Summary | ZeroBOX

HTMLIEcontentHistory.vbs

Category Machine Started Completed
FILE s1_win7_x6401 Oct. 30, 2023, 5:35 p.m. Oct. 30, 2023, 5:40 p.m.
Size 137.3KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 329ec572360f8e6cdddd1d7304e77001
SHA256 76a73ec52afc9b6ba0596388abba0ace5eb64779c0154fd976c521c470d53f14
CRC32 B2A7C633
ssdeep 1536:F+5lollote4Mi3mI2hb7KZ18C2NGkikGkFjGkikGkKEt0eEKU+kCKGWGPrbrbTDr:KqyeBQFJy
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 172.67.187.200
IP Address Status Action
104.21.84.67 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49161 -> 104.21.84.67:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.101:49161 -> 104.21.84.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49161
104.21.84.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee cd:77:4c:26:1f:f8:63:15:43:5a:ba:aa:11:f1:e7:1a:23:3e:4b:15

request GET https://paste.ee/d/w2GD0
Symantec ISB.Downloader!gen40
Kaspersky HEUR:Trojan.VBS.SAgent.gen
Google Detected
ZoneAlarm HEUR:Trojan.VBS.SAgent.gen
Varist VBS/Agent.BFC!Eldorado
Time & API Arguments Status Return Repeated

WSASend

buffer: kge?jã¥Ë¡š®òHОAú ٍ¾YBBáãm”ƒ/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 592
0 0

WSASend

buffer: FBA]Yý;ÍöxÂÒ¥ÙDÓݬáèü/±RôOök”X® XŽ°¦ô©äPÿ>Z ‡ò’ü.Ӏè >h^0©²g:$ÿ¤(Y]rI!fPÍQ³ýò~o@*©ñs÷g>£ïË4Ù6±ówsm*šï
socket: 592
0 0

WSASend

buffer: À®€4çS†£±†®Møæ&0ÜāðZŽ°¸ò‡òGØå“È:Ì>dúl¡P®O¤OB.?å+í*bïëZŸìŸ8nKÎøUO]GŸ¸0 äº,’ÅŠý”0זõãUçˆØW1ÊÛ\&O/"ÙUÆ} 6hañ¥¯zŠ8ù¹ÿ°®Ä=%ßãתã+´1Æþd›ÅðEÑk—}ôÙÁ+ bâyG(”AA#X]}ÿ Õ¢ÿW‡—SºRÓlGò)
socket: 592
0 0
Time & API Arguments Status Return Repeated

WSASend

buffer: kge?jã¥Ë¡š®òHОAú ٍ¾YBBáãm”ƒ/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 592
0 0

WSASend

buffer: FBA]Yý;ÍöxÂÒ¥ÙDÓݬáèü/±RôOök”X® XŽ°¦ô©äPÿ>Z ‡ò’ü.Ӏè >h^0©²g:$ÿ¤(Y]rI!fPÍQ³ýò~o@*©ñs÷g>£ïË4Ù6±ówsm*šï
socket: 592
0 0

WSASend

buffer: À®€4çS†£±†®Møæ&0ÜāðZŽ°¸ò‡òGØå“È:Ì>dúl¡P®O¤OB.?å+í*bïëZŸìŸ8nKÎøUO]GŸ¸0 äº,’ÅŠý”0זõãUçˆØW1ÊÛ\&O/"ÙUÆ} 6hañ¥¯zŠ8ù¹ÿ°®Ä=%ßãתã+´1Æþd›ÅðEÑk—}ôÙÁ+ bâyG(”AA#X]}ÿ Õ¢ÿW‡—SºRÓlGò)
socket: 592
0 0