Malicious RTF — malware analysis report

Static analysis result for SHA-256 5f5fb3cbfc0226f8…

MALICIOUS

RTF

307 B First seen: 2014-04-20
MD5: 419dc4a13b6d7080cbe512aecb0b4cba SHA-1: 57a84424aa0a695ac06e17d7026b05e2cf36caf8 SHA-256: 5f5fb3cbfc0226f82c7a49f236bce9ccd1b6a7476424ad2096c8745660b0d74c
62 Risk Score

Heuristics 2

  • ClamAV: BC.Legacy.Exploit.CVE_2010_3333-5 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: BC.Legacy.Exploit.CVE_2010_3333-5
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://the.earth.li/~sgtatham/putty/latest/x86/putty.exe In RTF body