cbcvebase.
CVE-2015-1641
published 2015-04-14

CVE-2015-1641: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation…

PriorityP189high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
96.79%
99.9th percentile
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Office Memory Corruption Vulnerability."

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoftoffice
microsoftoffice_web_apps
microsoftoffice_web_apps
microsoftoutlook
microsoftsharepoint_server
microsoftsharepoint_server
microsoftword
microsoftword
microsoftword
microsoftword

Detection & IOCsextracted from sources · hover to see the quote

domainkr44.78host[.]com
domaingtoimage[.]com
domaingogolekr[.]com
domaineurope.wikaba[.]com
domainrussiaboy.ssl443[.]org
domaincool.skywave[.]top
domainwww.dppline[.]org
domainwww.matrens[.]top
urlfiles[.]maintrplus[.]com
hash0a3d635eb11e78e6397a32c99dc0fd5a
path%APPDATA%\Intel\avinfo
commandcmd /C %TEMP%\~tmp.doc
registryHKLM\Software\Microsoft\Windows\CurrentVersion\Run\Eupdate - %APPDATA%\Intel\ResN32.dll
registryHKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs - %APPDATA%\Intel\ResN32.dll
registryHKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs – 0x1
path%AppData%\Microsoft\Windows\Start Menu\Programs\Startup
filenamehccutils.dll
filenameResN32.dll
filenameQQMgr.dll
otherExploit.MSWord.Agent.hp
  • Post-exploitation shellcode reads the last four bytes of the RTF file as payload size, then decrypts and writes payload to a temp file executed via WinExec; detect WinExec calls from Office processes writing to %TEMP%.
  • T9000 malware drops files into %APPDATA%\Intel directory; presence of hjwe.dat, tyeu.dat, vnkd.dat, qhnj.dat, dtl.dat, glp.uin, igfxtray.exe, hccutils.dll, ResN32.dll in that path is a strong indicator of compromise.
  • T9000 uses AppInit_DLLs persistence pointing to ResN32.dll; alert on writes to HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs by non-system processes.
  • DragonOK CVE-2015-1641 RTF exploit uses a unique shellcode; IPS signatures 14365, 14588, 13574, 13359 cover IsSpace and related C2 traffic.
  • ModifiedElephant used CVE-2015-1641 exploits in .doc lure files; monitor for Office processes injecting into explorer.exe without writing to its memory (process hollowing variant).
  • T9000 debug PDB path 'D:\WORK\T9000\hccutils_M4\Release\hccutils.pdb' embedded in hccutils.dll; scan memory/files for this string as a high-confidence T9000 indicator.
  • T9000 debug PDB path 'D:\WORK\T9000\ResN_M2\Release\ResN32.pdb' embedded in ResN32.dll; scan for this string as a high-confidence T9000 indicator.
  • T9000 BypassUAC component identified by PDB string 'H:\WORK\PROJECT\InfInstallBypassUAC\Release\BypassUAC.pdb' in QQMgr.dll; scan for this string.
  • ·The gtoimage[.]com and trend.gogolekr[.]com sysget C2 domains share the same registrant and resolve to the same netblock 104.202.173.0/24; blocking the netblock may affect other hosted services.
  • ·The Securelist source partially redacts the malicious hosting domain as 'files[.]maintr**plus[.]com'; the exact domain should be confirmed before blocking to avoid false positives.
  • ·The T9000 mutex value contains 'xx' placeholders (820C90CxxA1B084495866C6D95B2595xx1C3), suggesting the exact characters were redacted; the full mutex string must be confirmed from a live sample before using as a detection rule.
  • ·igfxtray.exe used by T9000 for DLL sideloading is a legitimate Microsoft executable; blocking or alerting on it alone will produce false positives — detection should focus on the presence of hccutils.dll in the same directory.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.