Malicious RTF — malware analysis report

Static analysis result for SHA-256 68f10c2f8a484fce…

MALICIOUS

RTF

238.0 KB Created: 2009-06-29 17:48:00 First seen: 2013-07-24
MD5: 2eea004842a335607b612ff10418f6c6 SHA-1: a81a35804c056186c533ddd31e22ee0c0d2aa4df SHA-256: 68f10c2f8a484fcecdbbaa69cf01caf3d3bb725f66e7db00cd30c3d84a5c6af4
242 Risk Score

Heuristics 4

  • CVE-2010-3333 — pFragments RTF stack overflow critical CVE exact CVE_2010_3333
    RTF shape property pFragments has an oversized value, matching the CVE-2010-3333 stack-overflow trigger in Microsoft Word 2002/2003.
  • ClamAV: Win.Trojan.Agent-30172 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Agent-30172
  • PE header (with DOS stub) in hex data critical RTF_MZ_HEX
    Hex-encoded PE (MZ + DOS stub) found inside RTF — likely an embedded executable payload
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ocsp.verisign.com0 In RTF body
    • http://ocsp.verisign.com01In RTF body
    • http://schemas.microsoft.com/office/word/2003/wordmlIn RTF body
    • https://www.verisign.com/rpaIn RTF body
    • http://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0DIn RTF body
    • https://www.verisign.com/rpa0In RTF body
    • http://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0In RTF body
    • https://www.verisign.com/cps0*In RTF body
    • http://logo.verisign.com/vslogo.gif0In RTF body
    • http://crl.verisign.com/pca3.crl0In RTF body

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_rtf_00017a3e.exe embedded-pe RTF hex-encoded MZ at offset 0x17A3E 73416 bytes
SHA-256: ef3e3dfca5d0cf34bc8984d0b3604e8012c45cb033320fe023dc7a2d8370d0ef
Detection
ClamAV: Win.Trojan.Agent2-1979
Obfuscation or payload: unlikely