Summary | ZeroBOX

HTMLIEBrowserHistory.vbs

Category Machine Started Completed
FILE s1_win7_x6401 Oct. 28, 2023, 12:39 p.m. Oct. 28, 2023, 12:41 p.m.
Size 137.3KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 56238116f5d9877c000e6431306d0071
SHA256 af3726be77dd71685498be6e2ec2276a2541ddbc96745b6663118078d9c3724c
CRC32 D4C85AB1
ssdeep 1536:F+RlOlqe4Mi3mI2hb7KZ18C2NGkikGkFjGkikGkKEt0eEKU+kCKGWGPrbrbTDDpZ:y0AeBQFJy
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 104.21.84.67
IP Address Status Action
104.21.84.67 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49161 -> 104.21.84.67:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.101:49161 -> 104.21.84.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49161
104.21.84.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee cd:77:4c:26:1f:f8:63:15:43:5a:ba:aa:11:f1:e7:1a:23:3e:4b:15

request GET https://paste.ee/d/MckQn
Symantec ISB.Downloader!gen40
Time & API Arguments Status Return Repeated

WSASend

buffer: kge<‚j€GÔöérùJk~çXL§ÓM5~í]A wN/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 588
0 0

WSASend

buffer: FBAš§V$ÙÏÈo£Á06Æý²a1†Îh0p°²Ñæ€q(,OiÂüò‹˜}ˆ•Wki£gqmtühz//ˆa½;0jìŸIÿ•æ?&wíA\s÷ÿËæ ²ľ°pâŒø‚Æ|=r2'¤ú‘ÓfE
socket: 588
0 0

WSASend

buffer: À+bþÍ¿™s{ƒ.˜]fçƒP«-âÖ%Ñ0Òœ‡Ñ"'+@Fá’¤ š"š ï¢÷þdAϨEÐsæ¾Ì‡,H=¼\£Äçn±â7Rp…íù±­”LËõ9n¶!ݛN´D5,&ªÓP$†3çRþ•´4`¥<!ë "Ì,ÿjöÕ×ú.Yé(òÃbšÂ‡¢€øú8°–4Äi½~o–õpB2Xԃ\Äâ¤!¼§ó †{Ó#ð·
socket: 588
0 0
Time & API Arguments Status Return Repeated

WSASend

buffer: kge<‚j€GÔöérùJk~çXL§ÓM5~í]A wN/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 588
0 0

WSASend

buffer: FBAš§V$ÙÏÈo£Á06Æý²a1†Îh0p°²Ñæ€q(,OiÂüò‹˜}ˆ•Wki£gqmtühz//ˆa½;0jìŸIÿ•æ?&wíA\s÷ÿËæ ²ľ°pâŒø‚Æ|=r2'¤ú‘ÓfE
socket: 588
0 0

WSASend

buffer: À+bþÍ¿™s{ƒ.˜]fçƒP«-âÖ%Ñ0Òœ‡Ñ"'+@Fá’¤ š"š ï¢÷þdAϨEÐsæ¾Ì‡,H=¼\£Äçn±â7Rp…íù±­”LËõ9n¶!ݛN´D5,&ªÓP$†3çRþ•´4`¥<!ë "Ì,ÿjöÕ×ú.Yé(òÃbšÂ‡¢€øú8°–4Äi½~o–õpB2Xԃ\Äâ¤!¼§ó †{Ó#ð·
socket: 588
0 0