Summary | ZeroBOX

3ebce3a4.png

MSOffice File
Category Machine Started Completed
FILE s1_win7_x6402 June 24, 2021, 6:49 p.m. June 24, 2021, 6:58 p.m.
Size 1.4MB
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Dec 11 11:47:44 2009, Security: 0, Code page: 936, Revision Number: {B6B0541C-9DBE-43EF-AEC8-07D4CEDF10E4}, Number of Words: 2, Subject: 6AkGp, Author: 6AkGp, Name of Creating Application: Advanced Installer 16.5 build 8df7ad95, Template: ;2052, Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200
MD5 d0fc39d941e2d32edc687c3f6275afd8
SHA256 c14533a0e3f966ae74436d586ae6674cfe96718b0acd0abdac63dd60a1e7ccd0
CRC32 E1CD4592
ssdeep 24576:hWuDXX4zG04BMeRocDP1NOYRn4nJjgDyk7TS4McbFdBbfYNn+Nnnm6ByMEUT:h7XIzi5ooRqJ8O6FbFdB0N+Nnnm6U4
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
172.217.25.14 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

host 172.217.25.14
MicroWorld-eScan Gen:Variant.Bulz.446252
CAT-QuickHeal Trojan.Convagent
Zillya Trojan.Convagent.Win32.3606
Arcabit Trojan.Bulz.D6CF2C
Cyren W64/Trojan.YKWW-0822
Symantec Trojan.Gen.MBT
ESET-NOD32 multiple detections
TrendMicro-HouseCall TrojanSpy.Win64.NOON.UHBAZCLOC
Avast Win32:ExploitX-gen [Expl]
ClamAV Win.Trojan.Bulz-9863763-0
Kaspersky Trojan.VBS.Agent.avh
BitDefender Gen:Variant.Bulz.446252
NANO-Antivirus Trojan.Win64.Packed2.iwazfy
AegisLab Trojan.VBS.Agent.4!c
Tencent Win32.Trojan.Agentb.Wsae
Sophos Mal/Generic-R
DrWeb Trojan.Packed2.43111
TrendMicro TROJ_GEN.R002C0PFG21
McAfee-GW-Edition RDN/Generic.com
FireEye Gen:Variant.Bulz.446252
Emsisoft Gen:Variant.Bulz.446252 (B)
Avira TR/VB.Agent.gnhre
MAX malware (ai score=81)
Microsoft Trojan:Win32/Phonzy.A!ml
GData Script.Trojan.PurpleFox.D
Cynet Malicious (score: 99)
McAfee RDN/Generic.com
VBA32 Trojan.Packed
Rising Trojan.PurpleFox/MSI!1.D10D (CLASSIC)
Ikarus Trojan.Win32.VMProtect
Fortinet W32/PossibleThreat
BitDefenderTheta Gen:NN.ZedlaF.34758.rG4@aWpFvhd
AVG Win32:ExploitX-gen [Expl]