Malicious Office (OOXML) / .DOCX — malware analysis report

Static analysis result for SHA-256 5875835796f05ac1…

MALICIOUS

Office (OOXML) / .DOCX

322.6 KB Created: 2016-07-28 11:04:00 UTC Authoring application: Microsoft Office Word 16.0000
MD5: 6976a6c4d2a219e23650c359ed1c87a5 SHA-1: 9b1ab8d630269546a3ea830d5a5793a1bd745583 SHA-256: 5875835796f05ac1960444de9c4eda1e08e4eafbc668b7aa71e3a51a73576130
180 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The sample is a malicious OOXML document that leverages the altChunk mechanism to import an embedded RTF file. This RTF file contains OLE objects and is configured to trigger an update via \objupdate, exploiting CVE-2026-21514. This indicates the document is designed to bypass security controls and execute embedded malicious content, likely a second-stage payload.

Heuristics 6

  • CVE-2026-21514 — Word/OLE security bypass in RTF high CVE likely CVE_2026_21514
    (in altChunk RTF word/el.rtf) RTF contains a hidden \svb hex package with DrsE2oDoc and downRevStg drawing compatibility parts. This matches an observed CVE-2026-21514 exploitation shape that manipulates Word's internal document structure and trust decisions.
  • altChunk imports embedded RTF (RTF injection) critical OOXML_ALTCHUNK_RTF
    Document inlines an embedded RTF via an aFChunk relationship and a <w:altChunk> body element. This is the canonical RTF-injection wrapper used to smuggle RTF exploits (Equation Editor / URL Moniker / objdata) past DOCX-only scanners. Word opens the wrapper and executes the RTF inline. Recursing into the RTF for the exact exploit primitive.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    (in altChunk RTF word/el.rtf) RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    (in altChunk RTF word/el.rtf) RTF contains 2 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    (in altChunk RTF word/el.rtf) RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.microsoft.com/office/drawing/2014/chartex
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2015/wordml/symex
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000af79f.bin
70680439422a115970299513c9a15844d3d99cf2ee2fda001d14dce3f78515eb
rtf-objdata-decoded RTF \objdata at offset 0xAF79F 78401 bytes
objdata_01_off000e0b9e.bin
7cedd8bade393af92a8beca2e2e4157dcb12a631247d0587ca24215aea88ac22
rtf-objdata-decoded RTF \objdata at offset 0xE0B9E 584266 bytes
rtf_svb_00000009.zip
28fc295dafc0bcccd998d6dc34a4e9ae47eb34cb74cb4b892eb6454833467799
rtf-svb-package RTF \svb hex-decoded ZIP at offset 0x9 116932 bytes