INCLUDE_REMOTE

← All detection heuristics · RTF

high RTF_INCLUDE_REMOTE

What it means

RTF document uses INCLUDETEXT or INCLUDEPICTURE with an http:// or https:// URL.

Why it fires

RTF \fldinst blocks with INCLUDETEXT or INCLUDEPICTURE and a remote (http:// or https://) target can cause Word to fetch the remote resource when the document is opened, depending on Office version and external-content settings. This is a remote template injection vector: the attacker controls what content is fetched, can steal NTLM credentials via a UNC redirect, or deliver a second-stage payload. Caveat: legitimate RTF documents very rarely include remote http:// field references; this construction has almost no benign use in consumer-produced documents, making the false-positive rate low.

Other RTF heuristics

RTF_EQUATION_EDITOR RTF_OBJCLASS_EQUATION RTF_MZ_HEX RTF_DDEAUTO_REGSVR32_SCRIPTLET RTF_MACOS_ZSH_LOADER RTF_PACKAGE_AUTOLINK_DELIVERY RTF_OBJAUTLINK RTF_EXCESSIVE_HEX RTF_PACKAGE_OLE RTF_OBFUSCATION RTF_PHP_IRC_BOT_SOURCE RTF_OBJCLASS_PACKAGE RTF_REMOTE_TEMPLATE RTF_EXPLOIT_TEMPLATE_ARTIFACT RTF_OBJUPDATE_LOOSE_HEX_PAYLOAD RTF_OBJUPDATE RTF_PFRAGMENTS_RELATED RTF_OBJEMB RTF_WORD_COMPATIBILITY_PACKAGE RTF_OBJDATA RTF_OLEPRES_STREAM RTF_OLE10NATIVE_STREAM