Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Docs_1450e5697578eb0d76440effd32f1587.doc"
- * File Size: 9160
- * File Type: "Rich Text Format data, unknown version"
- * SHA256: "d7a82c1ad2b0ad9804bec498dc6eeacacf7d6be5acb66f17e201c2773c885fc3"
- * MD5: "1450e5697578eb0d76440effd32f1587"
- * SHA1: "e71bbbfbb5419af8f564eb8b3d7fb0bab5c8dc5e"
- * SHA512: "7766ea5b8dff2a6a16cf9b9b6fcf65667b47e090d9e4e47c8440b6361d2eedcb27753d3e7bae249b510ed25fd49c01844752b0c54961df412f42fbf73e1c3280"
- * CRC32: "A3CC244B"
- * SSDEEP: "96:qFt0CQB3vR5I8nGwqeiM7vsQnxXj+xWuqxtv0gzdp0ORcuE:Ct09fRy8nGwqj+vpJRuqX0gzdKO6uE"
- * Process Execution:
- * Executed Commands:
- * Signatures Detected:
- "Description": "File has been identified by 32 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Exploit.CVE-2017-11882.Gen"
- "FireEye": "Exploit.CVE-2017-11882.Gen"
- "CAT-QuickHeal": "Exp.RTF.Obfus.Gen"
- "ALYac": "Exploit.CVE-2017-11882.Gen"
- "Arcabit": "Exploit.CVE-2017-11882.Gen"
- "Symantec": "Exp.CVE-2017-11882!g2"
- "ESET-NOD32": "probably a variant of Win32/Exploit.CVE-2017-11882.C"
- "Avast": "Win32:ShellCode Expl"
- "Kaspersky": "HEUR:Exploit.MSOffice.Generic"
- "BitDefender": "Exploit.CVE-2017-11882.Gen"
- "NANO-Antivirus": "Exploit.Rtf.Heuristic-rtf.dinbqn"
- "Ad-Aware": "Exploit.CVE-2017-11882.Gen"
- "Emsisoft": "Exploit.CVE-2017-11882.Gen (B)"
- "F-Secure": "Exploit:W97M/CVE-2017-0199.B"
- "DrWeb": "Exploit.Siggen.24772"
- "TrendMicro": "HEUR_RTFMALFORM"
- "McAfee-GW-Edition": "Exploit-CVE2017-11882.bu"
- "Sophos": "Troj/RtfExp-EQ"
- "Cyren": "CVE-2017-11882.C.gen!Camelot"
- "Avira": "EXP/CVE-2017-11882.phzie"
- "MAX": "malware (ai score=81)"
- "Antiy-AVL": "TrojanExploit/OLE.CVE-2017-11882"
- "Microsoft": "Trojan:O97M/Obfuse.AE"
- "ZoneAlarm": "HEUR:Exploit.RTF.Generic"
- "GData": "Exploit.CVE-2017-11882.Gen (2x)"
- "AhnLab-V3": "OLE/Cve-2017-11882.Gen"
- "McAfee": "Exploit-CVE2017-11882.bu"
- "TACHYON": "Trojan-Exploit/RTF.CVE-2017-11882"
- "Zoner": "Probably RTFObfuscationD"
- "Ikarus": "Exploit.CVE-2017-11882"
- "AVG": "Win32:ShellCode Expl"
- "Qihoo-360": "virus.exp.21711882.d"
- * Started Service:
- * Mutexes:
- * Modified Files:
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment