Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 f81e70c6951855e2…

MALICIOUS

RTF / .DOC

1.68 MB Created: 2026-01-27 07:43:00 First seen: 2026-03-01
MD5: 6ae497e1b1ba531753fa111520f215b6 SHA-1: e272b1abcdfc65f38799dc0064694dc9b0a6d055 SHA-256: f81e70c6951855e27ea34f60a6a32e55148a3a09dea84a3feacbeb649357ceee
122 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment T1059.001 PowerShell

The RTF file contains OLE object data with excessive hex-encoded data, indicative of a hidden payload. A critical heuristic identified the CVE-2026-21509 vulnerability, which is associated with the Shell.Explorer.1 CLSID in RTF files. This suggests the document is designed to exploit this vulnerability to achieve arbitrary code execution, likely for downloading and executing a second-stage payload. No scripts were extracted, and the document body content appears benign, focusing on consultation topics related to Ukraine.

Heuristics 4

  • CVE-2026-21509 — Shell.Explorer.1 CLSID in RTF critical CVE related CVE_2026_21509
    RTF document contains the Shell.Explorer.1 CLSID {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} associated with CVE-2026-21509 (OLE/COM Killbit / Protected View bypass). Actively exploited in the wild.
  • Large hex data blocks in OLE object high RTF_EXCESSIVE_HEX
    RTF contains ~1689KB of hex-encoded data inside \objdata sections — may hide a payload
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wo

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off001ac71b.bin
36a13c9488aaf0ed34254a7f44d963f4b06c214f4438857aec5cbad64049111d
rtf-objdata-decoded RTF \objdata at offset 0x1AC71B 2809 bytes
objdata_01_off001add71.bin
9368bcc57c086f9d26792eee0120444a676c7694ba691b243d066085fcb4cba3
rtf-objdata-decoded RTF \objdata at offset 0x1ADD71 2609 bytes