MALICIOUS
162
Risk Score
Malware Insights
MITRE ATT&CK
T1204.002 Malicious File
T1059.001 PowerShell
The RTF document contains embedded OLE objects and triggers critical heuristics for CVE-2017-8759 and CVE-2026-21509, indicating exploitation of known vulnerabilities in Microsoft Office. The document body, written in Romanian and English, presents a fabricated story about a criminal investigation to potentially lure the user into interacting with the malicious content. No scripts were extracted, but the presence of OLE objects and the specific CVEs strongly suggest an attempt to execute arbitrary code.
Heuristics 5
-
CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
-
CVE-2026-21509 — Shell.Explorer.1 CLSID in RTF critical CVE_2026_21509RTF document contains the Shell.Explorer.1 CLSID {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} associated with CVE-2026-21509 (OLE/COM Killbit / Protected View bypass). Actively exploited in the wild.
-
OLE object data medium RTF_OBJDATARTF contains 4 \objdata section(s) — embedded OLE objects
-
Embedded OLE object medium RTF_OBJEMBRTF contains \objemb — embedded OLE object
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.microsoft.com/office/word/2003/wordml}}\paperw11906\paperh16838\margl1134\margr1134\margt1134\margb1134\gutter0\ltrsect
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
objdata_00_off0000c725.binffd89acd72cf3f9f5d0dad586522665f75b7e25a03f1a7f42532b4e1ff0cece0 |
rtf-objdata-decoded | RTF \objdata at offset 0xC725 | 2809 bytes |
objdata_01_off0000ddd1.bin168317934a425253a40d3e63ff00818048e1003ed0c49c86d2b11d882bb6f679 |
rtf-objdata-decoded | RTF \objdata at offset 0xDDD1 | 2609 bytes |
objdata_02_off0000f3d2.bin4639ac27827b5ade2cb50fa8ee9ab1ddbb605b935e0c653c18be9bd2ad82a4ef |
rtf-objdata-decoded | RTF \objdata at offset 0xF3D2 | 2609 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.