Malicious RTF — malware analysis report

Static analysis result for SHA-256 56fddefb93f4676a…

MALICIOUS

RTF

1.61 MB Authoring application: Riched20 10.0.17763 First seen: 2020-08-10
MD5: 750d22588e045cc40cf3c570f5586793 SHA-1: bbfed7a002ad199fd2f61579249972b58754ce1a SHA-256: 56fddefb93f4676aaddd7082b5e6cca2c04d2e8a12dffb8bf7e972c60ba079c8
300 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains multiple embedded OLE objects, with ".objupdate" directives indicating an attempt to force activation. High heuristic scores for excessive hex data within these objects suggest a hidden payload. ClamAV detections of 'Xls.Malware.Stratos-7506050-0' on the main file and an extracted artifact further confirm malicious intent, likely involving exploitation for client execution.

Heuristics 7

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Stratos-7506050-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Stratos-7506050-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • Large hex data blocks in OLE object high RTF_EXCESSIVE_HEX
    RTF contains ~1012KB of hex-encoded data inside \objdata sections — may hide a payload
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • OlePres presentation stream in RTF OLE object medium RTF_OLEPRES_STREAM
    RTF contains an embedded OLE object with an OlePres presentation stream. OlePres is an OLE presentation marker and is not enough on its own to identify CVE-2025-21298.

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000113.bin rtf-objdata-decoded RTF \objdata at offset 0x113 82280 bytes
SHA-256: 8e97ec13d36d54b43d2cb1b7dac3586faf0cdb25b14ca4ecbdd04c044e77605b
Detection
ClamAV: Xls.Malware.Stratos-7506050-0
Obfuscation or payload: unlikely
objdata_01_off00029518.bin rtf-objdata-decoded RTF \objdata at offset 0x29518 82280 bytes
SHA-256: 30bbc6e4e23d1eba590ea1d618556a049e32a795dd6cb824dbf22f7d2c8f0fb1
Detection
ClamAV: Xls.Malware.Stratos-7506050-0
Obfuscation or payload: unlikely
objdata_02_off0005291d.bin rtf-objdata-decoded RTF \objdata at offset 0x5291D 82280 bytes
SHA-256: 40156da08d3ba97a6524b650103adffe5d90fc9bf9e0e4b40021306835eb8846
Detection
ClamAV: Xls.Malware.Stratos-7506050-0
Obfuscation or payload: unlikely
objdata_03_off0007bd22.bin rtf-objdata-decoded RTF \objdata at offset 0x7BD22 82280 bytes
SHA-256: 1b15276c4350152195df9ae7c11e7adddefe0c552f0228fe24075db29d69a9bf
Detection
ClamAV: Xls.Malware.Stratos-7506050-0
Obfuscation or payload: unlikely
objdata_04_off000a5127.bin rtf-objdata-decoded RTF \objdata at offset 0xA5127 82280 bytes
SHA-256: 3ad7406c0b906b48551c0e1927bcd164d48a037958301fd2d1ba4ce161deee6e
Detection
ClamAV: Xls.Malware.Stratos-7506050-0
Obfuscation or payload: unlikely
objdata_05_off000ce52c.bin rtf-objdata-decoded RTF \objdata at offset 0xCE52C 82280 bytes
SHA-256: 6353f4dba3de76027d6763c26668d845932aa49e8b3e1446c685789350b49991
Detection
ClamAV: Xls.Malware.Stratos-7506050-0
Obfuscation or payload: unlikely
objdata_06_off000f7931.bin rtf-objdata-decoded RTF \objdata at offset 0xF7931 82280 bytes
SHA-256: 3877eeec832bb785aac25b0f89f35849f0d34d13db214bf8e9644309ee7fb085
Detection
ClamAV: Xls.Malware.Stratos-7506050-0
Obfuscation or payload: unlikely
objdata_07_off00120d36.bin rtf-objdata-decoded RTF \objdata at offset 0x120D36 82280 bytes
SHA-256: b121f6647368a2ab8d5a59e572bb23fb9a5848e8ca9e59caabe8c01b661c6897
Detection
ClamAV: Xls.Malware.Stratos-7506050-0
Obfuscation or payload: unlikely
objdata_08_off0014a13b.bin rtf-objdata-decoded RTF \objdata at offset 0x14A13B 82280 bytes
SHA-256: 93f4952d94bf35a256863c02e13b4550349e87d3581864d44703bf6ce8f8c88f
Detection
ClamAV: Xls.Malware.Stratos-7506050-0
Obfuscation or payload: unlikely
objdata_09_off00173540.bin rtf-objdata-decoded RTF \objdata at offset 0x173540 82280 bytes
SHA-256: 2554a65f945710db75447690d9f93f245029716e31f164c9a1e848ba2a904320
Detection
ClamAV: Xls.Malware.Stratos-7506050-0
Obfuscation or payload: unlikely