Summary | ZeroBOX

ngone.vbs

Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 27, 2023, 10:51 a.m. Oct. 27, 2023, 10:53 a.m.
Size 110.5KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 bb1a98b873c6fbebb5c2bab804fbe831
SHA256 216cbc905e2d771116f663a938476560ebffe77f7433d20c52bfbe49929de8b0
CRC32 3E7028ED
ssdeep 1536:F+s5i5be4Mi3mI2hb7KZ18C2NGkikGkFjGkikGkKEt0eEKU+kCKGWGPrbrbTDDp5:f5i5beBQZxNj53e
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 172.67.187.200
IP Address Status Action
104.21.84.67 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49161 -> 104.21.84.67:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.103:49161 -> 104.21.84.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49161
104.21.84.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee cd:77:4c:26:1f:f8:63:15:43:5a:ba:aa:11:f1:e7:1a:23:3e:4b:15

request GET https://paste.ee/d/zTsQV
Symantec ISB.Downloader!gen40
Avast Script:SNH-gen [Trj]
Kaspersky HEUR:Trojan.VBS.SAgent.gen
ZoneAlarm HEUR:Trojan.VBS.SAgent.gen
AVG Script:SNH-gen [Trj]
Time & API Arguments Status Return Repeated

WSASend

buffer: kge;­²}¡ápñ_3û³I¼:è:ìÝÈNUysLg0¥/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 968
0 0

WSASend

buffer: FBAQÙû3¾d2’~Ý uë¡k¬)‹ž=Þ{f›LRŠDrdibßÁ¬sd²'Ô;@‘ Çnÿ/JI\OR0q €Å’lÛÂ?÷r=À7Djtö±9œvã2ôà¦9ǔ„ý³ïó¥PmQ¾U?
socket: 968
0 0

WSASend

buffer: Àòü†/Ja1$ôÖǐ¢e²÷”ñ¶ý&²ôå=pLË'#û;Yï…ž|µ›wS©Â®7£Ê÷‘xò¯P{œVì®rº;¦ž¨ñHx—wi×á3麵‹æÓÇ7Q‡øt¬ñåö$Yә  ƒŠ$TõÞ®»8«îåfkØl—g»W$ÐÈþ;,ƒg‡°N=j9 úœ) îd ç€r<N“„jYzü݋;z©sGfÔdœÿè9ç˜ (˜.>ÊÌ
socket: 968
0 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
Time & API Arguments Status Return Repeated

WSASend

buffer: kge;­²}¡ápñ_3û³I¼:è:ìÝÈNUysLg0¥/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 968
0 0

WSASend

buffer: FBAQÙû3¾d2’~Ý uë¡k¬)‹ž=Þ{f›LRŠDrdibßÁ¬sd²'Ô;@‘ Çnÿ/JI\OR0q €Å’lÛÂ?÷r=À7Djtö±9œvã2ôà¦9ǔ„ý³ïó¥PmQ¾U?
socket: 968
0 0

WSASend

buffer: Àòü†/Ja1$ôÖǐ¢e²÷”ñ¶ý&²ôå=pLË'#û;Yï…ž|µ›wS©Â®7£Ê÷‘xò¯P{œVì®rº;¦ž¨ñHx—wi×á3麵‹æÓÇ7Q‡øt¬ñåö$Yә  ƒŠ$TõÞ®»8«îåfkØl—g»W$ÐÈþ;,ƒg‡°N=j9 úœ) îd ç€r<N“„jYzü݋;z©sGfÔdœÿè9ç˜ (˜.>ÊÌ
socket: 968
0 0