Summary | ZeroBOX

miss-1732825037.xls

Downloader ScreenShot KeyLogger AntiDebug MSOffice File AntiVM
Category Machine Started Completed
FILE s1_win7_x6402 Nov. 3, 2021, 4:39 p.m. Nov. 3, 2021, 4:41 p.m.
Size 88.0KB
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 18:19:34 2015, Last Saved Time/Date: Tue Nov 2 07:35:16 2021, Security: 0
MD5 af175b239064b801b2fc6aa1f158ffc4
SHA256 dd9bd6c485a10c1292b6de139b48e19e89a05dc9627e73bd337448933e879704
CRC32 CCC116C4
ssdeep 1536:i5Kpb8rGYrMPe3q7Q0XV5xtezEsi8/dgw91vrVmxJiME2GhdD52lZPFu1AOgS+lO:0Kpb8rGYrMPe3q7Q0XV5xtezEsi8/dgK
Yara
  • Microsoft_Office_File_Downloader_Zero - Microsoft Office File Downloader
  • Microsoft_Office_File_Zero - Microsoft Office File

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2148
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6bce7000
process_handle: 0xffffffff
1 0 0
description Run a KeyLogger rule KeyLogger
description Take ScreenShot rule ScreenShot
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description Affect hook table rule win_hook
parent_process excel.exe martian_process "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" /Embedding
Process injection Process 2148 resumed a thread in remote process 812
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000464
suspend_count: 1
process_identifier: 812
1 0 0