Malicious RTF — malware analysis report

Static analysis result for SHA-256 f36542b449e0b164…

MALICIOUS

RTF

279.0 KB Created: 2026-04-01 23:35:00 First seen: 2026-04-02
MD5: 3ad3813b6d76db98a0d89786a299b798 SHA-1: 587ea7ed279423b0bf58e3883adb360ff064d148 SHA-256: f36542b449e0b164bf0927d48bd934aa0e66bd2fab483f532cf2010f3fc9d02b
82 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment T1059.001 PowerShell

The RTF document contains embedded OLE object data, specifically triggering the critical heuristic CVE_2026_21509. This indicates the exploitation of a known vulnerability (CVE-2026-21509) related to the Shell.Explorer.1 CLSID within RTF files. The presence of this exploit suggests the document is designed to execute arbitrary code upon opening, likely as a means to download and run a secondary malicious payload. The document body itself appears to be a benign agenda, suggesting the malicious functionality is entirely contained within the exploit.

Heuristics 3

  • CVE-2026-21509 — Shell.Explorer.1 CLSID in RTF critical CVE related CVE_2026_21509
    RTF document contains the Shell.Explorer.1 CLSID {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} associated with CVE-2026-21509 (OLE/COM Killbit / Protected View bypass). Actively exploited in the wild.
  • OLE object data medium RTF_OBJDATA
    RTF contains 3 \objdata section(s) — embedded OLE objects
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00010d1a.bin
4443d5aa1b979f173e17490df80a8e53e5893ac896f7ae1b779793f10de33d59
rtf-objdata-decoded RTF \objdata at offset 0x10D1A 418 bytes
objdata_01_off000144cd.bin
d6bc2a88817db649a1314865aa1c9c651e19e04c338ca7890ebd1577abe9a626
rtf-objdata-decoded RTF \objdata at offset 0x144CD 2565 bytes
objdata_02_off000299a6.bin
700a88ceada129429444247582a5821764c7e800c6dc3b361d8ca443b96743c1
rtf-objdata-decoded RTF \objdata at offset 0x299A6 2565 bytes