Malicious RTF — malware analysis report

Static analysis result for SHA-256 3c7fdd3d6dc3cd36…

MALICIOUS

RTF

100.7 KB First seen: 2021-02-20
MD5: d80d0e5a04f2206395d31dc11f5a06dc SHA-1: dfab42a4577066bb7dd7c15bcfefb414d8be3700 SHA-256: 3c7fdd3d6dc3cd362cbbcde30e241c031be44a2880722e3ea1e893c6e7bb723b
120 Risk Score

Heuristics 2

  • CVE-2010-3333 — pFragments RTF stack overflow critical CVE exact CVE_2010_3333
    RTF shape property pFragments has an oversized value, matching the CVE-2010-3333 stack-overflow trigger in Microsoft Word 2002/2003.
  • ClamAV: Rtf.Dropper.Agent-6942194-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Dropper.Agent-6942194-0