Malware

Exploit:O97M/CVE-2017-11882.PE!MTB (file analysis)

Malware Removal

The Exploit:O97M/CVE-2017-11882.PE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit:O97M/CVE-2017-11882.PE!MTB virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Exploit:O97M/CVE-2017-11882.PE!MTB?


File Info:

crc32: 12F6393C
md5: 5e524118d2f026f17345a1f67109ee14
name: upload_file
sha1: 838b5f8fe7e729b55ca58a4fe6676f8521d9c832
sha256: c80e00e44a9ad1f8209d72e1de7a5cc9fd239b2554f2ac53cdb609e7f5131a92
sha512: f199b0fc22164322b2372e981527fd7b5c28ca81d3b0e9e3de2ded5dd3b3ff2595797d07a6bdd70d7562264798eadaacc9d4e5819d9bb7fcb9c789787adf1f72
ssdeep: 768:opVt0nsz8QktIqoPJmQ8eAxhUDQyWoqw6NL2n/PXkmPvTm9hxxzL72TdWh:oPFKtIqvfeAEU5NwRXHvTwFL74C
type: Composite Document File V2 Document, No summary info

Version Info:

0: [No Data]

Exploit:O97M/CVE-2017-11882.PE!MTB also known as:

McAfeeRDN/Generic Exploit
AegisLabHacktool.MSOffice.Generic.3!c
TrendMicroTrojan.X97M.CVE201711882.AAQUOOVG
SymantecTrojan Horse
TrendMicro-HouseCallTrojan.X97M.CVE201711882.AAQUOOVG
AvastWin32:ShellCode [Expl]
CynetMalicious (score: 85)
KasperskyHEUR:Exploit.MSOffice.Generic
BitDefenderExploit.CVE-2017-11882.Gen
ViRobotDOC.Z.CVE-2017-1188.44032.B
MicroWorld-eScanExploit.CVE-2017-11882.Gen
Ad-AwareExploit.CVE-2017-11882.Gen
SophosTroj/DocExp-AB
F-SecureExploit.EXP/CVE-2017-11882.zzzok
DrWebExploit.Siggen2.47145
InvinceaTroj/DocExp-AB
McAfee-GW-EditionRDN/Generic Exploit
FireEyeExploit.CVE-2017-11882.Gen
EmsisoftExploit.CVE-2017-11882.Gen (B)
IkarusTrojan-Downloader.Office.Crypt
AviraEXP/CVE-2017-11882.zzzok
MAXmalware (ai score=80)
MicrosoftExploit:O97M/CVE-2017-11882.PE!MTB
ArcabitExploit.CVE-2017-11882.Gen
ZoneAlarmHEUR:Exploit.MSOffice.Generic
GDataExploit.CVE-2017-11882.Gen
ALYacExploit.CVE-2017-11882.Gen
TACHYONSuspicious/W97.CVE-2017-11882
ESET-NOD32probably a variant of Win32/Exploit.CVE-2017-11882.C
FortinetMSOffice/CVE_2017_11882.B!exploit
AVGWin32:ShellCode [Expl]
Qihoo-360Generic/Trojan.Exploit.ed7

How to remove Exploit:O97M/CVE-2017-11882.PE!MTB?

Exploit:O97M/CVE-2017-11882.PE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment