Malicious RTF — malware analysis report

Static analysis result for SHA-256 e52636f986eafe2c…

MALICIOUS

RTF

288.8 KB Authoring application: Riched20 10.0.17134 First seen: 2019-02-10
MD5: d170748f4b2974ecf96bab4aa5a74004 SHA-1: a29d1183a14f083c93ca0458790a55ce5b44e815 SHA-256: e52636f986eafe2cb3d69e0f59747ce41fd328cbfe98f78686b34f63d12eaa33
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains multiple embedded OLE objects, with one specifically triggered by the \objupdate directive. This suggests the file is designed to exploit OLE object activation to execute a secondary payload. The ClamAV detection 'Doc.Dropper.Agent-6949325-0' further supports its role as a dropper.

Heuristics 5

  • ClamAV: Doc.Dropper.Agent-6949325-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6949325-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 5 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • OlePres presentation stream in RTF OLE object medium RTF_OLEPRES_STREAM
    RTF contains an embedded OLE object with an OlePres presentation stream. OlePres is an OLE presentation marker and is not enough on its own to identify CVE-2025-21298.

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000010d.bin rtf-objdata-decoded RTF \objdata at offset 0x10D 28724 bytes
SHA-256: af57870aef8c01da82c32485722c5fe5dd74b4643c840d589d95495a0234e414
objdata_01_off0000e7ec.bin rtf-objdata-decoded RTF \objdata at offset 0xE7EC 28724 bytes
SHA-256: 838623aa28ae8ce01d377871a7386842e5ee079c56fb056cc0695d3cd93efcb1
objdata_02_off0001cecb.bin rtf-objdata-decoded RTF \objdata at offset 0x1CECB 28724 bytes
SHA-256: 0c3fb92a56e02ed0b5d7b2b387ba0b9b98f75d24d981398a5cc2131f4b04ce1b