Summary | ZeroBOX

afriq.js

ActiveXObject
Category Machine Started Completed
FILE s1_win7_x6401 Nov. 28, 2023, 10:02 a.m. Nov. 28, 2023, 10:04 a.m.
Size 37.7KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF line terminators
MD5 0cd971ef91e57c0c285da2fe74c2d6ec
SHA256 f4dc8b79421aa0047b5475ff67f1e357f329bc19d9165d23d3aee4a49e96c87f
CRC32 EFE752C0
ssdeep 768:WRKaOa5av1L5CTW9CCzCt150LVwawtHVjR26TPMmrnIhOS2FGYYq0:WRKaOa5aviTWcrt0VwawFxR26TPPrnI7
Yara
  • Javascript_ActiveXObject - Use ActiveXObject JavaScript

Name Response Post-Analysis Lookup
paste.ee 104.21.84.67
IP Address Status Action
104.21.84.67 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49161 -> 104.21.84.67:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.101:49161 -> 104.21.84.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49161
104.21.84.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee 75:09:97:90:38:ad:dd:cc:0d:1b:d8:8b:02:ab:5d:a9:3b:7a:1f:1d

request GET https://paste.ee/d/ly4Cq
Symantec ISB.Downloader!gen40
Kaspersky HEUR:Trojan.Script.SAgent.gen
NANO-Antivirus Trojan.Script.Heuristic-js.iacgm
ZoneAlarm HEUR:Trojan.Script.SAgent.gen
Rising Trojan.Undefined!8.1327C (TOPIS:E0:27pLkxQ5kpB)
Time & API Arguments Status Return Repeated

WSASend

buffer: kgee< ¥Ë¡š®òHОAú ٍ¾YBBáãm”ƒ/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 600
0 0

WSASend

buffer: FBA]Yý;ÍöxÂÒ¥ÙDÓݬáèü/±RôOök”X® XŽ°¦ô©äPÿ>Z ‡ò’ü.Ӏè >h^0ÎcÆ·k^²§ÀCòK±ˆÊÅj5­¼PÔGM«]˜sÿ¦´4¥âjr¦¸ï±°
socket: 600
0 0

WSASend

buffer: À¦Cn¯Ï’…î'ýg9á*)O\vÎ$ph‹Ùèh’ ž÷ͺŠjŒ–;yq]̏¯ùGd$ϓÅC~¡݉WPJ1&ÑkÉ œ¬(F‰Â;Qãjÿœàcøàj¼wÛTzä£òU;;—n¿TÎfÝ2É éQw6q³Ø‘~?䀳ÞÔħb<+Çá±Ö¦¸Þý儩›@¿L#‚ä7ñã™P»ƒP2Çj ^­ÑœÿjÖf'«¾iNžŽÿ¥^
socket: 600
0 0
Time & API Arguments Status Return Repeated

WSASend

buffer: kgee< ¥Ë¡š®òHОAú ٍ¾YBBáãm”ƒ/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 600
0 0

WSASend

buffer: FBA]Yý;ÍöxÂÒ¥ÙDÓݬáèü/±RôOök”X® XŽ°¦ô©äPÿ>Z ‡ò’ü.Ӏè >h^0ÎcÆ·k^²§ÀCòK±ˆÊÅj5­¼PÔGM«]˜sÿ¦´4¥âjr¦¸ï±°
socket: 600
0 0

WSASend

buffer: À¦Cn¯Ï’…î'ýg9á*)O\vÎ$ph‹Ùèh’ ž÷ͺŠjŒ–;yq]̏¯ùGd$ϓÅC~¡݉WPJ1&ÑkÉ œ¬(F‰Â;Qãjÿœàcøàj¼wÛTzä£òU;;—n¿TÎfÝ2É éQw6q³Ø‘~?䀳ÞÔħb<+Çá±Ö¦¸Þý儩›@¿L#‚ä7ñã™P»ƒP2Çj ^­ÑœÿjÖf'«¾iNžŽÿ¥^
socket: 600
0 0