Malicious RTF — malware analysis report

Static analysis result for SHA-256 08c38be704142757…

MALICIOUS

RTF

209.5 KB Created: 2010-11-29 16:43:00 First seen: 2013-05-15
MD5: 02b77c3941478a05f2ee6559e3b76fb6 SHA-1: cd7a8327dc8917d90bdbe693a310fa75a43a1ae0 SHA-256: 08c38be704142757bcde9f24a7a9d2db126fcc81ce6de7cc7792c035e956bedf
62 Risk Score

Heuristics 2

  • CVE-2010-3333 — pFragments RTF stack overflow critical CVE exact CVE_2010_3333
    RTF shape property pFragments has an oversized value, matching the CVE-2010-3333 stack-overflow trigger in Microsoft Word 2002/2003.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://english.chinamil.com.cn/site2/news-channels/2006-01/06/content_377935.htm In RTF body
    • http://csaweb114v.csa.com/ids70/view_record.php?id=15&recnum=1&log=from_res&SID=hvqslq5lvcnf5r549q1q8003j1In RTF body
    • http://csaweb105v.csa.com/ids70/view_record.php?id=2&recnum=10&log=from_res&SID=1brpo390558hrbki27s2pu4m85In RTF body
    • http://www.amazon.com/Richard-D.-Fisher/e/B001JS0WO6/ref=sr_ntt_srch_lnk_1?qid=1283484092&sr=1-1In RTF body
    • http://www.jamestown.org/articles-by-author/?no_cache=1&tx_cablanttnewsstaffrelation_pi1%5Bauthor%5D=356In RTF body
    • http://news.xinhuanet.com/english/2006-01/04/content_4009370.htmIn RTF body
    • http://armstrade.sipri.org/armstrade/page/values.phpIn RTF body
    • http://en.rian.ru/mlitary_news/20100604/159306694.htmlIn RTF body
    • http://schemas.microsoft.com/office/word/2003/wordmlIn RTF body