Summary | ZeroBOX

bdolsx.vbs

Category Machine Started Completed
FILE s1_win7_x6401 Oct. 27, 2023, 10:51 a.m. Oct. 27, 2023, 10:53 a.m.
Size 110.5KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 44c457dd13efcd6622b1b6dbab5c1965
SHA256 a10028e47cd2bb4aac0b201619eeb280cd7eafa3f2bf57749302b24f19c04f46
CRC32 5741F728
ssdeep 1536:F+FBcBqe4Mi3mI2hb7KZ18C2NGkikGkFjGkikGkKEt0eEKU+kCKGWGPrbrbTDDp5:+BcBqeBQZxNj53e
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 172.67.187.200
IP Address Status Action
164.124.101.2 Active Moloch
172.67.187.200 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49161 -> 172.67.187.200:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.101:49161 -> 172.67.187.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49161
172.67.187.200:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee cd:77:4c:26:1f:f8:63:15:43:5a:ba:aa:11:f1:e7:1a:23:3e:4b:15

request GET https://paste.ee/d/ntKQd
Symantec ISB.Downloader!gen40
Avast Script:SNH-gen [Trj]
Kaspersky HEUR:Trojan.VBS.SAgent.gen
ZoneAlarm HEUR:Trojan.VBS.SAgent.gen
AVG Script:SNH-gen [Trj]
Time & API Arguments Status Return Repeated

WSASend

buffer: kge;ª¥Ë¡š®òHОAú ٍ¾YBBáãm”ƒ/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 972
0 0

WSASend

buffer: FBA]Yý;ÍöxÂÒ¥ÙDÓݬáèü/±RôOök”X® XŽ°¦ô©äPÿ>Z ‡ò’ü.Ӏè >h^0‹óm0‹ýÅ‚·Ä”$©*^µ•mT ’2uò¶‡ÃL#J†6ˆÓ9R ‡Ó
socket: 972
0 0

WSASend

buffer: À£ö¬„ó*éP%†ËÛøÑ»K¦Å¦q‡cÀ¾­g–bHg·oö:æÞ»ÈÆ֍.x¨“¡änóÉ%Rà8!´Yù •}¼!í¶)@»ëÉÑ‹%^Aû–ÞÛ.ù¨ÁLðcúf„?Dò ã䖍^«6¬†ŽTs÷¤eGÿIn¥e¸5>í sÓíü^õ}@3HÏ#[lJà ¿EmIúÝJE)³‚ó4Þ, ÞZšÉ˜)ò¯˜Óù¨kÛÊÍ
socket: 972
0 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
Time & API Arguments Status Return Repeated

WSASend

buffer: kge;ª¥Ë¡š®òHОAú ٍ¾YBBáãm”ƒ/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 972
0 0

WSASend

buffer: FBA]Yý;ÍöxÂÒ¥ÙDÓݬáèü/±RôOök”X® XŽ°¦ô©äPÿ>Z ‡ò’ü.Ӏè >h^0‹óm0‹ýÅ‚·Ä”$©*^µ•mT ’2uò¶‡ÃL#J†6ˆÓ9R ‡Ó
socket: 972
0 0

WSASend

buffer: À£ö¬„ó*éP%†ËÛøÑ»K¦Å¦q‡cÀ¾­g–bHg·oö:æÞ»ÈÆ֍.x¨“¡änóÉ%Rà8!´Yù •}¼!í¶)@»ëÉÑ‹%^Aû–ÞÛ.ù¨ÁLðcúf„?Dò ã䖍^«6¬†ŽTs÷¤eGÿIn¥e¸5>í sÓíü^õ}@3HÏ#[lJà ¿EmIúÝJE)³‚ó4Þ, ÞZšÉ˜)ò¯˜Óù¨kÛÊÍ
socket: 972
0 0