Malicious RTF — malware analysis report

Static analysis result for SHA-256 fc167751d878b29f…

MALICIOUS

RTF

3.0 KB First seen: 2015-09-19
MD5: 2626ee5ce285c60232b9d59f3b6253e0 SHA-1: 0f2ffefcb3df539f75951f0463a1da2dee7bde98 SHA-256: fc167751d878b29f0bc6d0d396ab22970e86971182a87ba2625d53e8fb160cc8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The sample is an RTF file that triggers a critical ClamAV heuristic indicating exploitation of the CVE-2010-3333 vulnerability. This vulnerability allows for arbitrary code execution on the victim's machine. No further IOCs or script content were extracted to provide more specific details on the payload or family.

Heuristics 1

  • ClamAV: Win.Exploit.CVE_2010_3333-6 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Exploit.CVE_2010_3333-6