Malicious RTF — malware analysis report

Static analysis result for SHA-256 5ea298a20718f726…

MALICIOUS

RTF

87.3 KB First seen: 2026-06-19
MD5: 779e0fc6a5318e87a23a6ace277249d6 SHA-1: 024068fd58bfc6d7d9b88a5657da0cbf41676b9a SHA-256: 5ea298a20718f726a4747b60e01554e8bff2b9ab3a5fe33cc63a2d8159a53915
60 Risk Score

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000bd0.bin rtf-objdata-decoded RTF \objdata at offset 0xBD0 4198 bytes
SHA-256: ba0cadad3e14c280de2b72e06a2d56e3c2182b22ffba7297dff1f6fe4ea8ca49