RTF drops file to XLSTART | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Trojan, Spyware

83b0d7926fb2c5bc0708d9201043107e8709d77f2cd2fb5cb7693b2d930378d2 (SHA256)

Invitation CBS 2018 .doc.rtf

RTF Document

Created at 2018-08-05 19:04:00

Top Threat Indicators (View all 12 threat indicators)

Screenshots

Monitored Processes

Analysis Information

Creation Time 2018-08-05 21:04 (UTC+2)
Analysis Duration 00:02:15
Number of Monitored Processes 2
Execution Successful True
Reputation Enabled True
WHOIS Enabled True
YARA Enabled True
Termination Reason All processes terminated
Tags
#XLSTART

Sample Information

ID #1589167
MD5 6753671c0f469af750cbaba22b6708de Copy to Clipboard
SHA1 2c11aed13c5f68acd0227a7f215aab28fe98440f Copy to Clipboard
SHA256 83b0d7926fb2c5bc0708d9201043107e8709d77f2cd2fb5cb7693b2d930378d2 Copy to Clipboard
SSDeep 24576:i8hIwgbPMx4pTm944MYPT38GPvuHHe4Oq7Uxizlb0:J Copy to Clipboard
Filename Invitation CBS 2018 .doc.rtf
File Size 853.48 KB
File Type RTF Document
Has VBA Macros True

Analyzer Information

Dynamic Analyzer Build Date 2018-07-30 18:44 (UTC+2)
Dynamic Analyzer Version 2.3.1
Static Analyzer Version 1.0.0
VTI Ruleset Version 3.0
YARA Built-in Ruleset Version 1.0
Analysis Report Layout Version 3
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image