Report - document26.doc

MS_RTF_Obfuscation_Objects RTF File doc
ScreenShot
Created 2023.01.26 11:08 Machine s1_win7_x6403
Filename document26.doc
Type data
AI Score Not founds Behavior Score
4.8
ZERO API file : mailcious
VT API (file) 29 detected (ObfsStrm, CVE-2017-1188, Camelot, Bloodhound, multiple detections, Malicious, score, dinbqn, RTFMALFORM, RtfExp, Malformed, ai score=89, Wacatac, Detected, Malform, RTFObfustream, Probably Heur, RTFBadHeader)
md5 75dd58e072281f26204dc977d0cb83b3
sha256 a1bac6264ceea9789be383bc1a180d989f17d017560dde668fc67011711d3243
ssdeep 384:WPzFG+x96ejlud5zasYqkkIUWg8jF0XMvvStdgncRUVfjYA1pMi:qQ+xsejlud5HYrkIUWg8jF0XMvv7jBgi
imphash
impfuzzy
  Network IP location

Signature (11cnts)

Level Description
warning File has been identified by 29 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
notice An application raised an exception which may be indicative of an exploit crash
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Looks up the external IP address
notice One or more potentially interesting buffers were extracted
notice Performs some HTTP requests
info One or more processes crashed

Rules (2cnts)

Level Name Description Collection
warning MS_RTF_Suspicious_documents Suspicious documents using RTF document OLE object binaries (upload)
info Rich_Text_Format_Zero Rich Text Format Signature Zero binaries (upload)

Network (10cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://104.223.76.152/126/vbc.exe US ASN-QUADRANET-GLOBAL 104.223.76.152 malware
http://ipinfo.io/ip US GOOGLE 34.117.59.81 clean
https://raw.githubusercontent.com/GodOfWareFare/TheGoodKidPhotos/main/rt.jpg US FASTLY 185.199.108.133 21821 malware
ipinfo.io US GOOGLE 34.117.59.81 clean
raw.githubusercontent.com US FASTLY 185.199.108.133 malware
185.199.108.133 US FASTLY 185.199.108.133 mailcious
194.5.212.164 Unknown 194.5.212.164 mailcious
104.223.76.152 US ASN-QUADRANET-GLOBAL 104.223.76.152 malware
46.183.223.109 LV DataClub S.A. 46.183.223.109 mailcious
34.117.59.81 US GOOGLE 34.117.59.81 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure