Summary | ZeroBOX

Funds_431353.wsf

Category Machine Started Completed
FILE s1_win7_x6403_us April 19, 2023, 5:50 p.m. April 19, 2023, 5:53 p.m.
Size 78.5KB
Type UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
MD5 05b869c9cc7e17a6216b23cc5da83ade
SHA256 8c399ed57197ce38c5aedbc5720690d34172f558701b50303ccf6c37700bc278
CRC32 567DA9B3
ssdeep 1536:RR3LU0FGHNkg5j+9GkGaeA1ZI4sDQ0G29cWoRWvmXYmSelDCPF:zU0Fs+9VpIRItovaYmSelDCPF
Yara None matched

Name Response Post-Analysis Lookup
pastebin.com 172.67.34.170
IP Address Status Action
104.20.67.143 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49161 -> 104.20.67.143:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49161
104.20.67.143:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com 79:b7:9c:ec:8a:be:ea:82:0d:16:04:fb:46:5f:89:6b:78:b9:43:fd

Time & API Arguments Status Return Repeated

__exception__

stacktrace:
CtfImeIsIME+0x36fd DllUnregisterServer-0xf9d9 msctf+0x2d08c @ 0x750bd08c
TF_GetGlobalCompartment+0x3dfd CtfImeIsIME-0x344 msctf+0x2964b @ 0x750b964b
TF_GetInputScope+0xf65 CtfImeDestroyThreadMgr-0x25ae msctf+0x14d6b @ 0x750a4d6b
TF_GetInputScope+0x3176 CtfImeDestroyThreadMgr-0x39d msctf+0x16f7c @ 0x750a6f7c
CtfImeDestroyInputContext+0x280 TF_CanUninitialize-0x1c msctf+0x1e825 @ 0x750ae825
TF_GetInputScope+0x21fc CtfImeDestroyThreadMgr-0x1317 msctf+0x16002 @ 0x750a6002
TF_GetInputScope+0x21e2 CtfImeDestroyThreadMgr-0x1331 msctf+0x15fe8 @ 0x750a5fe8
TF_GetInputScope+0xbdd CtfImeDestroyThreadMgr-0x2936 msctf+0x149e3 @ 0x750a49e3
TF_GetInputScope+0x1c1a CtfImeDestroyThreadMgr-0x18f9 msctf+0x15a20 @ 0x750a5a20
RtlIsCurrentThreadAttachExempt+0x5f TpCheckTerminateWorker-0x37 ntdll+0x39a91 @ 0x778d9a91
LdrShutdownProcess+0x97 RtlDetectHeapLeaks-0x1bb ntdll+0x58f10 @ 0x778f8f10
RtlExitUserProcess+0x74 LdrShutdownProcess-0x1d ntdll+0x58e5c @ 0x778f8e5c
ExitProcess+0x15 TerminateThread-0xa kernel32+0x17a25 @ 0x757f7a25
wscript+0x2fbd @ 0x352fbd
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: ff 51 0c 8b 45 fc 89 be 8c 04 00 00 3b c7 74 25
exception.symbol: TF_GetCompatibleKeyboardLayout+0x5885 TF_IsCtfmonRunning-0xfd3 msctf+0x43ef4
exception.instruction: call dword ptr [ecx + 0xc]
exception.module: MSCTF.dll
exception.exception_code: 0xc0000005
exception.offset: 278260
exception.address: 0x750d3ef4
registers.esp: 3405444
registers.edi: 0
registers.eax: 37364880
registers.ebp: 3405472
registers.edx: 1
registers.ebx: 0
registers.esi: 6689680
registers.ecx: 1941976444
1 0 0
request GET https://pastebin.com/raw/zD5ag0UX
request GET https://pastebin.com/raw/mJfkXNYx
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: https://pastebin.com/raw/zD5ag0UX
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 12582912
http_method: GET
referer:
path: /raw/zD5ag0UX
1 13369356 0

InternetReadFile

buffer: <!DOCTYPE html> <html lang="en"> <head> <meta name="viewport" content="width=device-width, initial-scale=0.75, maximum-scale=1.0, user-scalable=yes" /> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <title>Pastebin.com - Not Found (#404)</title> </head> <body> <h1>Not Found (#404)</h1> <p>This page is no longer available. It has either expired, been removed by its creator, or removed by one of the Pastebin staff.</p> </body> </html>
request_handle: 0x00cc000c
1 1 0

InternetCrackUrlW

url: https://pastebin.com/raw/mJfkXNYx
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 12582912
http_method: GET
referer:
path: /raw/mJfkXNYx
1 13369356 0

InternetReadFile

buffer: <!DOCTYPE html> <html lang="en"> <head> <meta name="viewport" content="width=device-width, initial-scale=0.75, maximum-scale=1.0, user-scalable=yes" /> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <title>Pastebin.com - Not Found (#404)</title> </head> <body> <h1>Not Found (#404)</h1> <p>This page is no longer available. It has either expired, been removed by its creator, or removed by one of the Pastebin staff.</p> </body> </html>
request_handle: 0x00cc000c
1 1 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: https://pastebin.com/raw/zD5ag0UX
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 12582912
http_method: GET
referer:
path: /raw/zD5ag0UX
1 13369356 0

send

buffer: !
socket: 852
sent: 1
1 1 0

send

buffer: okd?«k.ô~|Šn´ìŸä³™Úá"Xš*"¬þÌ-QEkÑ/5 ÀÀÀ À 28*ÿ pastebin.com  
socket: 960
sent: 116
1 116 0

send

buffer: !
socket: 852
sent: 1
1 1 0

send

buffer: FBAFÀº`ÆðJ”wQVžxQƒÿê,r¬Áib¥‘â_F3¾ÐÌ(2Q$ľ£]tA3BƒóÃá@VÃ#½‹ü0§ûª¦…½…z¨o9ƒí•$ŒÔ,¡v«ñŠ±jÙêäãåi,ÿqrñNqŸHU2è
socket: 960
sent: 134
1 134 0

send

buffer: !
socket: 852
sent: 1
1 1 0

send

buffer: PŒÿ…KŠ¬zä„a\p•Ú…ÿáô8Mp¡Ùbô3âH>ÕÜî…vH8÷Á[:§ÀD®•ü¼IÔ,¾²ÏKƈ-®Åç`½‰p§ö¬]46f E8A&9fGè2ûxJã×Ëe£òi’W'ŠåãbÁÙæ˜M[%"¨… MSFF³T°WG5åüzÿ‡hüÇ%ä_¹ŸVݝÜ¦lфzk…ѧÍ—_Ó2ƒ´Ü\v…›Adqt¡ ¸·Á0 ž;oŸŽ¥%uK™Ëôæ1¶S“‹l¨Ïy¾Ï»I®äqë(Oãah NCŽJzw”xÙpRQ[¼Ørý»gÆV÷*É÷ï»M²)ëIw¢v«}äáü2p[áÂÅÿpêÜò¾Ûc0Êyr'o”¶Û ‹èÍ`‹-uéXwŒì™8y $[9jÌ{;­›¼7!0x
socket: 960
sent: 341
1 341 0

send

buffer: !
socket: 852
sent: 1
1 1 0

InternetCrackUrlW

url: https://pastebin.com/raw/mJfkXNYx
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 12582912
http_method: GET
referer:
path: /raw/mJfkXNYx
1 13369356 0

send

buffer: PRfˆct¡ÄÝÜû%ÖРңÐ÷_×µ%ôGõ’‰ßE¥@Ý6ؘ—='„1ñŽ0©´In ¿é{Ü_ 0ã¿%*»KBV´…™ê 0óZ±NhKרbU¶åìtP‹]fxüþe.nçÚ6ºAó› oò\«ãl]âDHÈ}ZCþó[L:õõÀƒSÞù"¥®;øÕý“ CÂ4mO–|ì+ePâúb˜¼2ô†ÊoѝR£îyT忹óâ³›Ýò§\‚6f©0^Âۉ ½óR}ª zØÀöüŽùU]Îã˜}©‰‰èÊ4“˜ºÑ qfˆS$Ò°‡³Ý¸ƒ!6ØwEê˜ó©íaæeÝs#úpISZ°$êYa¥T ,ÌS«ä^HÛh&)³‹ù«¡‡_¸.þ7­ªÝÜjé×! C-d
socket: 960
sent: 341
1 341 0

send

buffer: !
socket: 852
sent: 1
1 1 0