Equation Editor OLE CLSID (0002CE02) found in RTF hex data.
Object class name references Equation Editor.
MZ header (hex '4D5A') found in RTF hex data.
An RTF DDEAUTO field launches cmd and regsvr32 with scrobj.dll.
Visible RTF text contains a base64/gzip shell loader executed with zsh.
An RTF Package or Word OLE object is paired with objautlink/objupdate activation.
RTF contains \objautlink — an automatically linked OLE object marker.
RTF document uses INCLUDETEXT or INCLUDEPICTURE with an http:// or https:// URL.
RTF contains large blocks of hex-encoded data.
OLE Package CLSID pattern found alongside object data.
Many RTF control words appear fragmented or obfuscated.
RTF text contains PHP IRC bot source code.
OLE Package object found in RTF.
The RTF's \*\template destination is a remote URL/UNC path that Word fetches and loads on open.
RTF contains public exploit-builder placeholders around a Flash ActiveX object.
RTF declares an auto-activating OLE object (\objupdate) but stores its payload as a large loose hex region outside any \objdata destination.
RTF contains \objupdate — forces automatic OLE object activation.
RTF contains \pFragments without the oversized value needed for CVE-2010-3333.
RTF contains \objemb — an embedded OLE object marker.
RTF contains a hidden Word compatibility or frame relationship package.
RTF contains \objdata sections with embedded OLE objects.
RTF embedded OLE object contains an OlePres presentation stream marker.
RTF embedded object evidence: RTF OLE10Native Stream.