paladin316

Docs_ba536fab294fabc5505d3a7478544e38_Doc_2019-06-27_10_30.json

Jun 27th, 2019
2,663
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.80 KB | None | 0 0
  1.  
  2. [*] MalFamily: ""
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "Docs_ba536fab294fabc5505d3a7478544e38.Doc"
  7. [*] File Size: 10814
  8. [*] File Type: "Rich Text Format data, version 1, ANSI"
  9. [*] SHA256: "1ace05beed9df5465f9992b627865601ae45bf27ce4e7d5de8c9ce82bafb93d0"
  10. [*] MD5: "ba536fab294fabc5505d3a7478544e38"
  11. [*] SHA1: "adcdf06cf60dac83c8cd5ff8ea25123e4c5a0e54"
  12. [*] SHA512: "97e2228c168fc9b82d3dd54a50be5eb01ad54446f9f68708f38123c038ee5b98dcffb6f18d26fad66936fbc79dc70e419d61dc9f44772d70dbf452491da557d2"
  13. [*] CRC32: "C22DC638"
  14. [*] SSDEEP: "96:M0mrac3+sUG5VoWx20dD5kyRFVSX7neeEskMtfNg9IcWDR6y4hNbH1N2mgbF:wrd+sUGZxRpDVS6aL+9tSwZXVN2mgbF"
  15.  
  16. [*] Process Execution: []
  17.  
  18. [*] Signatures Detected: [
  19. {
  20. "Description": "File has been identified by 41 Antiviruses on VirusTotal as malicious",
  21. "Details": [
  22. {
  23. "MicroWorld-eScan": "Exploit.CVE-2017-11882.Gen"
  24. },
  25. {
  26. "CAT-QuickHeal": "Exp.RTF.CVE-2017-11882.G"
  27. },
  28. {
  29. "McAfee": "Exploit-CVE2017-11882.k"
  30. },
  31. {
  32. "K7AntiVirus": "Trojan ( 0051f3601 )"
  33. },
  34. {
  35. "K7GW": "Trojan ( 0051f3601 )"
  36. },
  37. {
  38. "Arcabit": "Exploit.CVE-2017-11882.Gen"
  39. },
  40. {
  41. "Baidu": "Win32.Exploit.CVE-2017-11882.b"
  42. },
  43. {
  44. "NANO-Antivirus": "Exploit.OleNative.CVE-2017-11882.evenbv"
  45. },
  46. {
  47. "Symantec": "Bloodhound.RTF.12"
  48. },
  49. {
  50. "ESET-NOD32": "probably a variant of Win32/Exploit.CVE-2017-11882.A"
  51. },
  52. {
  53. "TrendMicro-HouseCall": "Trojan.W97M.CVE201711882.SMAL02"
  54. },
  55. {
  56. "ClamAV": "Rtf.Exploit.CVE_2017_11882-6584355-0"
  57. },
  58. {
  59. "Kaspersky": "HEUR:Exploit.MSOffice.Generic"
  60. },
  61. {
  62. "BitDefender": "Exploit.CVE-2017-11882.Gen"
  63. },
  64. {
  65. "Tencent": "Exp.MSOffice.CVE-2017-11882.b"
  66. },
  67. {
  68. "Ad-Aware": "Exploit.CVE-2017-11882.Gen"
  69. },
  70. {
  71. "Emsisoft": "Exploit.CVE-2017-11882.Gen (B)"
  72. },
  73. {
  74. "Comodo": "Exploit.Script.Agent.CVE@7pju03"
  75. },
  76. {
  77. "F-Secure": "Exploit:W97M/CVE-2017-0199.B"
  78. },
  79. {
  80. "DrWeb": "Exploit.Rtf.293"
  81. },
  82. {
  83. "TrendMicro": "Trojan.W97M.CVE201711882.SMAL02"
  84. },
  85. {
  86. "McAfee-GW-Edition": "Exploit-CVE2017-11882.k"
  87. },
  88. {
  89. "FireEye": "Exploit.CVE-2017-11882.Gen"
  90. },
  91. {
  92. "Sophos": "Exp/201711882-B"
  93. },
  94. {
  95. "Cyren": "CVE-2017-11882.A.gen!Camelot"
  96. },
  97. {
  98. "Jiangmin": "Heur:Exploit.CVE-2017-11882.Gen"
  99. },
  100. {
  101. "Avira": "EXP/CVE-2017-11882.Gen"
  102. },
  103. {
  104. "MAX": "malware (ai score=81)"
  105. },
  106. {
  107. "Antiy-AVL": "Trojan[Exploit]/OLE.CVE-2017-11882"
  108. },
  109. {
  110. "Microsoft": "Exploit:O97M/CVE-2017-11882.E"
  111. },
  112. {
  113. "ZoneAlarm": "HEUR:Exploit.Win32.CVE-2017-11882.a"
  114. },
  115. {
  116. "GData": "Generic.Exploit.CVE-2017-11882.A"
  117. },
  118. {
  119. "AhnLab-V3": "RTF/Malform-C.Gen"
  120. },
  121. {
  122. "ALYac": "Exploit.CVE-2017-11882.Gen"
  123. },
  124. {
  125. "TACHYON": "Trojan-Exploit/RTF.CVE-2017-11882"
  126. },
  127. {
  128. "Zoner": "Probably RTFObfuscationD"
  129. },
  130. {
  131. "Rising": "Exploit.CVE-2017-11882/SLT!1.AEE3 (CLASSIC)"
  132. },
  133. {
  134. "Ikarus": "Exploit.CVE-2017-11882"
  135. },
  136. {
  137. "MaxSecure": "Trojan.Trojan.RTF.Agent.ap"
  138. },
  139. {
  140. "Fortinet": "MSOffice/CVE_2017_11882.A!exploit"
  141. },
  142. {
  143. "Qihoo-360": "virus.exp.21711882.gen"
  144. }
  145. ]
  146. }
  147. ]
  148.  
  149. [*] Started Service: []
  150.  
  151. [*] Executed Commands: []
  152.  
  153. [*] Mutexes: []
  154.  
  155. [*] Modified Files: []
  156.  
  157. [*] Deleted Files: []
  158.  
  159. [*] Modified Registry Keys: []
  160.  
  161. [*] Deleted Registry Keys: []
  162.  
  163. [*] DNS Communications: []
  164.  
  165. [*] Domains: []
  166.  
  167. [*] Network Communication - ICMP: []
  168.  
  169. [*] Network Communication - HTTP: []
  170.  
  171. [*] Network Communication - SMTP: []
  172.  
  173. [*] Network Communication - Hosts: []
  174.  
  175. [*] Network Communication - IRC: []
  176.  
  177. [*] Static Analysis: {}
  178.  
  179. [*] Resolved APIs: []
  180.  
  181. [*] Static Analysis: {}
Advertisement
Add Comment
Please, Sign In to add comment