Malicious RTF — malware analysis report

Static analysis result for SHA-256 299d4a840fac4c14…

MALICIOUS

RTF

1.18 MB First seen: 2015-09-18
MD5: 5b697f11a169dee45f3b1713610732a7 SHA-1: 1d46dd75104229e670841ced2a7cf02c12a2c786 SHA-256: 299d4a840fac4c14f72adbf01be9d9e4dd2245b0645ea89e014bec0ab30a0ccb
120 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The sample is an RTF document that triggers a critical heuristic for CVE-2010-3333, a known stack overflow vulnerability. This indicates the file is designed to exploit this vulnerability for client-side code execution. No other malicious behaviors were observed.

Heuristics 2

  • CVE-2010-3333 — pFragments RTF stack overflow critical CVE exact CVE_2010_3333
    RTF shape property pFragments has an oversized value, matching the CVE-2010-3333 stack-overflow trigger in Microsoft Word 2002/2003.
  • ClamAV: BC.Legacy.Exploit.CVE_2010_3333-5 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: BC.Legacy.Exploit.CVE_2010_3333-5