Malicious RTF — malware analysis report

Static analysis result for SHA-256 5dfc7a6d0ec07678…

MALICIOUS

RTF

149.3 KB Created: 1998-11-23 19:37:00 First seen: 2015-09-20
MD5: 373dc23a4078eed01c570993f2ebf2b0 SHA-1: 37997245257761ba9352c7a3ccd9491ea95a7425 SHA-256: 5dfc7a6d0ec07678da87a337d33974d61ece417c3cb6d6050e88f390acf527a2
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains embedded OLE objects, specifically a composite moniker, which is a common technique for exploiting vulnerabilities or delivering malicious content. The document body presents a seemingly benign email about report comments, likely a social engineering lure. The presence of OLE objects and the ClamAV detection strongly suggest malicious intent, likely involving exploitation of a vulnerability via the embedded object.

Heuristics 5

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Doc.Trojan.Class-37 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.Class-37
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • OlePres presentation stream in RTF OLE object medium RTF_OLEPRES_STREAM
    RTF contains an embedded OLE object with an OlePres presentation stream. OlePres is an OLE presentation marker and is not enough on its own to identify CVE-2025-21298.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000c33.bin rtf-objdata-decoded RTF \objdata at offset 0xC33 71356 bytes
SHA-256: 331148f332ec2b0340ca74d6742121aaab6a12269a1ba00173d501250c103f37