Malicious RTF — malware analysis report

Static analysis result for SHA-256 5d5d4fa2330efa3d…

MALICIOUS

RTF

111.6 KB First seen: 2026-06-11
MD5: b135e8f3a5a927ba6abadb04d9e06da8 SHA-1: 5d7956d14ab007c86acf4b49a13228ede89ee3d7 SHA-256: 5d5d4fa2330efa3d8e513717b070684948facec5d9c27b5c8ed38c5f74f55728
80 Risk Score

Heuristics 3

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000011a8.bin rtf-objdata-decoded RTF \objdata at offset 0x11A8 4282 bytes
SHA-256: f022587885149eef70271dc7229aa51c8025f854c51a219e96585f6962ec44f7