MALICIOUS
260
Risk Score
Heuristics 6
-
MSCOMCTL.ListView RTF object with shellcode — CVE-2012-0158 critical CVE likely CVE_2012_0158RTF embeds an MSCOMCTL ListView ActiveX object in \objdata and the same object stream contains shellcode-like hex bytes (NOP sled plus function-prologue/GetPC style code). This is the weaponized RTF delivery shape of CVE-2012-0158, including payload evidence, not just a benign reference to the control.
-
CVE-2012-0158 RTF embedded encrypted payload high RTF_CVE_2012_0158_EMBEDDED_PAYLOADThe CVE-2012-0158 document embeds a large high-entropy binary blob — the encrypted/packed second-stage payload the exploit shellcode drops and runs. Hex-encoded object data cannot reach this entropy, so the region is genuine binary, not markup. The payload is encrypted in the file, so it is surfaced as an IOC (offset, size, SHA-256) rather than a decoded executable.
-
ClamAV: Rtf.Exploit.Cve_2014_1761-2 critical CLAMAV_DETECTIONClamAV detected this file as malware: Rtf.Exploit.Cve_2014_1761-2
-
XOR-encoded strings (key 0xF3) critical SC_XOR_ENCODEDFound 2 Windows library/API name(s) XOR-encoded with single-byte key 0xF3: 'advapi32.dll', 'advapi32.dll'Disassembly hidden — these bytes score as data, not coherent x86 code (4/8 branch targets land on an instruction boundary (50% coherence)).
-
OLE object data medium RTF_OBJDATARTF contains 2 \objdata section(s) — embedded OLE objects
-
OlePres presentation stream in RTF OLE object medium RTF_OLEPRES_STREAMRTF contains an embedded OLE object with an OlePres presentation stream. OlePres is an OLE presentation marker and is not enough on its own to identify CVE-2025-21298.
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
objdata_00_off00000080.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x80 | 14938 bytes |
SHA-256: 43b38d2893b3e8f015394ec8b01b41c9a09ea082c5ef1e57531bb6c69ecca39e |
|||
objdata_01_off00007868.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x7868 | 5686 bytes |
SHA-256: ad7105df08ae2e1fd0ab47f30e3cce6337c3e810b110fb3c76da50ee3f0dd4d0 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.