A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #30855  by explo1t
 Sat Sep 23, 2017 4:12 am
An interesting writeup on an RTF variant of Document exploiting CVE-2017-8759. It shows different steps of analysis from basic analysis of the Exploit File to payload.

http://www.pwncode.club/2017/09/rtf-bas ... -8759.html

The final stage of the payload is fetched from: www.thyssenkrupp-marinesystems.org. Is it a legitimate and compromised site?