Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * ID: 2914
- * MalFamily: "Obfsobjdat"
- * MalScore: 10.0
- * File Name: "Docs_6e4b83d2d2247fbf6e72febd6b280e3f.doc"
- * File Size: 6594231
- * File Type: "Rich Text Format data, unknown version"
- * SHA256: "2e84cdeeca4afb7a92e4f87c586b1c393fd2694f735b6f4c18406badff4d41b0"
- * MD5: "6e4b83d2d2247fbf6e72febd6b280e3f"
- * SHA1: "789105db4272cb0be314672768f1226f5cf88d13"
- * SHA512: "a5817b276fe9e62f46297d1cf90b68bfa3c7c5d1d888c8e78ba48cc5d3fa8bfb1960a04885802179c2bdee717385dd6d447ebed5c75adcebb03e652cda4765c8"
- * CRC32: "4A6E251E"
- * SSDEEP: "24576:XFv/vdOG7mvgTO0osq/IcAiNRsrjwALslhWRhnSSw1tCT3togDjYilsDxwGrU2Bv:e"
- * Process Execution:
- "WINWORD.EXE",
- "svchost.exe",
- "EQNEDT32.EXE",
- "WmiPrvSE.exe",
- "svchost.exe"
- * Executed Commands:
- "\"C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\EQUATION\\EQNEDT32.EXE\" -Embedding",
- "C:\\Users\\user\\AppData\\Roaming\\educry.exe"
- * Signatures Detected:
- "Description": "SetUnhandledExceptionFilter detected (possible anti-debug)",
- "Details":
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "EQNEDT32.EXE, PID 2928"
- "Description": "Guard pages use detected - possible anti-debugging.",
- "Details":
- "Description": "The RTF file has an unknown version",
- "Details":
- "Description": "The EQNEDT32 equation process created a child process likely indicative of CVE-2017-11882 Office exploit",
- "Details":
- "created_process": "C:\\Users\\user\\AppData\\Roaming\\educry.exe"
- "Description": "Stack pivoting was detected when using a critical API",
- "Details":
- "process": "svchost.exe:1548"
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\~$rNf5x6.doc"
- "Description": "File has been identified by 22 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Exploit.RTF-ObfsObjDat.Gen"
- "FireEye": "Exploit.RTF-ObfsObjDat.Gen"
- "CAT-QuickHeal": "Exp.RTF.Obfus.Gen"
- "McAfee": "Exploit-cve2017-11882.cl"
- "Arcabit": "Exploit.RTF-ObfsObjDat.Gen"
- "ESET-NOD32": "probably a variant of Win32/Exploit.CVE-2017-11882.E"
- "Kaspersky": "HEUR:Exploit.MSOffice.Generic"
- "BitDefender": "Exploit.RTF-ObfsObjDat.Gen"
- "Ad-Aware": "Exploit.RTF-ObfsObjDat.Gen"
- "Emsisoft": "Exploit.RTF-ObfsObjDat.Gen (B)"
- "TrendMicro": "HEUR_RTFMALFORM"
- "McAfee-GW-Edition": "Exploit-cve2017-11882.cl"
- "MAX": "malware (ai score=89)"
- "Antiy-AVL": "TrojanExploit/RTF.Obscure.Gen"
- "Microsoft": "Trojan:Script/Oneeva.A!ml"
- "ZoneAlarm": "HEUR:Exploit.MSOffice.Generic"
- "GData": "Exploit.RTF-ObfsObjDat.Gen"
- "ALYac": "Exploit.RTF-ObfsObjDat.Gen"
- "TACHYON": "Trojan-Exploit/RTF.CVE-2017-11882"
- "Zoner": "Probably RTFObfuscationD"
- "Ikarus": "Exploit.CVE-2017-11882"
- "Qihoo-360": "susp.rtf.objupdate.c"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\A3rNf5x6.doc",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~$rNf5x6.doc",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.Word\\~WRF8F915FFC-E4A3-49A8-B2B2-850CB215E034.tmp",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\PIPE\\samr",
- "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
- "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Word\\Resiliency\\StartupItems\\o/q",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Word\\Security\\Trusted Documents\\LastPurgeTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Roaming\\RoamingConfigurableSettings",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Roaming\\RoamingLastSyncTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Roaming\\RoamingLastWriteTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00005109E60090400000000000F01FEC\\Usage\\ProductNonBootFilesIntl_1033",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00005119110000000000000000F01FEC\\Usage\\OUTLOOKFiles",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00005109E60090400000000000F01FEC\\Usage\\EquationEditorFilesIntl_1033",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Equation Editor\\3.0\\Options",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider"
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "ysuiteschd.com",
- "answers":
- * Domains:
- "ip": "108.179.246.152",
- "domain": "ysuiteschd.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment