Summary | ZeroBOX

embedded-empire-xls.docx

Category Machine Started Completed
FILE s1_win7_x6401 May 19, 2021, 1:24 p.m. May 19, 2021, 1:49 p.m.
Size 29.2KB
Type Microsoft Word 2007+
MD5 78676b31e396f912739664c3154f5169
SHA256 15e817f764c157e948451b6c98af0141cf8aba4039e19c16e5aeb25ebac12283
CRC32 C693E655
ssdeep 768:/DPBHe/RfbPH//WBChEa2oFBoWqNmiPvkN884pPj3S:785Tf2C3FBoWq8iPvkN88mPLS
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1116
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6c9b1000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1116
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6ca05000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1116
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x732d1000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1116
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6c981000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1116
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6c781000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1116
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6c784000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1116
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x65001000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1116
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6c761000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1116
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x061b0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1116
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x061b0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1116
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x061c0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1116
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x061d0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1116
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x507c1000
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\~$bedded-empire-xls.docx
Time & API Arguments Status Return Repeated

NtCreateFile

create_disposition: 5 (FILE_OVERWRITE_IF)
file_handle: 0x000003ec
filepath: C:\Users\test22\AppData\Local\Temp\~$bedded-empire-xls.docx
desired_access: 0x40100080 (FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: \??\C:\Users\test22\AppData\Local\Temp\~$bedded-empire-xls.docx
create_options: 4194400 (FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT)
status_info: 2 (FILE_CREATED)
share_access: 0 ()
1 0 0
cve CVE-2013-3906
MicroWorld-eScan VB.Heur2.PwShell.2.B3FB2559.Gen
CAT-QuickHeal X97M.Downloader.37566
Sangfor Trojan.Macro.PowerShell.se
Alibaba TrojanDownloader:VBA/Obfuscation.A
Arcabit VB.Heur2.PwShell.2.B3FB2559.Gen
Cyren Trojan.UYHU-2
Symantec Trojan.Gen.NPE
ESET-NOD32 a variant of Generik.MRTBRXU
Baidu VBA.Trojan-Downloader.Agent.cme
Avast VBA:Downloader-GFZ [Trj]
Kaspersky HEUR:Trojan-Downloader.Script.Generic
BitDefender VB.Heur2.PwShell.2.B3FB2559.Gen
NANO-Antivirus Trojan.Macro.Downloader.inbiqr
ViRobot DOC.Z.Agent.29878
Tencent Win32.Trojan.Macrov.Ahyl
TACHYON Suspicious/WOX.Obfus.Gen.2
Emsisoft VB.Heur2.PwShell.2.B3FB2559.Gen (B)
Comodo TrojWare.Win32.BadShell.XSN@7pmib7
F-Secure Heuristic.HEUR/Macro.Downloader.MRSQ.Gen
DrWeb modification of W97M.Suspicious.1
McAfee-GW-Edition BehavesLike.Downloader.mc
FireEye VB.Heur2.PwShell.2.B3FB2559.Gen
Ikarus Trojan.SuspectCRC
GData VB.Heur2.PwShell.2.B3FB2559.Gen
Avira HEUR/Macro.Downloader.MRSQ.Gen
AegisLab Trojan.Script.Generic.a!c
ZoneAlarm HEUR:Trojan-Downloader.Script.Generic
Cynet Malicious (score: 99)
AhnLab-V3 Powershell/Downloader.S5
MAX malware (ai score=81)
Rising Macro.Powershell.b (CLASSIC)
SentinelOne Static AI - Suspicious OPENXML
Fortinet WM/Agent.C93D!tr
AVG VBA:Downloader-GFZ [Trj]