Summary | ZeroBOX

HRE.vbs

Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 31, 2023, 5:42 p.m. Oct. 31, 2023, 5:50 p.m.
Size 137.3KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 dd68aaf78901710759406c19281e1d6b
SHA256 ed894c41caf24ca689f2155ce7ce263ad06b4662830a25fb8ec25271ffb49184
CRC32 F3C4DA45
ssdeep 1536:F+ye4Mi3mI2hb7KZ18C2NGkikGkFjGkikGkKEt0eEKU+kCKGWGPrbrbTDDpOAWGv:xeBQFJy
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 172.67.187.200
IP Address Status Action
164.124.101.2 Active Moloch
172.67.187.200 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49161 -> 172.67.187.200:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.103:49161 -> 172.67.187.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49161
172.67.187.200:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee 75:09:97:90:38:ad:dd:cc:0d:1b:d8:8b:02:ab:5d:a9:3b:7a:1f:1d

request GET https://paste.ee/d/e59ok
Symantec ISB.Downloader!gen40
Avast Script:SNH-gen [Drp]
Kaspersky HEUR:Trojan.VBS.SAgent.gen
Varist VBS/Agent.BFC!Eldorado
ZoneAlarm HEUR:Trojan.VBS.SAgent.gen
Google Detected
AVG Script:SNH-gen [Drp]
Time & API Arguments Status Return Repeated

WSASend

buffer: kge@½íÎð‹„°¼6¼ã1,‡w_V=7´Ã}ò‹™ïÊm4/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 584
0 0

WSASend

buffer: FBAÓHB¢2!%74a³ž³Nçæâä,_걃ý-}e¤ˆ¬²²’êXå8Vö³ÄÏ{H–éáƒqʪlÎ}0°ÓY×xw¯7ÄÝ4·+R¢r¿â}"”÷7\ä›4v"åð•} z>ڔ‹6ä
socket: 584
0 0

WSASend

buffer: À{±­vnßɔÍښUS7±Œ{fšÉ&%Ò[(qÓ¯(77‰9s7y;zHSÂqå.j[ûÂý½V5;ÚIÅhܨjbÛ/7©¼1b7ß:q1ýhd@EþüŽ2·ó9¬H_›1Hõ¢Šîý1TEÎE—p·!ó5b%äJÅq/n'G äHà¶%Cþ¸Î•ØÃôôß]²Ëk¶¤Ð¥©‡!/‚ĝ:gŒËRöm‰… )ÉâƒNù÷ñ;gZnxÄçÓ
socket: 584
0 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
Time & API Arguments Status Return Repeated

WSASend

buffer: kge@½íÎð‹„°¼6¼ã1,‡w_V=7´Ã}ò‹™ïÊm4/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 584
0 0

WSASend

buffer: FBAÓHB¢2!%74a³ž³Nçæâä,_걃ý-}e¤ˆ¬²²’êXå8Vö³ÄÏ{H–éáƒqʪlÎ}0°ÓY×xw¯7ÄÝ4·+R¢r¿â}"”÷7\ä›4v"åð•} z>ڔ‹6ä
socket: 584
0 0

WSASend

buffer: À{±­vnßɔÍښUS7±Œ{fšÉ&%Ò[(qÓ¯(77‰9s7y;zHSÂqå.j[ûÂý½V5;ÚIÅhܨjbÛ/7©¼1b7ß:q1ýhd@EþüŽ2·ó9¬H_›1Hõ¢Šîý1TEÎE—p·!ó5b%äJÅq/n'G äHà¶%Cþ¸Î•ØÃôôß]²Ëk¶¤Ð¥©‡!/‚ĝ:gŒËRöm‰… )ÉâƒNù÷ñ;gZnxÄçÓ
socket: 584
0 0