Summary | ZeroBOX

InvoiceP038455.jar

Category Machine Started Completed
FILE s1_win7_x6402 July 2, 2021, 6:10 p.m. July 2, 2021, 6:13 p.m.
Size 184.3KB
Type Zip archive data, at least v2.0 to extract
MD5 3b9807d9332a324f920ca95e2282c082
SHA256 5536d8f5600ef53726c59c1027a620fce65ca6176179694bbddba2f52cb09c09
CRC32 F1B59C64
ssdeep 3072:21JQihTDw+IAH+0cyBPO5auK32iCXvev38caxy9jwwyO/NPeEoNx37Ly3TEt:YJQkkXAH+qBPO5auKm3ENkOVPnwvy3T4
Yara None matched

Name Response Post-Analysis Lookup
d2js2viceajwla.cloudfront.net
AAAA 2600:9000:2139:e400:11:6feb:6f80:93a1
AAAA 2600:9000:2139:f200:11:6feb:6f80:93a1
AAAA 2600:9000:2139:9a00:11:6feb:6f80:93a1
AAAA 2600:9000:2139:e600:11:6feb:6f80:93a1
AAAA 2600:9000:2139:6000:11:6feb:6f80:93a1
AAAA 2600:9000:2139:7200:11:6feb:6f80:93a1
AAAA 2600:9000:2139:3000:11:6feb:6f80:93a1
AAAA 2600:9000:2139:1c00:11:6feb:6f80:93a1
54.230.62.19
aus.thunderbird.net 54.230.62.19
prod.balrog.prod.cloudops.mozgcp.net 35.244.181.201
d2js2viceajwla.cloudfront.net 54.230.62.19
aus5.mozilla.org 35.244.181.201
prod.balrog.prod.cloudops.mozgcp.net 35.244.181.201
IP Address Status Action
164.124.101.2 Active Moloch
35.244.181.201 Active Moloch
99.86.144.100 Active Moloch
99.86.144.46 Active Moloch
99.86.144.61 Active Moloch
99.86.144.82 Active Moloch
99.86.202.125 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.102:49322
99.86.202.125:443
C=US, O=Let's Encrypt, CN=R3 CN=thunderbird.net dd:92:a0:f3:c5:f2:3a:c7:42:66:30:75:8a:b3:b3:03:6b:8c:df:9d
TLS 1.2
192.168.56.102:49323
35.244.181.201:443
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA C=US, ST=California, L=Mountain View, O=Mozilla Corporation, CN=aus5.mozilla.org 37:1a:8a:6e:ae:e7:b7:ae:1f:a9:c0:87:53:e5:a0:94:ef:0b:de:0c

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 8452
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 2555904
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000002640000
process_handle: 0xffffffffffffffff
1 0 0
host 99.86.144.100
host 99.86.144.46
host 99.86.144.61
host 99.86.144.82
count 3512 name heapspray process java.exe total_mb 878 length 262144 protection PAGE_READWRITE