Summary | ZeroBOX

InvoicePO-03092021.jar

Category Machine Started Completed
FILE s1_win7_x6402 July 2, 2021, 6:23 p.m. July 2, 2021, 6:26 p.m.
Size 188.9KB
Type Zip archive data, at least v2.0 to extract
MD5 88811d5b8004bca2c3166e3cedd10fe3
SHA256 6a39055318c5ff39bb354e675325e0f929de46455a92117afba43b3824a4da9a
CRC32 07270557
ssdeep 3072:lacjzJ3t108fD2yIYgyZVDP1CdbpL0XVN4vS74xHtrLRJo3a98MbrlbV:laWysD2yIYgofspLsN4vS7Qh3b1V
Yara None matched

Name Response Post-Analysis Lookup
d2js2viceajwla.cloudfront.net
AAAA 2600:9000:2139:e800:11:6feb:6f80:93a1
AAAA 2600:9000:2139:b800:11:6feb:6f80:93a1
AAAA 2600:9000:2139:a00:11:6feb:6f80:93a1
AAAA 2600:9000:2139:aa00:11:6feb:6f80:93a1
AAAA 2600:9000:2139:9000:11:6feb:6f80:93a1
AAAA 2600:9000:2139:8a00:11:6feb:6f80:93a1
AAAA 2600:9000:2139:1c00:11:6feb:6f80:93a1
AAAA 2600:9000:2139:600:11:6feb:6f80:93a1
54.230.62.45
aus.thunderbird.net 54.230.62.45
prod.balrog.prod.cloudops.mozgcp.net 35.244.181.201
d2js2viceajwla.cloudfront.net 54.230.62.45
aus5.mozilla.org 35.244.181.201
prod.balrog.prod.cloudops.mozgcp.net 35.244.181.201
IP Address Status Action
164.124.101.2 Active Moloch
35.244.181.201 Active Moloch
99.86.144.100 Active Moloch
99.86.144.46 Active Moloch
99.86.144.61 Active Moloch
99.86.144.82 Active Moloch
99.86.202.23 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.102:49324
99.86.202.23:443
C=US, O=Let's Encrypt, CN=R3 CN=thunderbird.net dd:92:a0:f3:c5:f2:3a:c7:42:66:30:75:8a:b3:b3:03:6b:8c:df:9d
TLS 1.2
192.168.56.102:49325
35.244.181.201:443
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA C=US, ST=California, L=Mountain View, O=Mozilla Corporation, CN=aus5.mozilla.org 37:1a:8a:6e:ae:e7:b7:ae:1f:a9:c0:87:53:e5:a0:94:ef:0b:de:0c

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 5568
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 2555904
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000002550000
process_handle: 0xffffffffffffffff
1 0 0
host 99.86.144.100
host 99.86.144.46
host 99.86.144.61
host 99.86.144.82
count 3534 name heapspray process java.exe total_mb 883 length 262144 protection PAGE_READWRITE