Summary | ZeroBOX

JDS.vbs

Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 31, 2023, 5:42 p.m. Oct. 31, 2023, 6:01 p.m.
Size 137.3KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 16c6922f713e35f485266c858eeeb038
SHA256 f3f7dff00ae17fb0044043a1e7f792bf8047ffa80020bf4099bcbdeee2be3245
CRC32 4180FC68
ssdeep 1536:F+WNSe4Mi3mI2hb7KZ18C2NGkikGkFjGkikGkKEt0eEKU+kCKGWGPrbrbTDDpOAH:lNSeBQFJy
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 172.67.187.200
IP Address Status Action
164.124.101.2 Active Moloch
172.67.187.200 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49161 -> 172.67.187.200:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.103:49161 -> 172.67.187.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49161
172.67.187.200:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee 75:09:97:90:38:ad:dd:cc:0d:1b:d8:8b:02:ab:5d:a9:3b:7a:1f:1d

request GET https://paste.ee/d/puovb
Time & API Arguments Status Return Repeated

WSASend

buffer: kge@½ð²}¡ápñ_3û³I¼:è:ìÝÈNUysLg0¥/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 584
0 0

WSASend

buffer: FBAQÙû3¾d2’~Ý uë¡k¬)‹ž=Þ{f›LRŠDrdibßÁ¬sd²'Ô;@‘ Çnÿ/JI\OR0Uö°Ø&¦<n󃈚pé²Ð™yÝA4V—¤¾.ÁNj*Ú³@tx ˪g9u3ù‹®
socket: 584
0 0

WSASend

buffer: À´öùKçòø‚)ÆÒ&W…ÁXgŠW)JÕ f±©&B ýߎ³RՍK e©FsêaÂC{X6%g¯0&³ø»›…—×?ÏÂA&+š"æÐâJr%C@N½Š›?,œ6$³A#R,¨¬Ð’Òœ/źœ!9S÷F]æà"ÆH'@s9³^9VÒmÔ»Ù¢ =ø% rX„B¾F¤ub‘±?„Ä4Zù`ЧÓbqA.±gúbv7!Œ`„žM]5‘a
socket: 584
0 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
Time & API Arguments Status Return Repeated

WSASend

buffer: kge@½ð²}¡ápñ_3û³I¼:è:ìÝÈNUysLg0¥/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 584
0 0

WSASend

buffer: FBAQÙû3¾d2’~Ý uë¡k¬)‹ž=Þ{f›LRŠDrdibßÁ¬sd²'Ô;@‘ Çnÿ/JI\OR0Uö°Ø&¦<n󃈚pé²Ð™yÝA4V—¤¾.ÁNj*Ú³@tx ˪g9u3ù‹®
socket: 584
0 0

WSASend

buffer: À´öùKçòø‚)ÆÒ&W…ÁXgŠW)JÕ f±©&B ýߎ³RՍK e©FsêaÂC{X6%g¯0&³ø»›…—×?ÏÂA&+š"æÐâJr%C@N½Š›?,œ6$³A#R,¨¬Ð’Òœ/źœ!9S÷F]æà"ÆH'@s9³^9VÒmÔ»Ù¢ =ø% rX„B¾F¤ub‘±?„Ä4Zù`ЧÓbqA.±gúbv7!Œ`„žM]5‘a
socket: 584
0 0