Summary | ZeroBOX

MSS.vbs

Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 31, 2023, 5:42 p.m. Oct. 31, 2023, 5:57 p.m.
Size 137.3KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 95ef971ad0bbdace8a049b8b59ddd0e8
SHA256 917f30ee59de50efe5fc8d75c7efd730a79adc56587b4be1b40e5e77628a4c25
CRC32 F5E1E386
ssdeep 1536:F+PEWEse4Mi3mI2hb7KZ18C2NGkikGkFjGkikGkKEt0eEKU+kCKGWGPrbrbTDDpZ:qEWEseBQFJy
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 104.21.84.67
IP Address Status Action
164.124.101.2 Active Moloch
172.67.187.200 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49161 -> 172.67.187.200:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.103:49161 -> 172.67.187.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49161
172.67.187.200:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee 75:09:97:90:38:ad:dd:cc:0d:1b:d8:8b:02:ab:5d:a9:3b:7a:1f:1d

request GET https://paste.ee/d/lbxjP
Time & API Arguments Status Return Repeated

WSASend

buffer: kge@½ê)íy9Ä$ñ©‚«á‘Å+á¨x^­‰·û#‡² /5 ÀÀÀ À 28&ÿ paste.ee  
socket: 584
0 0

WSASend

buffer: FBA’xH•Æn5l¥š£×JL‹ý[±¨[Sä8‹FFÈPFxA[~ä¯}]ØW4š¤âx¬ìhýÊEFÒ0>úÚZœ§?Åý4Ôt /­_ãUÊñça¬$7Zcû[˜Ø¤9mŸ!¸L”]C3
socket: 584
0 0

WSASend

buffer: À$vu§Ýeæ±sÇɬ·³‹LùSï€%3äʐ-nðOæfÜ„ððe%ѱ[Šº]²|R½|þ{¸F”ë2}þ'TlÊa…SgTzÙן÷¹ËTô ¯»0€BÊ;5úª!FD¼fÆçk.¹žMH5¨f¤Â6e÷W%·×}þœ¥Í€Ášéº3èÃ>ŠØ.oá˜ÊÁÿ°kû›Hj;D^ï›`ڀ¾½hÚsPåƒâ¯o`à]ô
socket: 584
0 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
Time & API Arguments Status Return Repeated

WSASend

buffer: kge@½ê)íy9Ä$ñ©‚«á‘Å+á¨x^­‰·û#‡² /5 ÀÀÀ À 28&ÿ paste.ee  
socket: 584
0 0

WSASend

buffer: FBA’xH•Æn5l¥š£×JL‹ý[±¨[Sä8‹FFÈPFxA[~ä¯}]ØW4š¤âx¬ìhýÊEFÒ0>úÚZœ§?Åý4Ôt /­_ãUÊñça¬$7Zcû[˜Ø¤9mŸ!¸L”]C3
socket: 584
0 0

WSASend

buffer: À$vu§Ýeæ±sÇɬ·³‹LùSï€%3äʐ-nðOæfÜ„ððe%ѱ[Šº]²|R½|þ{¸F”ë2}þ'TlÊa…SgTzÙן÷¹ËTô ¯»0€BÊ;5úª!FD¼fÆçk.¹žMH5¨f¤Â6e÷W%·×}þœ¥Í€Ášéº3èÃ>ŠØ.oá˜ÊÁÿ°kû›Hj;D^ï›`ڀ¾½hÚsPåƒâ¯o`à]ô
socket: 584
0 0