MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious File
The file is an RTF document that contains multiple embedded OLE objects, as indicated by the RTF_OBJDATA and RTF_OBJEMB heuristics. The ClamAV detection 'Doc.Trojan.Thus-10' strongly suggests malicious intent. While the document body appears to be a legitimate academic abstract, the presence of embedded objects points to a delivery mechanism for a secondary payload. No specific family could be identified.
Heuristics 4
-
ClamAV: Doc.Trojan.Thus-10 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Trojan.Thus-10
-
OLE object data medium RTF_OBJDATARTF contains 2 \objdata section(s) — embedded OLE objects
-
Embedded OLE object medium RTF_OBJEMBRTF contains \objemb — embedded OLE object
-
OlePres presentation stream in RTF OLE object medium RTF_OLEPRES_STREAMRTF contains an embedded OLE object with an OlePres presentation stream. OlePres is an OLE presentation marker and is not enough on its own to identify CVE-2025-21298.
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
objdata_00_off0001d555.binec6e0152ce093ae38bb06c9aa0d86f0a5cf2621d891fc42423a7ffa019ac8f70 |
rtf-objdata-decoded | RTF \objdata at offset 0x1D555 | 27185 bytes |
objdata_01_off000387bf.bin657fbfe5055eb57d087b48844441b1e2d3ce7f7dc25b5337dfdfb5b21a9d4d27 |
rtf-objdata-decoded | RTF \objdata at offset 0x387BF | 56113 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.