Summary | ZeroBOX

Remittance%20E-MAIL%20Layout%20-%2011_.jar

Category Machine Started Completed
FILE s1_win7_x6402 May 11, 2021, 10:50 a.m. May 11, 2021, 10:52 a.m.
Size 89.4KB
Type Zip archive data, at least v2.0 to extract
MD5 9b6d479272935796ca92e0a610c8ae45
SHA256 7bd29b61cdc2bbcdb2ba87ed9f103bba116eda52a53030242bc74742429ab494
CRC32 8E3F0DD0
ssdeep 1536:E0m2TVXUMPQi92GDrnIJvDbprCX6Qal36JvYtgMWsI8xvHueGCRaGy/cbiio/7Vg:tTVdMcOxCKGJvY0IxWeGCRviZr5g
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
172.217.25.14 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1836
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 2555904
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00000000024d0000
process_handle: 0xffffffffffffffff
1 0 0
host 172.217.25.14
DrWeb Java.Siggen.491
MicroWorld-eScan Trojan.Java.Agent.BPX
FireEye Trojan.Java.Agent.BPX
AegisLab Trojan.Script.Generic.4!c
Alibaba TrojanSpy:JAVA/Generic.2bf3b32b
Cyren Java/Kryptik.L.gen!Eldorado
Symantec Trojan.Gen.NPE
ESET-NOD32 a variant of Java/Spy.Agent.S
Avast Java:Malware-gen [Trj]
Kaspersky HEUR:Trojan.Java.Agent.gen
BitDefender Trojan.Java.Agent.BPX
Ad-Aware Trojan.Java.Agent.BPX
Emsisoft Trojan.Java.Agent.BPX (B)
Avira JAVA/Spy.Agent.ilyda
MAX malware (ai score=81)
GData Trojan.Java.Agent.BPX
Cynet Malicious (score: 99)
Ikarus Trojan.Java.Spy
Fortinet Java/Agent.S!tr.spy
AVG Java:Malware-gen [Trj]
count 3421 name heapspray process java.exe total_mb 855 length 262144 protection PAGE_READWRITE