paladin316

Docs_b885078b07e3fe49540d06c7f27ff961_doc_2019-06-26_08_30.json

Jun 26th, 2019
2,388
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.89 KB | None | 0 0
  1.  
  2. [*] MalFamily: "Msoffice"
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "Docs_b885078b07e3fe49540d06c7f27ff961.doc"
  7. [*] File Size: 8497
  8. [*] File Type: "Rich Text Format data, version 1, unknown character set"
  9. [*] SHA256: "1cc95071137a5cf79f60d1bf0c7aeb2699af479ff285a26b9dd2b090863a9724"
  10. [*] MD5: "b885078b07e3fe49540d06c7f27ff961"
  11. [*] SHA1: "35fbc05c71742e6984782386ddb30e9d97263c3c"
  12. [*] SHA512: "40938cb68f6518b27737b877518cc081bcf004213a1fa23e8d602c1f08f3850a8c8727d1eb757ee1ad6cd1c6c04f166ca9209170e00818ceeb016d104050a8bd"
  13. [*] CRC32: "1A0BAE0D"
  14. [*] SSDEEP: "96:7f0BaPwvRmWqGOfywiEO8ZOI/fIJlU7FUktqRTVUsYPfjs5y3:7fUwgRmiWiEOguUPfjs5y3"
  15.  
  16. [*] Process Execution: []
  17.  
  18. [*] Signatures Detected: [
  19. {
  20. "Description": "File has been identified by 31 Antiviruses on VirusTotal as malicious",
  21. "Details": [
  22. {
  23. "MicroWorld-eScan": "Exploit.CVE-2017-11882.Gen"
  24. },
  25. {
  26. "McAfee": "Exploit-CVE2017-11882.yx"
  27. },
  28. {
  29. "Arcabit": "Exploit.CVE-2017-11882.Gen"
  30. },
  31. {
  32. "Symantec": "Exp.CVE-2017-11882!g3"
  33. },
  34. {
  35. "ESET-NOD32": "probably a variant of Win32/Exploit.CVE-2017-11882.A"
  36. },
  37. {
  38. "Avast": "Win32:ShellCode [Expl]"
  39. },
  40. {
  41. "Kaspersky": "HEUR:Exploit.MSOffice.Generic"
  42. },
  43. {
  44. "BitDefender": "Exploit.CVE-2017-11882.Gen"
  45. },
  46. {
  47. "Rising": "Exploit.CVE-2017-11882!1.B40D (CLASSIC)"
  48. },
  49. {
  50. "Ad-Aware": "Exploit.CVE-2017-11882.Gen"
  51. },
  52. {
  53. "Emsisoft": "Exploit.CVE-2017-11882.Gen (B)"
  54. },
  55. {
  56. "F-Secure": "Exploit:W97M/CVE-2017-0199.B"
  57. },
  58. {
  59. "DrWeb": "Exploit.ShellCode.69"
  60. },
  61. {
  62. "McAfee-GW-Edition": "Exploit-CVE2017-11882.yx"
  63. },
  64. {
  65. "FireEye": "Exploit.CVE-2017-11882.Gen"
  66. },
  67. {
  68. "Sophos": "Troj/RtfExp-EQ"
  69. },
  70. {
  71. "Cyren": "CVE-2017-11882.C.gen!Camelot"
  72. },
  73. {
  74. "Avira": "EXP/CVE-2017-11882.Gen"
  75. },
  76. {
  77. "MAX": "malware (ai score=94)"
  78. },
  79. {
  80. "Microsoft": "Exploit:O97M/CVE-2017-11882.L"
  81. },
  82. {
  83. "ZoneAlarm": "HEUR:Exploit.MSOffice.Generic"
  84. },
  85. {
  86. "GData": "Exploit.CVE-2017-11882.Gen (2x)"
  87. },
  88. {
  89. "AhnLab-V3": "OLE/Cve-2017-11882.Gen"
  90. },
  91. {
  92. "ALYac": "Exploit.CVE-2017-11882.Gen"
  93. },
  94. {
  95. "TACHYON": "Trojan-Exploit/RTF.CVE-2017-11882"
  96. },
  97. {
  98. "Zoner": "Probably W97NativeOnly"
  99. },
  100. {
  101. "Tencent": "Office.Exploit.Generic.Pgmn"
  102. },
  103. {
  104. "Ikarus": "Exploit.CVE-2017-11882"
  105. },
  106. {
  107. "Fortinet": "MSOffice/CVE_2017_11882.BB!exploit"
  108. },
  109. {
  110. "AVG": "Win32:ShellCode [Expl]"
  111. },
  112. {
  113. "Qihoo-360": "virus.exp.21711882.d"
  114. }
  115. ]
  116. }
  117. ]
  118.  
  119. [*] Started Service: []
  120.  
  121. [*] Executed Commands: []
  122.  
  123. [*] Mutexes: []
  124.  
  125. [*] Modified Files: []
  126.  
  127. [*] Deleted Files: []
  128.  
  129. [*] Modified Registry Keys: []
  130.  
  131. [*] Deleted Registry Keys: []
  132.  
  133. [*] DNS Communications: []
  134.  
  135. [*] Domains: []
  136.  
  137. [*] Network Communication - ICMP: []
  138.  
  139. [*] Network Communication - HTTP: []
  140.  
  141. [*] Network Communication - SMTP: []
  142.  
  143. [*] Network Communication - Hosts: []
  144.  
  145. [*] Network Communication - IRC: []
  146.  
  147. [*] Static Analysis: {}
  148.  
  149. [*] Resolved APIs: []
  150.  
  151. [*] Static Analysis: {}
Advertisement
Add Comment
Please, Sign In to add comment