Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Exploit.CVE-2018-0798.4.1674.19041.rtf

Overview

General Information

Sample Name:SecuriteInfo.com.Exploit.CVE-2018-0798.4.1674.19041.rtf
Analysis ID:756308
MD5:651c9a6ce618676610f649779edc714b
SHA1:cd74ad99acc4c1caf5e8379367b9df24f07746db
SHA256:de9a977c672758a706c96568e202c075590bb60a848fb3b7680c2f83df7f203e
Tags:rtf
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Malicious sample detected (through community Yara rule)
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Multi AV Scanner detection for submitted file
Yara signature match

Classification

  • System is w10x64
  • WINWORD.EXE (PID: 1916 cmdline: "C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE" /Automation -Embedding MD5: 0B9AB9B9C4DE429473D6450D4297A123)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
SecuriteInfo.com.Exploit.CVE-2018-0798.4.1674.19041.rtfSUSP_INDICATOR_RTF_MalVer_ObjectsDetects RTF documents with non-standard version and embedding one of the object mostly observed in exploit (e.g. CVE-2017-11882) documents.ditekSHen
  • 0x4723:$obj2: \objdata
  • 0x48f8:$obj3: \objupdate
  • 0x46fd:$obj5: \objautlink
SecuriteInfo.com.Exploit.CVE-2018-0798.4.1674.19041.rtfINDICATOR_RTF_MalVer_ObjectsDetects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents.ditekSHen
  • 0x4723:$obj2: \objdata
  • 0x48f8:$obj3: \objupdate
  • 0x46fd:$obj5: \objautlink
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: SecuriteInfo.com.Exploit.CVE-2018-0798.4.1674.19041.rtfReversingLabs: Detection: 26%
Source: SecuriteInfo.com.Exploit.CVE-2018-0798.4.1674.19041.rtfVirustotal: Detection: 26%Perma Link
Source: C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXEFile opened: C:\Windows\SysWOW64\MSVCR100.dllJump to behavior
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: http://b.c2r.ts.cdn.office.net/pr
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: http://f.c2r.ts.cdn.office.net/pr
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/acquisitionlogging
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/authenticated
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/unauthenticated
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://addinsinstallation.store.office.com/orgid/appinstall/authenticated
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://addinslicensing.store.office.com/apps/remove
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://addinslicensing.store.office.com/entitlement/query
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/apps/remove
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/entitlement/query
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.aadrm.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.aadrm.com/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.addins.store.office.com/addinstemplate
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.addins.store.officeppe.com/addinstemplate
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.cortana.ai
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.diagnosticssdf.office.com/v2/feedback
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.diagnosticssdf.office.com/v2/file
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.office.net
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.onedrive.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://api.scheduler.
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://augloop.office.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://augloop.office.com/v2
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://cdn.entity.
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://cdn.odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://clients.config.office.net/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://clients.config.office.net/c2r/v1.0/InteractiveInstallation
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://config.edge.skype.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://consent.config.office.com/consentcheckin/v1.0/consents
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://consent.config.office.com/consentweb/v1.0/consents
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://cortana.ai
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://cortana.ai/api
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://cr.office.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://dev.cortana.ai
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://devnull.onenote.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://directory.services.
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://enrichment.osi.office.net/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Refresh/v1
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Resolve/v1
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Search/v1
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/StockHistory/v1
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/ipcheck/v1
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/metadata.json
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/desktop/main.cshtml
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/web/main.cshtml
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://graph.windows.net
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://graph.windows.net/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?secureurl=1
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://inclient.store.office.com/gyro/client
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://inclient.store.office.com/gyro/clientstore
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://invites.office.com/
Source: 1BC0D30C-906E-41DA-A53D-99EC4AE5726E.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech