Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Msoffice"
- [*] MalScore: 10.0
- [*] File Name: "Docs_b885078b07e3fe49540d06c7f27ff961.doc"
- [*] File Size: 8497
- [*] File Type: "Rich Text Format data, version 1, unknown character set"
- [*] SHA256: "1cc95071137a5cf79f60d1bf0c7aeb2699af479ff285a26b9dd2b090863a9724"
- [*] MD5: "b885078b07e3fe49540d06c7f27ff961"
- [*] SHA1: "35fbc05c71742e6984782386ddb30e9d97263c3c"
- [*] SHA512: "40938cb68f6518b27737b877518cc081bcf004213a1fa23e8d602c1f08f3850a8c8727d1eb757ee1ad6cd1c6c04f166ca9209170e00818ceeb016d104050a8bd"
- [*] CRC32: "1A0BAE0D"
- [*] SSDEEP: "96:7f0BaPwvRmWqGOfywiEO8ZOI/fIJlU7FUktqRTVUsYPfjs5y3:7fUwgRmiWiEOguUPfjs5y3"
- [*] Process Execution: []
- [*] Signatures Detected: [
- {
- "Description": "File has been identified by 31 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "MicroWorld-eScan": "Exploit.CVE-2017-11882.Gen"
- },
- {
- "McAfee": "Exploit-CVE2017-11882.yx"
- },
- {
- "Arcabit": "Exploit.CVE-2017-11882.Gen"
- },
- {
- "Symantec": "Exp.CVE-2017-11882!g3"
- },
- {
- "ESET-NOD32": "probably a variant of Win32/Exploit.CVE-2017-11882.A"
- },
- {
- "Avast": "Win32:ShellCode [Expl]"
- },
- {
- "Kaspersky": "HEUR:Exploit.MSOffice.Generic"
- },
- {
- "BitDefender": "Exploit.CVE-2017-11882.Gen"
- },
- {
- "Rising": "Exploit.CVE-2017-11882!1.B40D (CLASSIC)"
- },
- {
- "Ad-Aware": "Exploit.CVE-2017-11882.Gen"
- },
- {
- "Emsisoft": "Exploit.CVE-2017-11882.Gen (B)"
- },
- {
- "F-Secure": "Exploit:W97M/CVE-2017-0199.B"
- },
- {
- "DrWeb": "Exploit.ShellCode.69"
- },
- {
- "McAfee-GW-Edition": "Exploit-CVE2017-11882.yx"
- },
- {
- "FireEye": "Exploit.CVE-2017-11882.Gen"
- },
- {
- "Sophos": "Troj/RtfExp-EQ"
- },
- {
- "Cyren": "CVE-2017-11882.C.gen!Camelot"
- },
- {
- "Avira": "EXP/CVE-2017-11882.Gen"
- },
- {
- "MAX": "malware (ai score=94)"
- },
- {
- "Microsoft": "Exploit:O97M/CVE-2017-11882.L"
- },
- {
- "ZoneAlarm": "HEUR:Exploit.MSOffice.Generic"
- },
- {
- "GData": "Exploit.CVE-2017-11882.Gen (2x)"
- },
- {
- "AhnLab-V3": "OLE/Cve-2017-11882.Gen"
- },
- {
- "ALYac": "Exploit.CVE-2017-11882.Gen"
- },
- {
- "TACHYON": "Trojan-Exploit/RTF.CVE-2017-11882"
- },
- {
- "Zoner": "Probably W97NativeOnly"
- },
- {
- "Tencent": "Office.Exploit.Generic.Pgmn"
- },
- {
- "Ikarus": "Exploit.CVE-2017-11882"
- },
- {
- "Fortinet": "MSOffice/CVE_2017_11882.BB!exploit"
- },
- {
- "AVG": "Win32:ShellCode [Expl]"
- },
- {
- "Qihoo-360": "virus.exp.21711882.d"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: []
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {}
- [*] Resolved APIs: []
- [*] Static Analysis: {}
Advertisement
Add Comment
Please, Sign In to add comment