Summary | ZeroBOX

HTMLIEbrowserHistorycache.vbs

Category Machine Started Completed
FILE s1_win7_x6401 Nov. 2, 2023, 10:03 a.m. Nov. 2, 2023, 10:05 a.m.
Size 51.4KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 857f884bf745995ea1ccd1275446201f
SHA256 ba97164dd8f816967dd22dc025621fc1200cfbba8485ef10206796bf9de97c11
CRC32 B4F05FB3
ssdeep 768:elowjTyU0EteFw4Ghtr5A9xoO3R5Y9Uvyw2qZkQFRFPUHvjudm9d26f1:PZpJ3R5Y9FBkW
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 104.21.84.67
IP Address Status Action
164.124.101.2 Active Moloch
172.67.187.200 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49161 -> 172.67.187.200:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.101:49161 -> 172.67.187.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49161
172.67.187.200:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee 75:09:97:90:38:ad:dd:cc:0d:1b:d8:8b:02:ab:5d:a9:3b:7a:1f:1d

request GET https://paste.ee/d/QBMBa
Symantec ISB.Downloader!gen40
Kaspersky HEUR:Trojan.VBS.SAgent.gen
ZoneAlarm HEUR:Trojan.VBS.SAgent.gen
Time & API Arguments Status Return Repeated

WSASend

buffer: kgeBõJ¥Ë¡š®òHОAú ٍ¾YBBáãm”ƒ/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 592
0 0

WSASend

buffer: FBA]Yý;ÍöxÂÒ¥ÙDÓݬáèü/±RôOök”X® XŽ°¦ô©äPÿ>Z ‡ò’ü.Ӏè >h^0õ~‰­k“ž`wÊÒ°†pô¡Ã¡Ö«’®à²OÛRšÿTæÿqŽLdª‚Z¾LDG;X
socket: 592
0 0

WSASend

buffer: ÀºiXÊjcùÉgtn¯‘(?;ؤtÌàhÆLÚFßÁb¼Yþx¡ïræEë/]/R§ÍãʏŇvêÙÛϤÕñ†G”è qs«QÍ!àýŒ¬µ,ÌöS’âf6‘,«÷â}ú€Ú”`fûi#!?ź.”ë W72ÎoÇ ±¯m/¹uúhØ fŸ%ì]rºp²È쟇ñŸ±-ÿ¡¡¯Ì&ª—Rˆ~‘ˆË$Rò]Ñ(¥Â²ژxelxOþßñ
socket: 592
0 0
Time & API Arguments Status Return Repeated

WSASend

buffer: kgeBõJ¥Ë¡š®òHОAú ٍ¾YBBáãm”ƒ/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 592
0 0

WSASend

buffer: FBA]Yý;ÍöxÂÒ¥ÙDÓݬáèü/±RôOök”X® XŽ°¦ô©äPÿ>Z ‡ò’ü.Ӏè >h^0õ~‰­k“ž`wÊÒ°†pô¡Ã¡Ö«’®à²OÛRšÿTæÿqŽLdª‚Z¾LDG;X
socket: 592
0 0

WSASend

buffer: ÀºiXÊjcùÉgtn¯‘(?;ؤtÌàhÆLÚFßÁb¼Yþx¡ïræEë/]/R§ÍãʏŇvêÙÛϤÕñ†G”è qs«QÍ!àýŒ¬µ,ÌöS’âf6‘,«÷â}ú€Ú”`fûi#!?ź.”ë W72ÎoÇ ±¯m/¹uúhØ fŸ%ì]rºp²È쟇ñŸ±-ÿ¡¡¯Ì&ª—Rˆ~‘ˆË$Rò]Ñ(¥Â²ژxelxOþßñ
socket: 592
0 0