Summary | ZeroBOX

HTMLDesginbrowser.vbs

Category Machine Started Completed
FILE s1_win7_x6401 Oct. 28, 2023, 12:37 p.m. Oct. 28, 2023, 12:39 p.m.
Size 110.5KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 b32067242d7b194386069c8cf33741df
SHA256 f1098c69adab031391ddc2a53df8af450f1a0c908fed813e6bc962d30a56599b
CRC32 46AF1E3D
ssdeep 1536:F+Xe4Mi3mI2hb7KZ18C2NGkikGkFjGkikGkKEt0eEKU+kCKGWGPrbrbTDDpOAWG/:keBQZxNj53e
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 104.21.84.67
IP Address Status Action
164.124.101.2 Active Moloch
172.67.187.200 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49161 -> 172.67.187.200:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.101:49161 -> 172.67.187.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49161 -> 172.67.187.200:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49161
172.67.187.200:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee cd:77:4c:26:1f:f8:63:15:43:5a:ba:aa:11:f1:e7:1a:23:3e:4b:15

request GET https://paste.ee/d/QzBhy
Symantec ISB.Downloader!gen40
Avast Script:SNH-gen [Trj]
Kaspersky HEUR:Trojan.VBS.SAgent.gen
ZoneAlarm HEUR:Trojan.VBS.SAgent.gen
AVG Script:SNH-gen [Trj]
Time & API Arguments Status Return Repeated

WSASend

buffer: kge<öE¼hðæȺ­ÕÁÚ°6ýæ‰K`Ô"8ÞW²×­ç/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 972
0 0

WSASend

buffer: FBA•û<.5†«?BÔϺNzˆmó½@5Y¿%—cô±óæ%ãøÊx°à«ÅÚ ›nUá²Ë›Ä”ÿ0ƒ¾~I€Xës„[Mç%4àLØ!žœ´¿ñ‡c ó†ÉÈrsք•Œ\}½GëÿY
socket: 972
0 0

WSASend

buffer: À¿²Àwú¤8F°Rq˜Í·»q¿ShXƒ‹(X0véÉ&èØyŸ5Äç%¶ÏňZhӔJ)9v÷AçÁX‘¨ˆW÷¢­ìt ùtažÿ )“OÔêi«%’gVáºÄ(ÞÏ{S&øVƒ­£.FñAɨÝxcш-ÄüE4Õ+¼Ø҈ýá¯×°aGO€ï<<“íɜÚVݹkÖXºJÄ#~B~؄n™°5¶.!`Ï÷ïSb‹K?æ ®€Á
socket: 972
0 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
Time & API Arguments Status Return Repeated

WSASend

buffer: kge<öE¼hðæȺ­ÕÁÚ°6ýæ‰K`Ô"8ÞW²×­ç/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 972
0 0

WSASend

buffer: FBA•û<.5†«?BÔϺNzˆmó½@5Y¿%—cô±óæ%ãøÊx°à«ÅÚ ›nUá²Ë›Ä”ÿ0ƒ¾~I€Xës„[Mç%4àLØ!žœ´¿ñ‡c ó†ÉÈrsք•Œ\}½GëÿY
socket: 972
0 0

WSASend

buffer: À¿²Àwú¤8F°Rq˜Í·»q¿ShXƒ‹(X0véÉ&èØyŸ5Äç%¶ÏňZhӔJ)9v÷AçÁX‘¨ˆW÷¢­ìt ùtažÿ )“OÔêi«%’gVáºÄ(ÞÏ{S&øVƒ­£.FñAɨÝxcш-ÄüE4Õ+¼Ø҈ýá¯×°aGO€ï<<“íɜÚVݹkÖXºJÄ#~B~؄n™°5¶.!`Ï÷ïSb‹K?æ ®€Á
socket: 972
0 0