Malicious RTF — malware analysis report

Static analysis result for SHA-256 8c5787410a673152…

MALICIOUS

RTF

316.7 KB
MD5: 5fff1ed477dbdfd31a26849aa315431e SHA-1: 5efc547efc373a7287841827e3dc9079b2522f39 SHA-256: 8c5787410a673152aee51586f601be88e0afb134fb381e9866d29049b38878d0
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains an embedded OLE object, indicated by multiple RTF_OBJ* heuristic firings. ClamAV detected this as Doc.Trojan.Marker-31. The embedded object, objdata_00_off000002a0.bin, is a strong indicator of malicious intent, likely serving as a container for a secondary payload. The document body content is benign, suggesting the maliciousness is solely within the embedded object.

Heuristics 5

  • ClamAV: Doc.Trojan.Marker-31 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.Marker-31
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • OlePres presentation stream in RTF OLE object medium RTF_OLEPRES_STREAM
    RTF contains an embedded OLE object with an OlePres presentation stream. OlePres is an OLE presentation marker and is not enough on its own to identify CVE-2025-21298.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000002a0.bin
44be8be047d678c09159fefbb75b5abec020f47844e8a1643f477281204e33b5
rtf-objdata-decoded RTF \objdata at offset 0x2A0 153906 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.