Report - inv_0098788000.wbk

RTF File doc
ScreenShot
Created 2021.10.21 08:32 Machine s1_win7_x6403
Filename inv_0098788000.wbk
Type Rich Text Format data, unknown version
AI Score Not founds Behavior Score
4.6
ZERO API file : clean
VT API (file) 30 detected (Obfuscated, ObfsStrm, Save, CVE-2017-1188, Camelot, Bloodhound, multiple detections, dinbqn, Hwdb, RtfExp, RTFMALFORM, CVE2017, Malformed, ASDOH, Malicious, score, Malform, RTFObfustream, Probably Heur, RTFBadVersion, ai score=86, GenericKD)
md5 9aaf287388698afd5ef8bfeb1fb8ee24
sha256 c01942eeca190f7672db0e7e3322a21b52c66f669b41f1dd0ef852c8dd003cb3
ssdeep 384:8re1DnPyqPy89WFWsPvdiL7QQgYbQ/LEGwlEVX/VnjW3pCX9Lito/WEsWo:8reYqNadiwV/KEVZs8X9LaoeENo
imphash
impfuzzy
  Network IP location

Signature (10cnts)

Level Description
danger File has been identified by 30 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
notice An application raised an exception which may be indicative of an exploit crash
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates hidden or system file
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice One or more potentially interesting buffers were extracted
notice Performs some HTTP requests
notice RTF file has an unknown version
info One or more processes crashed

Rules (1cnts)

Level Name Description Collection
info Rich_Text_Format_Zero Rich Text Format Signature Zero binaries (upload)

Network (41cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://www.digisor.com/mxnu/?uZfX=UVMBiiaCgBTVCfU1vNNEq08V9m7XAvZZglUNdI143I2X7Zl4GMtYquItbp7SrE/Ljcqvb/Ed&Vnw0_=-Z1l72l0kFHhurC DE AMAZON-02 52.58.78.16 clean
http://www.revgeek.com/mxnu/?uZfX=LFHT7yJDHTG5j2x991585jkXyYBkZkjzIUaPFc8bTKfmXG7pnxx1T4PiHIQyjDj8X+wed1XV&Vnw0_=-Z1l72l0kFHhurC HK ICIDC NETWORK 156.234.138.23 6656 mailcious
http://www.265411.com/mxnu/?uZfX=25s1ERxOA1FsQEL58dsMzLXIm6T2LEHWrovGfnVbwWX5qUTqFcrkTCI5ju9rUaWf+2K12S96&Vnw0_=-Z1l72l0kFHhurC US DXTL Tseung Kwan O Service 192.249.80.207 6734 mailcious
http://www.funkidsroomdecor.com/mxnu/?uZfX=iFpbfMx0kR1NhQJhtaFPfzg8Nsy3dm+jXQd2Fi3YicbHa3sz/htfiB2IN3yla1aALZWfkU50&Vnw0_=-Z1l72l0kFHhurC US UNIFIEDLAYER-AS-1 192.254.189.87 6395 mailcious
http://www.desongli.com/mxnu/?uZfX=hZ80obWBB1Dtx9mJDJ/B6KhSbXm9N4IXZ9kDZpitpQpTEQWdqR+8a/o3g7qjE+O8VqYt5r7Y&Vnw0_=-Z1l72l0kFHhurC US PEGTECHINC 108.186.180.79 6643 mailcious
http://www.gatescres.com/mxnu/?uZfX=/h7P8W3KCMqF8sHgbHgxGw3KDEtccpvlr5o0RXreZvWALZ7/fG1Fr8cUEgi4cFDVX1k6R9aW&Vnw0_=-Z1l72l0kFHhurC Unknown 3.33.152.147 6387 mailcious
http://www.whitebot.xyz/mxnu/?uZfX=mJKlLoR4AxZK/RYIFKAo0UiVtoPyzBJ6SQAFXLfvSOBYEGo1cqGoAX7CRK1QxANrckFntybM&Vnw0_=-Z1l72l0kFHhurC DE Linode, LLC 172.104.153.244 6647 mailcious
http://www.epilasyonmerkeziankara.com/mxnu/?uZfX=bngcEK+xZs1ednOYrpus6XFKnrxKN2uCCnQcEZtwxddq7ZQQDv/23m99KJW03q/XcaqcaNGj&Vnw0_=-Z1l72l0kFHhurC DE Hetzner Online GmbH 5.9.250.2 6388 mailcious
http://www.closetu.com/mxnu/?uZfX=rJ249TMVQMCwGwXS7eMNhvOWH4SbGXiKs4Vq1JHmstm/5V4DyV8c/XoA/4BgaERVtEbRuzyC&Vnw0_=-Z1l72l0kFHhurC US AMAZON-AES 3.223.115.185 6644 mailcious
http://www.hanjyu.com/mxnu/?uZfX=e1Tv98kFs0Gi2+72/XvHySgQIb+R11LQEZu1blwPIgW3VgOqIrXEf8kBKhEPSuWOnZ0Oxl1j&Vnw0_=-Z1l72l0kFHhurC US EGIHOSTING 107.186.149.170 clean
http://192.227.228.38/0080008/vbc.exe US AS-COLOCROSSING 192.227.228.38 clean
http://www.naplesconciergerealty.com/mxnu/?uZfX=hecv2sMFcvsyFIpzJOhZbtwMh1SG6St5/U1aPglBFWownzq2qPNpvMi/ho6Sg43JWpVw027R&Vnw0_=-Z1l72l0kFHhurC US GOOGLE 34.102.136.180 6394 mailcious
http://www.029atk.xyz/mxnu/?uZfX=6sRgvWVFBb3Q/xwRSmzppKeefWZYMhtu8mXrbS5z1U4Jv8b+WQjv+VljYqCaCxejjINp6HL4&Vnw0_=-Z1l72l0kFHhurC US CNSERVERS 172.247.0.172 6486 mailcious
www.gatescres.com Unknown 3.33.152.147 clean
www.promovart.com Unknown mailcious
www.closetu.com US AMAZON-AES 3.223.115.185 clean
www.naplesconciergerealty.com US GOOGLE 34.102.136.180 clean
www.uggs-line.com Unknown clean
www.desongli.com US PEGTECHINC 108.186.180.79 clean
www.epilasyonmerkeziankara.com DE Hetzner Online GmbH 5.9.250.2 clean
www.265411.com US DXTL Tseung Kwan O Service 192.249.80.207 clean
www.hanjyu.com US EGIHOSTING 107.186.149.170 clean
www.blue-ivy-boutique-au.com Unknown mailcious
www.whitebot.xyz DE Linode, LLC 172.104.153.244 clean
www.029atk.xyz US CNSERVERS 172.247.0.172 clean
www.funkidsroomdecor.com US UNIFIEDLAYER-AS-1 192.254.189.87 clean
www.digisor.com DE AMAZON-02 52.58.78.16 clean
www.revgeek.com HK ICIDC NETWORK 156.234.138.23 clean
108.186.180.79 US PEGTECHINC 108.186.180.79 mailcious
52.58.78.16 DE AMAZON-02 52.58.78.16 mailcious
5.9.250.2 DE Hetzner Online GmbH 5.9.250.2 mailcious
156.234.138.23 HK ICIDC NETWORK 156.234.138.23 mailcious
172.104.153.244 DE Linode, LLC 172.104.153.244 mailcious
15.197.142.173 Unknown 15.197.142.173 clean
192.227.228.38 US AS-COLOCROSSING 192.227.228.38 clean
34.102.136.180 US GOOGLE 34.102.136.180 mailcious
192.249.80.207 US DXTL Tseung Kwan O Service 192.249.80.207 mailcious
192.254.189.87 US UNIFIEDLAYER-AS-1 192.254.189.87 mailcious
107.186.149.170 US EGIHOSTING 107.186.149.170 clean
3.223.115.185 US AMAZON-AES 3.223.115.185 mailcious
104.233.181.170 US PEGTECHINC 104.233.181.170 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure