Summary | ZeroBOX

ttt.hta

Category Machine Started Completed
FILE s1_win7_x6401 May 17, 2024, 10:10 a.m. May 17, 2024, 10:12 a.m.
Size 1.5KB
Type HTML document, ASCII text, with CRLF line terminators
MD5 b5080c0d123ce430f1e28c370a0fa18b
SHA256 b3ab0b19478336a8c17ee9fd28ab6463df206b23f69c7e3b5eacc3efb11a0a95
CRC32 65DE6AD6
ssdeep 48:l4f/6SpKMucAjeYqgt40qPH5qs+X4h8+rda88Zjz:jSVAhtWntMjz
Yara None matched

Name Response Post-Analysis Lookup
brandwizer.co.in 5.9.123.217
IP Address Status Action
164.124.101.2 Active Moloch
5.9.123.217 Active Moloch

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2548
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73bc2000
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2548
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 32 (PAGE_EXECUTE_READ)
base_address: 0x7ef80000
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

RegSetValueExA

key_handle: 0x000003c0
regkey_r: ProxyEnable
reg_type: 4 (REG_DWORD)
value: 0
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
1 0 0
Lionic Trojan.HTML.Valyria.a!c
Skyhigh BehavesLike.HTML.Dropper.zq
ALYac Trojan.Script.Agent
VIPRE VB:Trojan.Kimsuky.A
Arcabit VB:Trojan.Kimsuky.A
Symantec Trojan Horse
ESET-NOD32 VBS/Kimsuky.AM
TrendMicro-HouseCall TROJ_FRS.0NA104EE24
Avast Other:Malware-gen [Trj]
Kaspersky HEUR:Trojan-Downloader.HTA.SLoad.gen
BitDefender VB:Trojan.Kimsuky.A
MicroWorld-eScan VB:Trojan.Kimsuky.A
Rising Trojan.Kimsuky/VBS!8.13D95 (TOPIS:E0:3BSGVFy9i7O)
Emsisoft VB:Trojan.Kimsuky.A (B)
TrendMicro TROJ_FRS.0NA104EE24
FireEye VB:Trojan.Kimsuky.A
Ikarus Trojan.VBS.Kimsuky
Microsoft Trojan:VBS/Malgent!MSR
ViRobot VBS.S.Running.1556
ZoneAlarm HEUR:Trojan-Downloader.HTA.SLoad.gen
GData VB:Trojan.Kimsuky.A
MAX malware (ai score=81)
AVG Other:Malware-gen [Trj]