Malware

probably Win32/Exploit.CVE-2017-11882.C (file analysis)

Malware Removal

The probably Win32/Exploit.CVE-2017-11882.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What probably Win32/Exploit.CVE-2017-11882.C virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • A potential decoy document was displayed to the user
  • Creates a hidden or system file

How to determine probably Win32/Exploit.CVE-2017-11882.C?


File Info:

crc32: 917B5DCF
md5: e6c64e4cd42b95cb63ca4abb0f769979
name: tmp9ybss2id
sha1: 4ad8d4540d573c39a788e2ed8ce1cb25df8c35d6
sha256: 0361fd13953a2930d32e19aab7bddfc3dc74f5e247400820f87c54fa8008c384
sha512: cd7158e50d5ae70be4bd8c8b4d2e0103e283122f0422276fdc04cd3b228f6d325aceabc053f79d43e965ab7751c92ec5911091f229c4d7bafb4e01783891b690
ssdeep: 96:0EZdg5q6uNSD4JLdLbM93gv4qgoLtrs1QPKHafU+gKtpawWd8Kv5pf0:0ELM8/ww4qgoLtrs1QPK+ppa7ycl0
type: Rich Text Format data, unknown version

Version Info:

0: [No Data]

probably Win32/Exploit.CVE-2017-11882.C also known as:

DrWebExploit.Siggen2.4888
MicroWorld-eScanTrojan.GenericKD.34027693
FireEyeTrojan.GenericKD.34027693
CAT-QuickHealExp.RTF.Obfus.Gen
McAfeeExploit-CVE2017-11882.by
SangforMalware
K7GWTrojan ( 655333331 )
CyrenCVE-2017-11882.E.gen!Camelot
SymantecExp.CVE-2017-11882!g2
ESET-NOD32probably a variant of Win32/Exploit.CVE-2017-11882.C
AvastWin32:ShellCode [Expl]
ClamAVRtf.Exploit.CVE_2017_11882-6584355-0
GDataTrojan.GenericKD.34027693
KasperskyHEUR:Exploit.MSOffice.Generic
BitDefenderTrojan.GenericKD.34027693
NANO-AntivirusExploit.Rtf.Heuristic-rtf.dinbqn
AegisLabHacktool.MSOffice.Generic.3!c
TencentOffice.Exploit.Generic.Amcc
Ad-AwareTrojan.GenericKD.34027693
TACHYONTrojan-Exploit/RTF.CVE-2017-11882
F-SecureExploit:W97M/CVE-2017-0199.B
TrendMicroHEUR_RTFMALFORM
McAfee-GW-EditionExploit-CVE2017-11882.by
EmsisoftTrojan.GenericKD.34027693 (B)
AviraEXP/CVE-2017-11882.wdoql
ArcabitTrojan.Generic.D20738AD
AhnLab-V3RTF/Malform-A.Gen
ZoneAlarmHEUR:Exploit.MSOffice.Generic
MicrosoftExploit:O97M/CVE-2017-11882.YB!MTB
CynetMalicious (score: 85)
ALYacTrojan.GenericKD.34027693
MAXmalware (ai score=100)
ZonerProbably Heur.RTFBadVersion
RisingExploit.CVE-2017-11882!1.B40D (CLASSIC)
YandexTrojan.ARicher.bSxJ5m
IkarusExploit.CVE-2017-11882
FortinetRTF/CVE_2017_11882.ACU!exploit
AVGWin32:ShellCode [Expl]
Qihoo-360virus.exp.21711882.d

How to remove probably Win32/Exploit.CVE-2017-11882.C?

probably  Win32/Exploit.CVE-2017-11882.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment