Summary | ZeroBOX

ls.txt

Antivirus
Category Machine Started Completed
FILE s1_win7_x6402 May 2, 2021, 6:14 p.m. May 2, 2021, 6:17 p.m.
Size 4.5KB
Type ASCII text
MD5 af14952111df8accaad09dfaaae03ae6
SHA256 2cef710ffbfe236e8fa4e468e4ce8ff83a8958c0b020cc9a06268b03d4474990
CRC32 5BE79E00
ssdeep 96:FF8nYbF8IYbqbYbZbX4bYbZbGbYbZb2bYbZb5ba/LxbYbZb/:FIqFqAqBXKqBsqBcqB5bEL5qB/
Yara
  • Antivirus - Contains references to security software

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
172.217.25.14 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 7092
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73772000
process_handle: 0xffffffff
1 0 0
Symantec ISB.Downloader!gen221
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 7092
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 32 (PAGE_EXECUTE_READ)
base_address: 0x7ef90000
process_handle: 0xffffffff
1 0 0
host 172.217.25.14