MALICIOUS
182
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
T1566.001 Spearphishing Attachment
The RTF file contains multiple indicators of exploitation, including OLE object data and explicit triggers for OLE activation. High-severity heuristics identify vulnerabilities CVE-2017-8759 and CVE-2026-21514, which are known to allow arbitrary code execution when the document is opened. This suggests the file is designed to exploit these flaws to download and execute a secondary payload.
Heuristics 6
-
CVE-2017-8759 — MSXML SAX OLE activation critical CVE likely CVE_2017_8759RTF contains a hex-encoded OLE1 object for Msxml2.SAXXMLReader.6.0 followed by an embedded OLE compound document, and the document requests OLE activation. This matches the RTF staging shape used for CVE-2017-8759 SOAP/WSDL parser code injection.
-
CVE-2026-21514 — Word/OLE security bypass in RTF high CVE likely CVE_2026_21514RTF contains a hidden \svb hex package with DrsE2oDoc and downRevStg drawing compatibility parts. This matches an observed CVE-2026-21514 exploitation shape that manipulates Word's internal document structure and trust decisions.
-
\objupdate forces OLE activation high RTF_OBJUPDATERTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
-
OLE object data medium RTF_OBJDATARTF contains 9 \objdata section(s) — embedded OLE objects
-
Embedded OLE object medium RTF_OBJEMBRTF contains \objemb — embedded OLE object
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.microsoft.com/office/word/2003/wordml
Extracted artifacts 10
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
objdata_00_off00002ce7.bin8a017c17b7075ee07cb1883811a854a3ed042fe0d11edb7ab5e9ee05664c38bf |
rtf-objdata-decoded | RTF \objdata at offset 0x2CE7 | 24635 bytes |
objdata_01_off0001473f.bin96191cfac62880a84588a0b9fe7b4e4ec0848d290638a1b64575888a26468c23 |
rtf-objdata-decoded | RTF \objdata at offset 0x1473F | 24635 bytes |
objdata_02_off00026197.binec488a996a4ab908290eae1e0a25e319f2b2ab9f6fa91982a99d25373387fda5 |
rtf-objdata-decoded | RTF \objdata at offset 0x26197 | 24635 bytes |
objdata_03_off00037bef.bin543df9838a1ae148849ab2a3cec68df9938ae3aa8eb30e4c4325c07824226c3d |
rtf-objdata-decoded | RTF \objdata at offset 0x37BEF | 24635 bytes |
objdata_04_off00049647.binef23adaf01638e367fe681db762c28997d42b2898d714eae38971329b5666061 |
rtf-objdata-decoded | RTF \objdata at offset 0x49647 | 24635 bytes |
objdata_05_off0005b09f.binab5d283abb780bb13cd937d409a9442414b003dcd72d8c06d78d36d484385774 |
rtf-objdata-decoded | RTF \objdata at offset 0x5B09F | 24635 bytes |
objdata_06_off0006caf7.bin0d9989a9905e110a0d5508b915f20c387d40687afec67a308b169b30beef8c43 |
rtf-objdata-decoded | RTF \objdata at offset 0x6CAF7 | 24635 bytes |
objdata_07_off0007fbd3.bincc052fedb73926e49ca78ce42513b346333006180a952372f019dd4e10471a65 |
rtf-objdata-decoded | RTF \objdata at offset 0x7FBD3 | 24635 bytes |
objdata_08_off0009162b.bin4754f0cac4dedd1aff6a1355379aa38408b35b53880b18cea812d351c3805b45 |
rtf-objdata-decoded | RTF \objdata at offset 0x9162B | 24635 bytes |
rtf_svb_0007e70f.zip366882e6fdbcd59074b2d34677683675916635cc14c7cb4447502d1461e3a131 |
rtf-svb-package | RTF \svb hex-decoded ZIP at offset 0x7E70F | 1697 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.