Summary | ZeroBOX

ALL.TXT

Category Machine Started Completed
FILE s1_win7_x6402 April 27, 2021, 9:45 a.m. April 27, 2021, 9:49 a.m.
Size 1.2KB
Type ASCII text, with CRLF line terminators
MD5 52552b7037fd640317f7d2de1b854288
SHA256 0d74a33006727ab086e281681cc8ee3d71ee7843f19b6fa52a86efc92b0444a1
CRC32 4BCBDC0E
ssdeep 24:mdfz1RoYFZl8V7OOMm8V7LOsTjMtXiOiP659who5lKuPxNYK/tC9+NYfwQcB:mB1KYFZl8TMm80s3qyOiP6LGZuPxNltV
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
172.217.25.14 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 6988
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73772000
process_handle: 0xffffffff
1 0 0
description Take screenshot rule screenshot
description Affect system registries rule win_registry
description Affect system token rule win_token
description Affect private profile rule win_files_operation
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
host 172.217.25.14
MicroWorld-eScan Heur.BZC.PZQ.Boxter.794.C1C92E66
FireEye Heur.BZC.PZQ.Boxter.794.C1C92E66
ALYac Heur.BZC.PZQ.Boxter.794.C1C92E66
Symantec ISB.Downloader!gen281
ESET-NOD32 PowerShell/TrojanDownloader.Agent.DTA
Avast Script:SNH-gen [Trj]
BitDefender Heur.BZC.PZQ.Boxter.794.C1C92E66
Ad-Aware Heur.BZC.PZQ.Boxter.794.C1C92E66
Arcabit Heur.BZC.PZQ.Boxter.794.C1C92E66
GData Heur.BZC.PZQ.Boxter.794.C1C92E66
MAX malware (ai score=83)
AVG Script:SNH-gen [Trj]