MALICIOUS
242
Risk Score
Heuristics 4
-
CVE-2010-3333 — pFragments RTF stack overflow critical CVE exact CVE_2010_3333RTF shape property pFragments has an oversized value, matching the CVE-2010-3333 stack-overflow trigger in Microsoft Word 2002/2003.
-
ClamAV: Win.Trojan.Agent-30172 critical CLAMAV_DETECTIONClamAV detected this file as malware: Win.Trojan.Agent-30172
-
PE header (with DOS stub) in hex data critical RTF_MZ_HEXHex-encoded PE (MZ + DOS stub) found inside RTF — likely an embedded executable payload
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://ocsp.verisign.com0 In RTF body
- http://ocsp.verisign.com01In RTF body
- http://schemas.microsoft.com/office/word/2003/wordmlIn RTF body
- https://www.verisign.com/rpaIn RTF body
- http://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0DIn RTF body
- https://www.verisign.com/rpa0In RTF body
- http://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0In RTF body
- https://www.verisign.com/cps0*In RTF body
- http://logo.verisign.com/vslogo.gif0In RTF body
- http://crl.verisign.com/pca3.crl0In RTF body
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_rtf_00017a3e.exe |
embedded-pe | RTF hex-encoded MZ at offset 0x17A3E | 73416 bytes |
SHA-256: ef3e3dfca5d0cf34bc8984d0b3604e8012c45cb033320fe023dc7a2d8370d0ef |
|||
|
Detection
ClamAV:
Win.Trojan.Agent2-1979
Obfuscation or payload:
unlikely
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.