Malicious RTF — malware analysis report

Static analysis result for SHA-256 70bead8598bf90c0…

MALICIOUS

RTF

100.6 KB
MD5: 722e07c34bc47bf3159445e93ebec5f6 SHA-1: acdf720e5f75bf4b05db14922790fb2e227e4026 SHA-256: 70bead8598bf90c00fa492c8d212bb9af20ebfd68a0cefbeea3dc909bc366ed5
120 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The sample is an RTF document that triggers a critical heuristic for CVE-2010-3333, a known stack overflow vulnerability. This indicates the file is designed to exploit this vulnerability for code execution. No further malicious behavior or payloads were identified in the static analysis.

Heuristics 2

  • CVE-2010-3333 — pFragments RTF stack overflow critical CVE exact CVE_2010_3333
    RTF shape property pFragments has an oversized value, matching the CVE-2010-3333 stack-overflow trigger in Microsoft Word 2002/2003.
  • ClamAV: BC.Legacy.Exploit.CVE_2010_3333-5 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: BC.Legacy.Exploit.CVE_2010_3333-5