Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 dfade43b170cbeef…

MALICIOUS

RTF / .DOC

7.2 KB
MD5: a8cfd32e2bd9180b0b7bf1dcdc880f99 SHA-1: 8e162cf763f149ac2d6436de1808df569a75f72b SHA-256: dfade43b170cbeefcb58db57df4095fb2c109f85af3dd6bc514cbf2a9d86b2b9
200 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The RTF document contains embedded OLE object data and specifically targets the Equation Editor component, triggering heuristics for OLE object activation and a known vulnerability (CVE-2026-21514). This indicates the file is designed to exploit a security bypass in Equation Editor to achieve arbitrary code execution.

Heuristics 5

  • CVE-2026-21514 — Word/OLE security bypass in RTF high CVE likely CVE_2026_21514
    RTF document contains an embedded OLE object with an Ole10Native stream. CVE-2026-21514 exploits OLE stream metadata validation in Word; the Ole10Native stream is used to deliver payloads and trigger the bypass when the document is opened.
  • Equation Editor CLSID critical RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • Automatically linked OLE object high RTF_OBJAUTLINK
    RTF contains \objautlink — an automatically linked OLE object surface that can be updated or activated when Word opens the document.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000003e.bin
ecfd4b2862bd0a1e47a808f902bf7602af09bcdf44de283fda37668712b9a625
rtf-objdata-decoded RTF \objdata at offset 0x3E 3640 bytes