Malicious RTF — malware analysis report

Static analysis result for SHA-256 37f15f4d60724a73…

MALICIOUS

RTF

546.7 KB Created: 1996-10-29 19:47:00 First seen: 2019-08-04
MD5: 22d00f502c2fa3804b67324a03d884de SHA-1: 6cc3424be2cd6e400c544a0398f2b394898e9ca9 SHA-256: 37f15f4d60724a7395cc8c4916d7cce731b2df47fd1d111392b63fb84bacfcd6
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains multiple OLE object data sections and embedded OLE objects, indicated by the RTF_OBJDATA, RTF_OBJEMB, and RTF_OLE10NATIVE_STREAM heuristics. This strongly suggests the file is designed to exploit vulnerabilities associated with OLE object handling or to embed and execute malicious content. The document body appears to be templated data related to property viewing, which is likely a lure.

Heuristics 4

  • Ole10Native stream in RTF OLE object high CVE related RTF_OLE10NATIVE_STREAM
    RTF contains an embedded OLE object with an Ole10Native stream. This is a strong payload-container signal and is related to Word/OLE exploit delivery, but it is not specific enough on its own to assign a CVE.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • OlePres presentation stream in RTF OLE object medium RTF_OLEPRES_STREAM
    RTF contains an embedded OLE object with an OlePres presentation stream. OlePres is an OLE presentation marker and is not enough on its own to identify CVE-2025-21298.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000d2f.bin rtf-objdata-decoded RTF \objdata at offset 0xD2F 163940 bytes
SHA-256: 618e2a7362e17c5a4fb6e4cb601c8216ea9d69df5bb0d7f15bf5105262395930
objdata_01_off000698bb.bin rtf-objdata-decoded RTF \objdata at offset 0x698BB 29799 bytes
SHA-256: f0182bef585f533c8a32f790eb0c7945a98c5b7e2bd8f55252cdcfb9a6c2df4a