Summary | ZeroBOX

wezg.vbs

Category Machine Started Completed
FILE s1_win7_x6403_us Nov. 11, 2023, 4:10 p.m. Nov. 11, 2023, 4:36 p.m.
Size 173.4KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 aab95e79e0cb76d5b9740c28b4b503ed
SHA256 191ab4cd8bd2b8e1ebf53d06895f8dd01f4225c7438ba62f69e7c58ee3bca2df
CRC32 E697A87D
ssdeep 768:5gm4STQ8638ssssslsssssrsssssBsssss+ssssslsssssXsssssjsssssmssssD:5gm4STQ863T0NRdSKhnOG
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 172.67.187.200
IP Address Status Action
164.124.101.2 Active Moloch
172.67.187.200 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49162 -> 172.67.187.200:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.103:49162 -> 172.67.187.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49162
172.67.187.200:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee 75:09:97:90:38:ad:dd:cc:0d:1b:d8:8b:02:ab:5d:a9:3b:7a:1f:1d

request GET https://paste.ee/d/t2Iek
Time & API Arguments Status Return Repeated

WSASend

buffer: kgeO(ÑYJ¹ê°,hÚÿF;¾lœR=Ðøž%†3uÙ¢/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 584
0 0

WSASend

buffer: FBA3(Iƒwk4yUgÕ º(±YÜ»# è­ÏTHvºU¦v–yGgöò\š£\FƒÏø»ž%LôÿÜ¡ 0`nÍËÆnxÑþˆ|Ûu}¸ó± ö2"ä2E¬ÆÆ\=›yÒväÔ+ ÿfÀŒ
socket: 584
0 0

WSASend

buffer: ÀE#F‹··D"ÐÐÈÂCzÈli€Oô‰"Ør­¯H:ÓÈؽ™–JÙA4‡ÞŸ_Ýg/ªNÄ²“ £_õ†Ö§@[:'™7ÙÞ%â½ÐStóښ±ÏAñ¹âÁ¯ÝìY¤6§QwxãQ·)/è뚎@½<ÜàsÿU¬ålw#¼Ùý$Ĕoø&±qݶª•§ì Z{˜œ§Àè7nsΪEÿ°ßq.z{ÐàùÇ¥õsŸ­µX¸|ô®ËgÉx
socket: 584
0 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
Time & API Arguments Status Return Repeated

WSASend

buffer: kgeO(ÑYJ¹ê°,hÚÿF;¾lœR=Ðøž%†3uÙ¢/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 584
0 0

WSASend

buffer: FBA3(Iƒwk4yUgÕ º(±YÜ»# è­ÏTHvºU¦v–yGgöò\š£\FƒÏø»ž%LôÿÜ¡ 0`nÍËÆnxÑþˆ|Ûu}¸ó± ö2"ä2E¬ÆÆ\=›yÒväÔ+ ÿfÀŒ
socket: 584
0 0

WSASend

buffer: ÀE#F‹··D"ÐÐÈÂCzÈli€Oô‰"Ør­¯H:ÓÈؽ™–JÙA4‡ÞŸ_Ýg/ªNÄ²“ £_õ†Ö§@[:'™7ÙÞ%â½ÐStóښ±ÏAñ¹âÁ¯ÝìY¤6§QwxãQ·)/è뚎@½<ÜàsÿU¬ålw#¼Ùý$Ĕoø&±qݶª•§ì Z{˜œ§Àè7nsΪEÿ°ßq.z{ÐàùÇ¥õsŸ­µX¸|ô®ËgÉx
socket: 584
0 0