Malware

What is “Exploit:O97M/CVE-2017-11882.AZL!MTB”?

Malware Removal

The Exploit:O97M/CVE-2017-11882.AZL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit:O97M/CVE-2017-11882.AZL!MTB virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • A potential decoy document was displayed to the user
  • Creates a hidden or system file

How to determine Exploit:O97M/CVE-2017-11882.AZL!MTB?


File Info:

crc32: DEF0FFC7
md5: c442eddb89f85c2c9aca3a7155413b0e
name: upload_file
sha1: 36b582b33c8633b9ca6d1c3eb3e73dc42abac1ba
sha256: 4a25856a07811127b8f1b492abc00f953572f0c6bee4e5c1056c0af93528ca68
sha512: ff9fd1931b081693a4dfca3d3c1288e310cd8ec47560c2537ac449295ba2481f868edc92f002732dadc1c7e5c5a1ccadb8d65281e4ce014d08b068988b1830f8
ssdeep: 192:HU8ePXwgvwc6aAnwBJk2Rlof+vSCQYUOZ7peVtYFCHfJCP:08ePXFvw7akMJkOlkoSCjjwVSkfJCP
type: Rich Text Format data, unknown version

Version Info:

0: [No Data]

Exploit:O97M/CVE-2017-11882.AZL!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.44168186
FireEyeTrojan.GenericKD.44168186
CAT-QuickHealExp.RTF.Obfus.Gen
McAfeeExploit-GCO!C442EDDB89F8
AegisLabHacktool.RTF.CVE-2017-11882.3!c
SangforMalware
TrendMicroTROJ_FRS.VSNW18J20
CyrenRTF/CVE-2017-11882.N.gen!Camelot
SymantecExp.CVE-2017-11882!g2
TrendMicro-HouseCallTROJ_FRS.0NA103JO20
AvastRTF:Obfuscated-gen [Trj]
KasperskyHEUR:Exploit.RTF.CVE-2017-11882.gen
BitDefenderTrojan.GenericKD.44168186
NANO-AntivirusExploit.Rtf.Heuristic-rtf.dinbqn
Ad-AwareTrojan.GenericKD.44168186
SophosTroj/RTFDl-BXP
ComodoMalware@#1emrz14jlmnh8
F-SecureMalware.W97M/Abnormal.ereiv
DrWebExploit.Siggen2.57904
InvinceaTroj/RTFDl-BXP
McAfee-GW-EditionExploit-GCO!C442EDDB89F8
EmsisoftTrojan.GenericKD.44168186 (B)
IkarusTrojan.Doc.Agent
GDataTrojan.GenericKD.44168186
AviraW97M/Abnormal.ereiv
Antiy-AVLTrojan[Exploit]/RTF.Obscure.Gen
ZoneAlarmHEUR:Exploit.RTF.CVE-2017-11882.gen
MicrosoftExploit:O97M/CVE-2017-11882.AZL!MTB
CynetMalicious (score: 85)
AhnLab-V3RTF/Malform-A.Gen
ALYacTrojan.GenericKD.44168186
TACHYONTrojan-Exploit/RTF.CVE-2017-11882
ZonerProbably Heur.RTFBadVersion
ESET-NOD32a variant of DOC/Abnormal.A
MAXmalware (ai score=100)
FortinetRTF/CVE_2017_11882.C!exploit
AVGRTF:Obfuscated-gen [Trj]
Qihoo-360susp.rtf.objupdate.gen

How to remove Exploit:O97M/CVE-2017-11882.AZL!MTB?

Exploit:O97M/CVE-2017-11882.AZL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment