Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Aug. 9, 2024, 3:49 p.m. | Aug. 9, 2024, 3:51 p.m. |
-
WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE" C:\Users\test22\AppData\Local\Temp\iden.doc
2548
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\~$iden.doc |
com_class | Scripting.FileSystemObject | May attempt to write one or more files to the harddisk |
cve | CVE-2013-3906 |
parent_process | winword.exe | martian_process | C:\\Users\\Public\\Documents\\MicrosoftWordUpdater.log |
file | C:\Users\Public\Documents\MicrosoftWordUpdater.log |
Bkav | W32.Common.3AD25B27 |
Lionic | Trojan.MSWord.ObfDldr.b!c |
Cynet | Malicious (score: 99) |
Skyhigh | BehavesLike.OLE2.Suspicious.tg |
ALYac | Trojan.Downloader.DOC.Gen |
VIPRE | VBA.Heur2.ObfDldr.9.01CA8320.Gen |
Arcabit | VBA.Heur2.ObfDldr.9.01CA8320.Gen |
Symantec | ISB.Downloader!gen433 |
Elastic | malicious (high confidence) |
ESET-NOD32 | Win64/Agent.DZF |
Avast | VBA:Downloader-BMF [Trj] |
Kaspersky | HEUR:Trojan-Dropper.MSOffice.SDrop.gen |
BitDefender | VBA.Heur2.ObfDldr.9.01CA8320.Gen |
NANO-Antivirus | Trojan.Ole2.Vbs-heuristic.druvzi |
MicroWorld-eScan | VBA.Heur2.ObfDldr.9.01CA8320.Gen |
Rising | Trojan.Agent!8.B1E (TOPIS:E0:rYd0cec0tnN) |
Emsisoft | VBA.Heur2.ObfDldr.9.01CA8320.Gen (B) |
F-Secure | Malware.W97M/AVA.Downloader.lwxgm |
TrendMicro | HEUR_VBA.O2 |
FireEye | VBA.Heur2.ObfDldr.9.01CA8320.Gen |
Ikarus | VBA.ObfDldr |
Detected.Heuristic.Script | |
Avira | W97M/AVA.Downloader.lwxgm |
MAX | malware (ai score=89) |
Antiy-AVL | Trojan[Downloader]/MSOffice.Agent |
Microsoft | Trojan:Win32/Leonem |
ZoneAlarm | HEUR:Trojan-Dropper.MSOffice.SDrop.gen |
GData | VBA.Heur2.ObfDldr.9.01CA8320.Gen |
Varist | ABRisk.ZIZZ- |
AhnLab-V3 | Trojan/DOC.Agent |
Acronis | suspicious |
TACHYON | Suspicious/W97M.DRP.Gen |
Tencent | Trojan.MsOffice.MacroS.11030723 |
Fortinet | VBA/Dloader.BMF!tr |
AVG | VBA:Downloader-BMF [Trj] |
alibabacloud | Trojan[dropper]:MSOffice/SDrop.gyf |
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1096 | length | 561152 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 512 | name | heapspray | process | WINWORD.EXE | total_mb | 220 | length | 450560 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1032 | length | 528384 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1208 | length | 618496 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 512 | name | heapspray | process | WINWORD.EXE | total_mb | 232 | length | 475136 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1072 | length | 548864 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 1345 | name | heapspray | process | WINWORD.EXE | total_mb | 236 | length | 184320 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2051 | name | heapspray | process | WINWORD.EXE | total_mb | 1121 | length | 573440 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 897 | name | heapspray | process | WINWORD.EXE | total_mb | 115 | length | 135168 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1104 | length | 565248 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1192 | length | 610304 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 512 | name | heapspray | process | WINWORD.EXE | total_mb | 230 | length | 471040 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 448 | name | heapspray | process | WINWORD.EXE | total_mb | 108 | length | 253952 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 1336 | name | heapspray | process | WINWORD.EXE | total_mb | 203 | length | 159744 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 896 | name | heapspray | process | WINWORD.EXE | total_mb | 108 | length | 126976 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 1044 | name | heapspray | process | WINWORD.EXE | total_mb | 668 | length | 671744 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1296 | length | 663552 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 448 | name | heapspray | process | WINWORD.EXE | total_mb | 126 | length | 294912 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 512 | name | heapspray | process | WINWORD.EXE | total_mb | 226 | length | 462848 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 448 | name | heapspray | process | WINWORD.EXE | total_mb | 105 | length | 245760 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 896 | name | heapspray | process | WINWORD.EXE | total_mb | 129 | length | 151552 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1232 | length | 630784 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 294 | name | heapspray | process | WINWORD.EXE | total_mb | 89 | length | 319488 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 448 | name | heapspray | process | WINWORD.EXE | total_mb | 106 | length | 249856 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1160 | length | 593920 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 1344 | name | heapspray | process | WINWORD.EXE | total_mb | 262 | length | 204800 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1280 | length | 655360 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 449 | name | heapspray | process | WINWORD.EXE | total_mb | 103 | length | 241664 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1272 | length | 651264 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1216 | length | 622592 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 896 | name | heapspray | process | WINWORD.EXE | total_mb | 196 | length | 229376 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1264 | length | 647168 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1064 | length | 544768 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 512 | name | heapspray | process | WINWORD.EXE | total_mb | 222 | length | 454656 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 448 | name | heapspray | process | WINWORD.EXE | total_mb | 133 | length | 311296 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 385 | name | heapspray | process | WINWORD.EXE | total_mb | 175 | length | 479232 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 449 | name | heapspray | process | WINWORD.EXE | total_mb | 121 | length | 282624 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 1344 | name | heapspray | process | WINWORD.EXE | total_mb | 220 | length | 172032 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 1344 | name | heapspray | process | WINWORD.EXE | total_mb | 252 | length | 196608 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 897 | name | heapspray | process | WINWORD.EXE | total_mb | 199 | length | 233472 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1128 | length | 577536 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 897 | name | heapspray | process | WINWORD.EXE | total_mb | 105 | length | 122880 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1136 | length | 581632 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 512 | name | heapspray | process | WINWORD.EXE | total_mb | 218 | length | 446464 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 448 | name | heapspray | process | WINWORD.EXE | total_mb | 115 | length | 270336 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 448 | name | heapspray | process | WINWORD.EXE | total_mb | 131 | length | 307200 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 1345 | name | heapspray | process | WINWORD.EXE | total_mb | 210 | length | 163840 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 900 | name | heapspray | process | WINWORD.EXE | total_mb | 189 | length | 221184 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 448 | name | heapspray | process | WINWORD.EXE | total_mb | 119 | length | 278528 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 2048 | name | heapspray | process | WINWORD.EXE | total_mb | 1248 | length | 638976 | protection | PAGE_READWRITE |