Summary | ZeroBOX

presentation.jar

Category Machine Started Completed
FILE s1_win7_x6402 May 6, 2021, 10:36 a.m. May 6, 2021, 10:51 a.m.
Size 6.7KB
Type Java archive data (JAR)
MD5 c8548c1e92d4429e23ebd7aa1715a7b8
SHA256 0a8029dbf432e021dc701ffec76afbfd5111e26d7c7cf179e013d48e56d33de7
CRC32 463D6775
ssdeep 192:wjJg069FrSc66oicPgMoUReNaUc8avBen:wl56zeuEXoUn8qK
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
172.217.25.14 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 7388
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 2555904
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000002400000
process_handle: 0xffffffffffffffff
1 0 0
host 172.217.25.14
MicroWorld-eScan Trojan.GenericKD.46216341
FireEye Trojan.GenericKD.46216341
Alibaba Trojan:JAVA/Adwind.b58f8943
Arcabit Trojan.Generic.D2C13495
Avast Java:Malware-gen [Trj]
Kaspersky HEUR:Trojan.Java.Alien.gen
BitDefender Trojan.GenericKD.46216341
Ad-Aware Trojan.GenericKD.46216341
Comodo Malware@#2ly1thav7uzk1
McAfee-GW-Edition Artemis!Trojan
Emsisoft Trojan.GenericKD.46216341 (B)
Avira EXP/JAVA.Download.AMAA.Gen
MAX malware (ai score=89)
Gridinsoft Trojan.U.Downloader.oa
Microsoft Trojan:Java/Adwind.RA!MTB
AegisLab Trojan.Java.Alien.4!c
GData Trojan.GenericKD.46216341
Cynet Malicious (score: 99)
Tencent Java.Trojan.Alien.Syho
Ikarus Exploit.JAVA.Download
AVG Java:Malware-gen [Trj]
count 3569 name heapspray process java.exe total_mb 892 length 262144 protection PAGE_READWRITE