Summary | ZeroBOX

don.vbs

Category Machine Started Completed
FILE s1_win7_x6401 Oct. 27, 2023, 10:51 a.m. Oct. 27, 2023, 10:55 a.m.
Size 110.5KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 049cbf1fa6fb0b213b5d6aace06efbd9
SHA256 82363ed62f3c1c0bf01610e503da99c602bc262a8385597ccec894181b881aaa
CRC32 1E95AA2C
ssdeep 1536:F+GWMmWMWe4Mi3mI2hb7KZ18C2NGkikGkFjGkikGkKEt0eEKU+kCKGWGPrbrbTDb:aq1eBQZxNj53e
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 172.67.187.200
IP Address Status Action
164.124.101.2 Active Moloch
172.67.187.200 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49161 -> 172.67.187.200:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.101:49161 -> 172.67.187.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49161
172.67.187.200:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee cd:77:4c:26:1f:f8:63:15:43:5a:ba:aa:11:f1:e7:1a:23:3e:4b:15

request GET https://paste.ee/d/y2sCr
Symantec ISB.Downloader!gen40
Avast Script:SNH-gen [Trj]
Kaspersky HEUR:Trojan.VBS.SAgent.gen
ZoneAlarm HEUR:Trojan.VBS.SAgent.gen
AVG Script:SNH-gen [Trj]
Time & API Arguments Status Return Repeated

WSASend

buffer: kge;¶¥Ë¡š®òHОAú ٍ¾YBBáãm”ƒ/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 972
0 0

WSASend

buffer: FBAƒ‘WQó’#!©ŸPë_sn`–”è²¾ìÙÉt 1zG§ aG䁵…ó*!7ú'ª;ðF++º­ÅXùNoÓÒ0‹‘Ðu¯7FÚ£ èÁéËéd §xÄô¾øâoŒ —‘«ì_«|lH]˜{Õ©„Š
socket: 972
0 0

WSASend

buffer: Àšádz)“Ð;¿ÛQ[ÀûdÅ$tvËÀl‡wË =½”<9ߑ¯¿Jæ~2ú¥‹X¿9_„ÞÍÏâNb´½©«û1ÈùÇ:E‹ˆ :KšÆð3JÍxÒòÐÖè8>ج`–‰Ë³’OòFŽÆԑoôᝆ¯?…àà0^) ágù«ßK=V¨™Xr»+¡/>¬+4’õÁ€Å§ÅϦ%Ò ù(„ ê|aý£ ÚÉÝåµAB(C÷Žaz:“
socket: 972
0 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
Time & API Arguments Status Return Repeated

WSASend

buffer: kge;¶¥Ë¡š®òHОAú ٍ¾YBBáãm”ƒ/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 972
0 0

WSASend

buffer: FBAƒ‘WQó’#!©ŸPë_sn`–”è²¾ìÙÉt 1zG§ aG䁵…ó*!7ú'ª;ðF++º­ÅXùNoÓÒ0‹‘Ðu¯7FÚ£ èÁéËéd §xÄô¾øâoŒ —‘«ì_«|lH]˜{Õ©„Š
socket: 972
0 0

WSASend

buffer: Àšádz)“Ð;¿ÛQ[ÀûdÅ$tvËÀl‡wË =½”<9ߑ¯¿Jæ~2ú¥‹X¿9_„ÞÍÏâNb´½©«û1ÈùÇ:E‹ˆ :KšÆð3JÍxÒòÐÖè8>ج`–‰Ë³’OòFŽÆԑoôᝆ¯?…àà0^) ágù«ßK=V¨™Xr»+¡/>¬+4’õÁ€Å§ÅϦ%Ò ù(„ ê|aý£ ÚÉÝåµAB(C÷Žaz:“
socket: 972
0 0