top title background image
flash

SecuriteInfo.com.Exploit.CVE-2018-0798.4.11301.24836.rtf

Status: finished
Submission Time: 2022-11-29 16:49:18 +01:00
Malicious
Trojan
Spyware
Exploiter
Evader
Snake Keylogger

Comments

Tags

  • rtf

Details

  • Analysis ID:
    756118
  • API (Web) ID:
    1123394
  • Analysis Started:
    2022-11-29 16:49:20 +01:00
  • Analysis Finished:
    2022-11-29 16:59:29 +01:00
  • MD5:
    f2de9aa2a7a3c9890d2f799adc95c35b
  • SHA1:
    404dabf3e31da0bbf666df6397f803983961794f
  • SHA256:
    d04bf8b1677e02ada795c9a0e84abfca0ba2c1565736e9f34115783af32be764
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

Third Party Analysis Engines

malicious
Score: 16/40
malicious

IPs

IP Country Detection
208.67.105.179
United States
193.122.6.168
United States

Domains

Name IP Detection
checkip.dyndns.org
0.0.0.0
checkip.dyndns.com
193.122.6.168

URLs

Name Detection
http://208.67.105.179/arinzezx.exe
http://208.67.105.179/arinzezx.exemmC:
http://208.67.105.179/arinzezx.exej
Click to see the 8 hidden entries
http://checkip.dyndns.org
http://checkip.dyndns.orgP
http://checkip.dyndns.org/
http://checkip.dyndns.com
https://api.telegram.org/bot
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
http://208.67.105.179/arinzezx.exeC:
http://checkip.dyndns.org/q

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\arinzezx[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Roaming\rinzearec84736.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\SecuriteInfo.com.Exploit.CVE-2018-0798.4.11301.24836.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Mar 8 15:45:56 2022, mtime=Tue Mar 8 15:45:56 2022, atime=Tue Nov 29 23:50:14 2022, length=14484, window=hide
#
Click to see the 3 hidden entries
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
Generic INItialization configuration [misc]
#
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
#
C:\Users\user\Desktop\~$curiteInfo.com.Exploit.CVE-2018-0798.4.11301.24836.rtf
data
#