Summary | ZeroBOX

File_Vbs.vbs

Category Machine Started Completed
FILE s1_win7_x6403_us Nov. 10, 2023, 9:23 a.m. Nov. 10, 2023, 9:27 a.m.
Size 186.0KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 739bf7015a7bb68f0c0452e64497be77
SHA256 f9f3d93122f44a521e47daef1ac9126b45f0202c6a988822369ffe4b971592ce
CRC32 534671B4
ssdeep 3072:pQlZ3mRQteeeeeYeeeeeVeeeeeMeeeeeLeeeeeYeeeeeleeeeeheeeeeUeeeeeoI:n
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 104.21.84.67
IP Address Status Action
164.124.101.2 Active Moloch
172.67.187.200 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49161 -> 172.67.187.200:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.103:49161 -> 172.67.187.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49161
172.67.187.200:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee 75:09:97:90:38:ad:dd:cc:0d:1b:d8:8b:02:ab:5d:a9:3b:7a:1f:1d

request GET https://paste.ee/d/qZWyg
Avast Script:SNH-gen [Trj]
Kaspersky HEUR:Trojan.VBS.SAgent.gen
Kingsoft Win32.Troj.Undef.a
AVG Script:SNH-gen [Trj]
Time & API Arguments Status Return Repeated

WSASend

buffer: kgeMx)íy9Ä$ñ©‚«á‘Å+á¨x^­‰·û#‡² /5 ÀÀÀ À 28&ÿ paste.ee  
socket: 592
0 0

WSASend

buffer: FBA’xH•Æn5l¥š£×JL‹ý[±¨[Sä8‹FFÈPFxA[~ä¯}]ØW4š¤âx¬ìhýÊEFÒ0Á“‰¿aÑÍMÅqL4–Í® "_‚O¬Õўpƒ@Ì]Ze ðUª‘Z]ÄbÙ¤ÂÕ
socket: 592
0 0

WSASend

buffer: À)+J)_¤ËIÙ®ñ€–Û˜’oîÛі¶……ÜÝQ«<ÖÐöÜ>p;HMÓÖ¾Ö:5©€"£1—UÔ¦dÐ÷|&Nšd—)¢îR6ñ’HŒ•“E*IFxù+E’b?ŒDº·øs „õœyèÏüú™¤Ç)Î"ÞcŒ°±tÖà^Íø´¡ržš#¿ ãKËé@«ÝÁŒüŠý†²©öJ‹]Bƒ‚¥eØ<mîSÚ¤ÙÍMBK­°×­è̊Ԯ}ðC
socket: 592
0 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
Time & API Arguments Status Return Repeated

WSASend

buffer: kgeMx)íy9Ä$ñ©‚«á‘Å+á¨x^­‰·û#‡² /5 ÀÀÀ À 28&ÿ paste.ee  
socket: 592
0 0

WSASend

buffer: FBA’xH•Æn5l¥š£×JL‹ý[±¨[Sä8‹FFÈPFxA[~ä¯}]ØW4š¤âx¬ìhýÊEFÒ0Á“‰¿aÑÍMÅqL4–Í® "_‚O¬Õўpƒ@Ì]Ze ðUª‘Z]ÄbÙ¤ÂÕ
socket: 592
0 0

WSASend

buffer: À)+J)_¤ËIÙ®ñ€–Û˜’oîÛі¶……ÜÝQ«<ÖÐöÜ>p;HMÓÖ¾Ö:5©€"£1—UÔ¦dÐ÷|&Nšd—)¢îR6ñ’HŒ•“E*IFxù+E’b?ŒDº·øs „õœyèÏüú™¤Ç)Î"ÞcŒ°±tÖà^Íø´¡ržš#¿ ãKËé@«ÝÁŒüŠý†²©öJ‹]Bƒ‚¥eØ<mîSÚ¤ÙÍMBK­°×­è̊Ԯ}ðC
socket: 592
0 0