Summary | ZeroBOX

ibmSever.vbs

Category Machine Started Completed
FILE s1_win7_x6403_us Jan. 26, 2024, 12:08 p.m. Jan. 26, 2024, 12:12 p.m.
Size 160.4KB
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
MD5 bb9a31982bd53b29cc81e3027709727b
SHA256 d9c2a0240a8a4145728845cfeb9769f4906f1f825c1be919eee3303ba8d39404
CRC32 A675E416
ssdeep 3072:TjvNftRaeubmmwNmmyfC+smie4x49BTy3W4kUS3wuExYfyhRFcmJFIcNOb9j:Hlft4zWurrUSpE81
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 104.21.84.67
IP Address Status Action
104.21.84.67 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49162 -> 104.21.84.67:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.103:49162 -> 104.21.84.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49162
104.21.84.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee c2:b4:ac:5e:d6:d0:79:48:bd:61:49:ff:7a:f4:5f:ee:d4:45:1b:74

request GET http://paste.ee/d/Kiio7
request GET https://paste.ee/d/Kiio7
Avast Script:SNH-gen [Trj]
Kaspersky HEUR:Trojan.VBS.SAgent.gen
AVG Script:SNH-gen [Trj]
Time & API Arguments Status Return Repeated

WSASend

buffer: GET /d/Kiio7 HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5) Host: paste.ee
socket: 544
0 0

WSASend

buffer: kge³"4­GâÃkœÎ@ÿª®Õûàîó餮ÏpN8<° ¹/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 544
0 0

WSASend

buffer: FBA3ÀìEÿÐÖêQØÖÜvm¯³·z†™-"@–ÚpÌ#\í+/fø"žÑ- ™Ü¥áÀøžó"Ý,%Ç¢@$0ÚÞ¾:rèD˜¶«³+ŠdaŽÖLš¦ó4I™L_øê]WJħçšâÚ¤$éY"…
socket: 544
0 0

WSASend

buffer: °‡(·=<ÛöGaŸÿŸ€{ îÃ:㲛&›{ÿHèŒDßÆèåÒEJ3òÚ§½çô8éЌ« .Aþ&±aLõ!5ƒ"Dd²";÷“~ Wj÷ÍÐÚÞa.:ÒÂS–<Ô.š÷IÞðËU­¶v˜Ó¥æi~£b5 „ˆhŸê©©‡‰N•Ë+ÙEU`}ÕTúÞr@jm¨„.|Á ³ ªk2Ûy靜Ì
socket: 544
0 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
Time & API Arguments Status Return Repeated

WSASend

buffer: GET /d/Kiio7 HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5) Host: paste.ee
socket: 544
0 0

WSASend

buffer: kge³"4­GâÃkœÎ@ÿª®Õûàîó餮ÏpN8<° ¹/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 544
0 0

WSASend

buffer: FBA3ÀìEÿÐÖêQØÖÜvm¯³·z†™-"@–ÚpÌ#\í+/fø"žÑ- ™Ü¥áÀøžó"Ý,%Ç¢@$0ÚÞ¾:rèD˜¶«³+ŠdaŽÖLš¦ó4I™L_øê]WJħçšâÚ¤$éY"…
socket: 544
0 0

WSASend

buffer: °‡(·=<ÛöGaŸÿŸ€{ îÃ:㲛&›{ÿHèŒDßÆèåÒEJ3òÚ§½çô8éЌ« .Aþ&±aLõ!5ƒ"Dd²";÷“~ Wj÷ÍÐÚÞa.:ÒÂS–<Ô.š÷IÞðËU­¶v˜Ó¥æi~£b5 „ˆhŸê©©‡‰N•Ë+ÙEU`}ÕTúÞr@jm¨„.|Á ³ ªk2Ûy靜Ì
socket: 544
0 0