Summary | ZeroBOX

Invoice-No.-9004_20210908.xlsb

Category Machine Started Completed
FILE s1_win7_x6403_us Sept. 9, 2021, 8:48 a.m. Sept. 9, 2021, 8:50 a.m.
Size 108.5KB
Type Microsoft Excel 2007+
MD5 cc064043229bad8f94a41de8a6ce8721
SHA256 ab0918b014bd81b35ac4e11e74dcd68add1ca8318dde0a48139152627e6f3c03
CRC32 2EF69635
ssdeep 1536:EWw/szrvkfOEwt1sMwv2sSMGuCAnq1Ue+TAj/h3vD4SZ/Z/hJGBfmIGEumGxfVx5:FTt7s32sSMLCx1KwpD4o/hwBuI5udyU3
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2372
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6bff2000
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

NtCreateFile

create_disposition: 2 (FILE_CREATE)
file_handle: 0x00000474
filepath: C:\Users\test22\AppData\Local\Temp\~$Invoice-No.-9004_20210908.xlsb
desired_access: 0xc0110080 (FILE_READ_ATTRIBUTES|DELETE|SYNCHRONIZE|GENERIC_WRITE)
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: \??\C:\Users\test22\AppData\Local\Temp\~$Invoice-No.-9004_20210908.xlsb
create_options: 4198496 (FILE_NON_DIRECTORY_FILE|FILE_SYNCHRONOUS_IO_NONALERT|FILE_DELETE_ON_CLOSE)
status_info: 2 (FILE_CREATED)
share_access: 1 (FILE_SHARE_READ)
1 0 0
CAT-QuickHeal XLS4.IcedID.42146
McAfee-GW-Edition Artemis!Trojan
ZoneAlarm UDS:DangerousObject.Multi.Generic
Ikarus Win32.Outbreak
Fortinet XML/IcedId.AL!tr
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2372
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 32 (PAGE_EXECUTE_READ)
base_address: 0x7ef70000
process_handle: 0xffffffff
1 0 0