Microsoft Office Russian Dolls, (Fri, Nov 14th)
ID: d2284213-2642-591f-ae37-3ab01f12601f
STIX ID: report--d2284213-2642-591f-ae37-3ab01f12601f
Feed Name: SANS ISC Diary
Threat Score
The author describes a malicious Word (OOXML) document that contains an embedded RTF which exploits CVE-2017-11882 (Equation Editor) to execute shellcode and drop an obfuscated DLL (noted hash and Temp path). The analysis includes zip listing, relationship entries referencing the RTF, the rundll32 invocation used to execute the DLL, and sample indicators for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
