← All detection heuristics · RTF
high
RTF_REMOTE_TEMPLATE
What it means
The RTF's \*\template destination is a remote URL/UNC path that Word fetches and loads on open.
Why it fires
RTF template injection (MITRE T1221): the document attaches a remote template via {\*\template <url>}. On open, Word retrieves and loads it, which can deliver a macro/exploit template, a scriptlet/HTA (.html/.hta target), or leak NTLM credentials over a UNC path. Benign RTFs attach only a local template, so a remote target is the injection itself. Obfuscated targets (\uN/\'xx escapes), raw-IP or dynamic-DNS hosts, and active/script extensions escalate it to critical.
Other RTF heuristics
RTF_EQUATION_EDITOR RTF_OBJCLASS_EQUATION RTF_MZ_HEX RTF_DDEAUTO_REGSVR32_SCRIPTLET RTF_MACOS_ZSH_LOADER RTF_PACKAGE_AUTOLINK_DELIVERY RTF_OBJAUTLINK RTF_INCLUDE_REMOTE RTF_EXCESSIVE_HEX RTF_PACKAGE_OLE RTF_OBFUSCATION RTF_PHP_IRC_BOT_SOURCE RTF_OBJCLASS_PACKAGE RTF_EXPLOIT_TEMPLATE_ARTIFACT RTF_OBJUPDATE_LOOSE_HEX_PAYLOAD RTF_OBJUPDATE RTF_PFRAGMENTS_RELATED RTF_OBJEMB RTF_WORD_COMPATIBILITY_PACKAGE RTF_OBJDATA RTF_OLEPRES_STREAM RTF_OLE10NATIVE_STREAM