ScreenShot
Created | 2021.04.10 08:45 | Machine | s1_win7_x6401 |
Filename | ...............................................................................................................dot | ||
Type | Rich Text Format data, unknown version | ||
AI Score | Not founds | Behavior Score |
|
ZERO API | file : mailcious | ||
VT API (file) | 23 detected (ObfsObjDat, Bloodhound, a variant of DOC, Abnormal, Malicious, score, dinbqn, RTFMALFORM, CVE-2017-1188, CVE2017, Malformed, ai score=83, Wacatac, Malform, Probably Heur, RTFBadVersion, objupdate) | ||
md5 | 50d4dddb1000e7e62508148c84aa5f59 | ||
sha256 | 8e107b7cc6913c49b057fce4573694813028ed01cf47fa54b277c1ce50ac4216 | ||
ssdeep | 192:UT8gI2Jr0cJ0S8Qph8+a8V/fO50Rdz06DrYbjFojOuQVCUbkmgrIPAck:U4g/JrOSrzS0Rdz0urYWSuBUMck | ||
imphash | |||
impfuzzy |
Network IP location
Signature (9cnts)
Level | Description |
---|---|
warning | File has been identified by 23 AntiVirus engines on VirusTotal as malicious |
watch | Communicates with host for which no DNS query was performed |
notice | Allocates read-write-execute memory (usually to unpack itself) |
notice | An application raised an exception which may be indicative of an exploit crash |
notice | Creates hidden or system file |
notice | HTTP traffic contains suspicious features which may be indicative of malware related traffic |
notice | Performs some HTTP requests |
notice | RTF file has an unknown version |
info | One or more processes crashed |
Rules (1cnts)
Level | Name | Description | Collection |
---|---|---|---|
info | Rich_Text_Format_Zero | Rich Text Format Signature Zero | binaries (upload) |