Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: ""
- [*] MalScore: 10.0
- [*] File Name: "Docs_ba536fab294fabc5505d3a7478544e38.Doc"
- [*] File Size: 10814
- [*] File Type: "Rich Text Format data, version 1, ANSI"
- [*] SHA256: "1ace05beed9df5465f9992b627865601ae45bf27ce4e7d5de8c9ce82bafb93d0"
- [*] MD5: "ba536fab294fabc5505d3a7478544e38"
- [*] SHA1: "adcdf06cf60dac83c8cd5ff8ea25123e4c5a0e54"
- [*] SHA512: "97e2228c168fc9b82d3dd54a50be5eb01ad54446f9f68708f38123c038ee5b98dcffb6f18d26fad66936fbc79dc70e419d61dc9f44772d70dbf452491da557d2"
- [*] CRC32: "C22DC638"
- [*] SSDEEP: "96:M0mrac3+sUG5VoWx20dD5kyRFVSX7neeEskMtfNg9IcWDR6y4hNbH1N2mgbF:wrd+sUGZxRpDVS6aL+9tSwZXVN2mgbF"
- [*] Process Execution: []
- [*] Signatures Detected: [
- {
- "Description": "File has been identified by 41 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "MicroWorld-eScan": "Exploit.CVE-2017-11882.Gen"
- },
- {
- "CAT-QuickHeal": "Exp.RTF.CVE-2017-11882.G"
- },
- {
- "McAfee": "Exploit-CVE2017-11882.k"
- },
- {
- "K7AntiVirus": "Trojan ( 0051f3601 )"
- },
- {
- "K7GW": "Trojan ( 0051f3601 )"
- },
- {
- "Arcabit": "Exploit.CVE-2017-11882.Gen"
- },
- {
- "Baidu": "Win32.Exploit.CVE-2017-11882.b"
- },
- {
- "NANO-Antivirus": "Exploit.OleNative.CVE-2017-11882.evenbv"
- },
- {
- "Symantec": "Bloodhound.RTF.12"
- },
- {
- "ESET-NOD32": "probably a variant of Win32/Exploit.CVE-2017-11882.A"
- },
- {
- "TrendMicro-HouseCall": "Trojan.W97M.CVE201711882.SMAL02"
- },
- {
- "ClamAV": "Rtf.Exploit.CVE_2017_11882-6584355-0"
- },
- {
- "Kaspersky": "HEUR:Exploit.MSOffice.Generic"
- },
- {
- "BitDefender": "Exploit.CVE-2017-11882.Gen"
- },
- {
- "Tencent": "Exp.MSOffice.CVE-2017-11882.b"
- },
- {
- "Ad-Aware": "Exploit.CVE-2017-11882.Gen"
- },
- {
- "Emsisoft": "Exploit.CVE-2017-11882.Gen (B)"
- },
- {
- "Comodo": "Exploit.Script.Agent.CVE@7pju03"
- },
- {
- "F-Secure": "Exploit:W97M/CVE-2017-0199.B"
- },
- {
- "DrWeb": "Exploit.Rtf.293"
- },
- {
- "TrendMicro": "Trojan.W97M.CVE201711882.SMAL02"
- },
- {
- "McAfee-GW-Edition": "Exploit-CVE2017-11882.k"
- },
- {
- "FireEye": "Exploit.CVE-2017-11882.Gen"
- },
- {
- "Sophos": "Exp/201711882-B"
- },
- {
- "Cyren": "CVE-2017-11882.A.gen!Camelot"
- },
- {
- "Jiangmin": "Heur:Exploit.CVE-2017-11882.Gen"
- },
- {
- "Avira": "EXP/CVE-2017-11882.Gen"
- },
- {
- "MAX": "malware (ai score=81)"
- },
- {
- "Antiy-AVL": "Trojan[Exploit]/OLE.CVE-2017-11882"
- },
- {
- "Microsoft": "Exploit:O97M/CVE-2017-11882.E"
- },
- {
- "ZoneAlarm": "HEUR:Exploit.Win32.CVE-2017-11882.a"
- },
- {
- "GData": "Generic.Exploit.CVE-2017-11882.A"
- },
- {
- "AhnLab-V3": "RTF/Malform-C.Gen"
- },
- {
- "ALYac": "Exploit.CVE-2017-11882.Gen"
- },
- {
- "TACHYON": "Trojan-Exploit/RTF.CVE-2017-11882"
- },
- {
- "Zoner": "Probably RTFObfuscationD"
- },
- {
- "Rising": "Exploit.CVE-2017-11882/SLT!1.AEE3 (CLASSIC)"
- },
- {
- "Ikarus": "Exploit.CVE-2017-11882"
- },
- {
- "MaxSecure": "Trojan.Trojan.RTF.Agent.ap"
- },
- {
- "Fortinet": "MSOffice/CVE_2017_11882.A!exploit"
- },
- {
- "Qihoo-360": "virus.exp.21711882.gen"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: []
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {}
- [*] Resolved APIs: []
- [*] Static Analysis: {}
Advertisement
Add Comment
Please, Sign In to add comment