
On June 15, 2016 - just one day after the DNC announced it had been hacked by Russian intelligence - a new persona emerged online calling itself "Guccifer 2.0." This mysterious figure claimed to be a lone Romanian hacker and published what appeared to be leaked DNC documents as proof.
Within weeks, cybersecurity firms and the U.S. intelligence community attributed Guccifer 2.0 to Russian military intelligence (GRU). The documents became central evidence in the narrative of Russian interference in the 2016 election. But a peculiar detail emerged: the files contained obvious Russian-language metadata - the kind of "fingerprints" that seemed too careless for a sophisticated intelligence operation.
Were these Russian breadcrumbs genuine mistakes? Deliberate false flags? Or something else entirely?
This forensic analysis reveals how some of those documents were actually made.
Guccifer 2.0’s first three released documents were not independent files. Structural analysis of their raw RTF data shows that 2.doc and 3.doc were created by duplicating 1.doc at the file-system level and replacing its content.
The evidence is technical and reproducible:
A 38,637-byte stylesheet block appears byte-for-byte identical in all three files.
The block contains Russian-language style strings and the RSID 11758497, which originated during the editing session that produced 1.doc.
All three files share identical creation timestamps and the same document ancestry marker (rsidroot).
The metadata pattern matches file-system copying rather than Microsoft Word’s “Save As” behaviour.
The result is three documents with different visible content but identical inherited Russian-language metadata.
This establishes structural duplication and metadata inheritance. It does not, by itself, determine ultimate attribution. It demonstrates the workflow used to produce the files.
Document #1 was created by opening a Podesta email attachment (that was originally created in 2008) in Microsoft Word configured with Russian language settings (registered to “Феликс Эдмундович”), then pasting in Trump opposition research. That process introduced Russian-language metadata and editing markers into the file.
Documents #2 and #3 were not created independently. Instead, they were produced by copying the already-modified 1.doc at the file-system level and pasting new content into each duplicate. As a result, all three files share the same inherited Russian-language artefacts.
The shared 38KB stylesheet block and RSID patterns show that the Russian-language metadata in these documents was structurally propagated through duplication rather than independently introduced into each file.
This analysis establishes construction methodology at the document level - not motive or attribution. Whether the duplication workflow was deliberate, incidental, or part of a broader operation is a separate question beyond what document structure alone can resolve.
What is demonstrable is that these documents were not released in their original form. They were produced through a reproducible process of duplication and content replacement - a process that can be independently verified using the linked source files
Here's what the forensic evidence shows happened:
Step 1: Open Warren Flood's 2008 DNC document in Word 2007 configured for Russian language/user
↓
Step 2: Paste Trump opposition research → Creates Document #1 with Russian contamination
↓
Step 3: Copy Document #1 file twice (not "Save As" in Word)
↓
Step 4: Open first (pre-contaminated) copy, paste talking points content → Document #3
↓
Step 5: Open second (pre-contaminated) copy, paste GOP strategy content → Document #2
↓
Result: Three documents with different content but identical Russian metadata
The key finding: Documents #2 and #3 contain a 38KB block of Russian-contaminated formatting data that only makes sense in Document #1. This supports the conclusion that they were copies of #1, not independently created files.
Note: The order above shows what order the documents were opened in. The evidence indicates Guccifer 2.0 opened 3.doc before 2.doc and saved 2.doc before the final save of 3.doc. (i.e. It looks like the operation quickly worked on 2.doc while 3.doc was being worked on.). This is supported by edmins and revtim properties covered later in this article.
For attribution:
If Russian-language metadata had been introduced independently in multiple files, we would expect variation in editing histories and contamination markers. Instead, we observe systematic inheritance of the same 38KB stylesheet block and RSIDs across documents. This shifts the question from “Why was Russian metadata present?” to “Why was the same metadata propagated?”
For the documents themselves:
The released RTF files were not untouched originals. They were produced through duplication and content replacement of a modified base document. That distinction matters when evaluating how the files were prepared prior to release.
For verification:
Unlike much of the public attribution debate - which relies on classified intelligence - these findings are based on publicly available files and can be independently reproduced using Word 2007 and a text editor.
Primary finding: A 38,637-byte block of stylesheet data - containing Russian-language codes and unique editing markers - appears byte-for-byte identical in three separate Guccifer 2.0 documents.
Why it matters: This block is technically coherent in Document #1 (where Trump research was pasted), but appears in Documents #2 and #3 despite their completely different content - proving template reuse rather than independent creation.
How to verify: Click the highlighted viewer links throughout this article to compare the same byte ranges across files and confirm the shared RSIDs, Cyrillic strings, and metadata fields directly.
Before the technical walkthrough, here are the concepts this analysis relies on:
Stylesheet data: Word’s embedded formatting rulebook (styles, fonts, numbering, spacing). It can be carried along even when document content changes.
RSID (Revision Session ID): a value Word assigns to mark changes made during an editing session. RSIDs persist inside the file and are useful for tracing document lineage when files are duplicated and repurposed. RSIDs are essentially 32 bit IDs that identify changes occurring within the same unique document editing session.
Document grafting: copying content from one document and pasting it into another.
Metadata: embedded fields not visible in normal reading (author/operator strings, timestamps, language settings, and other internal markers).
Russian breadcrumbs: Specific technical markers indicating Russian language/user configuration:
These markers appear when documents are created or edited using Word configured for Russian language/region settings.
For Quick Verification (Recommended):
For Deep Verification (Advanced):
Most readers won't need the advanced tools - the browser-based viewer shows everything you need to verify the findings.
To verify that Guccifer 2.0's documents were created with Word 2007, view this 5-minute verification guide.
In 2018, an independent researcher known as Forensicator published a detailed analysis of how Guccifer 2.0 created the document "1.doc":

Did Guccifer 2.0 Plant His
Russian Fingerprints?
What Forensicator Discovered:
The Result: An odd hybrid document containing Trump research, but saturated with:
The stylesheet block is a large chunk of formatting data embedded in Word documents. In Guccifer 2.0's files, this ~38,000 byte block contains:
Here's what a small portion looks like (the full block is 38KB of similar code):
\sbasedon52 \snext50 \slink51 \sqformat \spriority0 \styrsid11758497 Sub-Bullet;}
{\\*\cs51 \additive \rtlch\fcs1 \af31507\afs24 \ltrch\fcs0
\f1\fs24\lang1033\langfe1033\langnp1033\langfenp1033
\sbasedon10 \slink50 \slocked \spriority0 \styrsid11758497

This identical 38KB block appears in three documents Guccifer 2.0 posted on June 15, 2016:
View the stylesheet block in each document:
Click any of these links to see the exact same 38KB block highlighted. You can scroll through it and see the identical RSID numbers, Cyrillic text, and Russian language codes.
Download the original files:
This is the crucial question. The stylesheet block isn't just random formatting data - it's specifically tied to the editing session where Trump research was pasted into document #1.
The Evidence: The RSID "11758497" that appears throughout the stylesheet block is the same RSID that marks where content was inserted throughout 1.doc.
Look at how this RSID appears in the actual document content:
In 1.doc's stylesheet definition (creating a style):
View highlighted: character style 63 definition

In 1.doc's body content (using that same style):
View highlighted: character style 63 being used

Both tagged with \styrsid11758497 and \insrsid11758497 - showing they're part of the same editing session.
If you search through 1.doc, you'll find \insrsid11758497 appears 8,589 times, marking all the pasted Trump research content. Search with your browser throughout 1.doc.

What This Means: The 38KB stylesheet block directly supports the content in 1.doc. It's the formatting rulebook for text that was pasted during editing session #11758497.
The key evidence: The RSID tagging proves this stylesheet's origin. STYRSID 11758497 marks when these styles were created - during the Trump oppo paste operation in 1.doc. When 2.doc and 3.doc were created by copying 1.doc at the file-system level, they inherited this contaminated stylesheet wholesale, complete with its RSID tags proving it came from that editing session.
Observation: All three documents share identical watermark and footer formatting, inherited from copying 1.doc.
The fundamental question: Why would an intelligence agency modify and graft leaked documents together like this?
Document modification introduces traceable structural artefacts and can complicate claims of original provenance.
It:
Three pieces of metadata prove these documents descended from the same source file:
All three documents share the exact same creation timestamp:
View the creation time in each file:
Click each link to see the identical \creatim\yr2016\mo6\dy15\hr13\min38 timestamp highlighted in the file.
Why this matters: When you use "Save As" in Microsoft Word, the creation time (\creatim) is updated to the current time. The fact that all three documents share identical creation times - down to the exact second - supports file-system copying (which preserves the original creation timestamp) rather than through "Save As" operations.
The presence of the identical 38KB stylesheet block in all three files - contaminated with Russian metadata and tagged with RSID 11758497 - is itself evidence of copying.
The RSID tagging proves the block originated in 1.doc's Trump oppo paste session. If 2.doc and 3.doc were created independently, they wouldn't inherit these specific RSID markers from 1.doc's editing history. The shared RSID tags prove file-level duplication.
Beyond the shared root and stylesheet, there's an even more detailed fingerprint: the RSID table. Each Word document contains a table listing all the revision session IDs that have touched the file throughout its history.
View the RSID tables:
When we compare these tables across all three Guccifer 2.0 documents AND their source materials, a striking pattern emerges:
Key Findings from RSID Analysis:
Shared contamination RSIDs - Multiple RSIDs appear in all three Guccifer documents:
Source-specific RSIDs - Each document also contains RSIDs from its pasted content:
This dual pattern - shared contamination RSIDs plus source-specific RSIDs - proves the documents were created by pasting clean content into contaminated shells.
What makes RSID 11758497 special:
Complete RSID Comparison Table:
For the complete detailed RSID table with all 400+ entries, click here.
Sample of key RSIDs:
| RSID | G2-1 | G2-2 | G2-3 | Source-1 | Source-2 | Source-3 | Flood |
|---|---|---|---|---|---|---|---|
| 1125774 | ✓ | ✓ | ✓ | - | - | - | ✓ |
| 4678604 | ✓ | ✓ | ✓ | - | - | - | ✓ |
| 5602882 | ✓ | ✓ | ✓ | - | - | - | ✓ |
| 6842998 | ✓ | ✓ | ✓ | - | - | - | ✓ |
| 11758497 | ✓ | ✓ | ✓ | - | - | - | - |
| 9588946 | ✓ | ✓ | ✓ | - | - | - | - |
| 16453316 | ✓ | ✓ | ✓ | - | - | - | ✓ |
| 2119710 | ✓ | - | - | ✓ | - | - | - |
| 5703012 | ✓ | - | - | ✓ | - | - | - |
| 4737387 | - | ✓ | - | - | ✓ | - | - |
| 9764998 | - | ✓ | - | - | ✓ | - | - |
| 656492 | - | - | ✓ | - | - | ✓ | - |
| 2310076 | - | - | ✓ | - | - | ✓ | - |
Legend:
What this proves:
The RSID table analysis provides evidence of the copying workflow:
All three documents also share the same rsidroot (16453316), which originated in Warren Flood's 2008 document.
This proves common deep ancestry - all three descended from the Flood document that was used to create 1.doc. However, this shared ancestry doesn't tell us how 2.doc and 3.doc were created; it only confirms they all trace back to the same 2008 foundation. The evidence above (creation times, stylesheet block, RSID tables and pivotal 11758497 RSID) shows that 2.doc and 3.doc were specifically duplicated from 1.doc rather than created independently from the Flood document.
View the rsidroot in each file:
Understanding how Guccifer 2.0 made these copies matters because different methods leave different metadata fingerprints. We can rule out possibilities systematically.
Here's the key metadata from all three documents:
| 1.doc | 2.doc | 3.doc | |
| \creatim Creation Time |
2016-06-15 13:38 |
2016-06-15 13:38 |
2016-06-15 13:38 |
| \printim Print Time |
2016-06-15 13:45 |
2016-06-15 13:45 |
2016-06-15 13:56 |
| \revtim Revision Time |
2016-06-15 14:08 |
2016-06-15 14:11 |
2016-06-15 14:12 |
| \edmins Editing Minutes |
2 | 2 | 4 |
| \version Document Revision |
4 | 5 | 7 |
| \author Created By |
Warren Flood | Warren Flood | Warren Flood |
| \operator Last Mod By |
Феликс Эдмундович | Феликс Эдмундович | Феликс Эдмундович |
Click any value to see it highlighted.
All times are based on the local system clock of the machine performing the action.
Note: For Cyrillic characters you will see character codes. For example, "Феликс Эдмундович" will appear as "\'d4\'e5\'eb\'e8\'ea\'f1 \'dd\'e4\'ec\'f3\'ed\'e4\'ee\'e2\'e8\'f7"
How it works: Open a document, click File → Save As, give it a new name.
Expected metadata signature:
What we actually observe:
Verdict: If "Save As" had been used to create 2.doc and 3.doc, each would have received a new creation time reflecting when it was saved. The identical timestamps prove these files were copied at the file-system level, not created through "Save As."
How it works: Create 1.doc, save as 2.doc, edit 2.doc, save as 3.doc, edit 3.doc.
Also applies to: Save a working document, copy the file and rename it to "1.doc", continue editing and save again, copy the file and rename it to "2.doc", continue editing and save again as "3.doc".
What we would expect:
What we actually observe:
Verdict: The math doesn't work, and the contamination pattern doesn't fit. 3.doc did not derive from 2.doc.
How it works:
Expected metadata signature:
What we observe: Perfect match.
Conclusion: Guccifer 2.0 duplicated 1.doc outside of Word - using file system copying - then opened each copy separately in Word 2007 to paste in new content.
This is how the Russian contamination propagated: the copies were pre-contaminated before any new content was added.
Understanding how Guccifer 2.0 made these copies matters because different methods leave different metadata fingerprints.
Note: The identical editing time between 1.doc and 2.doc (both showing 2 minutes) might appear anomalous, but this is due to Word 2007's minute-bucket tracking. If you open, edit, and save a document within the same clock minute, the editing time counter doesn't increment. This behavior is easily reproducible and documented in our verification guide.
To understand the construction process, we need to know what content ended up in each file and if this content was found in other documents that were leaked.
The following documents were identified as having matching content including multiple RSID overlaps.
Content: Trump opposition research
Source: WikiLeaks Podesta Email #26562
Attachment: "Donald Trump Report – Opposition Research"
View original attachment
Framework: Warren Flood's 2008 document
Source: Podesta Email #41518
Attachment: "Slate_-Domestic-USDA-_2008-12-20.doc"
View original attachment
Process: Flood document opened in Russian-registered Word → Trump research pasted in → Russian contamination created
Content: GOP strategy document
Source: WikiLeaks Podesta Email #55782
Attachment: "Strategy on GOP 2016ers.docx"
View original attachment
Framework: Copy of the already-contaminated 1.doc
Process: Pre-contaminated copy opened → GOP strategy pasted in → Russian contamination preserved
Content: Candidate talking points
Source: WikiLeaks Podesta Email #3405
Attachment: "Candidate Talking Points - all changes.docx"
View original attachment
Framework: Another copy of the already-contaminated 1.doc
Process: Pre-contaminated copy opened → Talking points pasted in → Russian contamination preserved
| Scenario | Expected RSID Pattern | Expected Stylesheet | What We Actually See |
|---|---|---|---|
| Three independent documents (separate leaks) |
Each has unique RSIDs from its own editing history. No shared contamination RSIDs. | Each has its own stylesheet matching its content and formatting needs. | ❌ All three share RSID 11758497 + identical 38KB stylesheet |
| Innocent format reuse (liked the watermark) |
RSIDs from format source, but no contamination RSIDs in content areas. | Minimal shared stylesheet (just watermark/footer styles). Each doc adds its own content styles. | ❌ Complete 38KB stylesheet block shared, tagged with contamination RSID |
| Careless random contamination (sloppy work) |
Different contamination patterns in each file. Random, not systematic. | Different Russian artifacts in each file, inconsistent patterns. | ❌ Identical contamination RSID across all files, identical stylesheet |
| Sequential editing (1→2→3) (progressive workflow) |
2.doc has RSIDs from both 1.doc and 2.doc content. 3.doc has RSIDs from all three. | 3.doc would accumulate style contamination from 2.doc, creating layered complexity. | ❌ 3.doc has only 1.doc contamination, not 2.doc. Timeline doesn't fit. |
| File duplication workflow (copy contaminated template) |
All files share contamination RSIDs from template. Each adds source-specific RSIDs. | Identical stylesheet inherited from template, byte-for-byte match. | ✓ Perfect match |
The key distinction: Independent document creation or innocent reuse would produce variation. We see replication - the signature of systematic copying from a contaminated template.
This analysis establishes something more specific than the presence of Russian-language metadata. It reconstructs the document workflow used to produce the files.
The structural evidence indicates that a pre-modified base document was duplicated and reused, resulting in systematic inheritance of its Russian-language metadata.
Create modified base file - A copy of a 2008 DNC document is opened in Word 2007 configured with Russian language settings, and new content is pasted into it, producing 1.doc with embedded Russian-language metadata and RSIDs.
Duplicate at file-system level - 1.doc is copied outside of Word (i.e. not duplicated via Word’s Save/Save-As functions)..
Open each duplicate separately - Each copied file is opened independently in Word.
Replace content - New content is pasted into each duplicate.
Save and release - The duplicated files retain the inherited metadata from the original modified base file.
Result: Three documents with different visible content but identical embedded editing history.
The structural pattern observed here is difficult to reconcile with several common explanations.
Independent document creation:
If each file were created separately - even in a Russian-configured environment - we would expect variation in editing histories and stylesheet structure. Instead, we observe replication: an identical 38KB block and shared RSIDs.
Simple formatting reuse:
If only visible formatting elements were reused, we would expect limited overlap in style definitions. Instead, the entire stylesheet block - including editing-session-specific RSIDs - was inherited intact.
Random or careless contamination:
Accidental metadata leakage would likely produce inconsistent patterns across files. Instead, the same contamination markers appear in all three documents, unchanged.
These patterns are consistent with duplication of a pre-modified base file followed by content replacement.
Document structure alone cannot determine whether this duplication was deliberate or incidental. It does, however, establish the mechanism by which the metadata propagated.
The metadata patterns allow several possible interpretations. The question is which explanation best matches the observable structure of the files.
If the three files had been created independently - even on the same Russian-configured system - we would expect:
Distinct editing histories
Variation in RSID patterns
Differences in stylesheet structure
Instead, we observe:
A byte-for-byte identical 38KB stylesheet block
The same contamination RSID (11758497) across all three
Identical creation timestamps
This pattern reflects duplication of an existing file rather than three separate editing sessions.
If 2.doc and 3.doc were created using Microsoft Word’s “Save As” function, we would expect:
New creation timestamps
Incremental revision lineage
Metadata reflecting sequential derivation
Instead, all three share the same \creatim value down to the second.
This behaviour is consistent with copying outside of Microsoft Word (e.g., via the operating system), not “Save As.”
If Russian-language metadata were introduced accidentally in multiple files, we would expect:
Variation in contamination markers
Different RSIDs associated with each file
Inconsistent propagation patterns
Instead, we observe replication: the same stylesheet block and RSID structure carried forward intact.
The contamination pattern is uniform across files rather than variable.
The structural indicators - shared stylesheet block, shared RSIDs, identical timestamps, and common ancestry markers - are consistent with duplication of a pre-modified base document followed by content replacement.
Document structure alone cannot determine the operator’s intent.
It does, however, establish the mechanism by which the Russian-language metadata propagated across files
Proven and verifiable facts:
How you can verify:
Click any of the highlighted links in this article to see the evidence in the actual files. No special software required - just your browser. Source files are also linked to from the viewer pages.
What this demonstrates:
The Russian fingerprints in Guccifer 2.0's documents were not independently introduced into each file. They resulted from a systematic process that preserved and propagated Russian metadata by copying contaminated templates. The documents themselves record their production history.
Not proven by this analysis:
Why attribution is difficult:
What this forensic analysis establishes is document duplication methodology, not ultimate attribution.
The released files were not independent originals. Structural evidence shows that they were produced by duplicating a modified base document and replacing its content, resulting in systematic inheritance of Russian-language metadata.
Whether this duplication was part of a broader intelligence operation, a false-flag effort, or something else entirely is beyond what technical document analysis alone can determine.
What is demonstrable is the mechanism: a reproducible process of duplication outside of Microsoft Word and content replacement that propagated embedded metadata across multiple documents. That process can be independently verified using the source files linked throughout this article.
This analysis makes specific claims about Word 2007 metadata behavior (Save As resets version, edmins doesn't increment within same minute, etc.). Rather than asking readers to trust these assertions, we've created a practical verification guide. Using free copies of Word 2007 and Word 2010 (from historic MS Office installations hosed by Archive.org), you can reproduce every test and confirm the metadata behaviors described in this article.
Verifying Word 2007 Metadata Behavior →
Just use your browser:
That's it. The viewer highlights everything you need to see.
For researchers who want to examine the raw files:
If this analysis is correct, you'll discover:
If you find something different, please document it and share your findings.
Last updated: February 19, 2026
This analysis focuses on verifiable technical findings from publicly available documents. Attribution questions beyond the scope of document forensics are acknowledged but not resolved by this work.
All findings can be independently verified using the interactive document viewer linked throughout this article.