Malicious RTF — malware analysis report

Static analysis result for SHA-256 8cac7e77e92bbf85…

MALICIOUS

RTF

1.8 KB First seen: 2015-09-30
MD5: 94b1743b6a0354108f27a14f69448380 SHA-1: 41fc565eb8daf36acb9529022cd4d1ca0ede6bc1 SHA-256: 8cac7e77e92bbf85ed5cbdf51bd626058082f7aa2abedc205bcb2e20ba4979a7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The RTF document contains a stack overflow vulnerability (CVE-2010-3333) that can be triggered by a specially crafted pFragments field. This vulnerability allows for arbitrary code execution, indicating a malicious intent to compromise the user's system. No document body or scripts were extracted, but the heuristic firing is sufficient for a high confidence assessment.

Heuristics 1

  • CVE-2010-3333 — pFragments RTF stack overflow critical CVE exact CVE_2010_3333
    RTF shape property pFragments has an oversized value, matching the CVE-2010-3333 stack-overflow trigger in Microsoft Word 2002/2003.