
These are stagers used by adversaries embedded in (docx/rtf/xml) to exploit cve-2017-118822 w/overflowing buffer for font at EQEDIT, stuff that they don't change easily, so use this info to recognize this #malware threat & campaign in the future. I attached here my static analysis for stager 1 and stager2 #shellcode they use. #MalwareMustDie! thanks @trufae for r2shell I use for this case! <3
Post summary
Adversaries are embedding stagers in Office documents to exploit CVE‑2017‑118822 by overflowing a buffer in EQEDIT; the author provides static analysis of the shellcode and references an exploitation tool, indicating documented active exploitation.
