Summary | ZeroBOX

createdloverkissed.vbs

Category Machine Started Completed
FILE s1_win7_x6401 March 31, 2024, 11:23 a.m. March 31, 2024, 11:28 a.m.
Size 292.7KB
Type Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
MD5 7cfb0e8a02678ccbd305bea1d747a88e
SHA256 c4e00149e62cc05e31e3aeeb5e26edd925a68a1c43dfeaca8441bdf54e8e9494
CRC32 91F85F37
ssdeep 3072:XYFEhNe4VTdRnTT8w4TWXBIgJdpe+og0S7A:XYFYM
Yara None matched

Name Response Post-Analysis Lookup
paste.ee 104.21.84.67
IP Address Status Action
164.124.101.2 Active Moloch
172.67.187.200 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49161 -> 172.67.187.200:443 2034978 ET POLICY Pastebin-style Service (paste .ee) in TLS SNI Potential Corporate Privacy Violation
TCP 192.168.56.101:49161 -> 172.67.187.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49161
172.67.187.200:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=paste.ee 7d:42:2d:94:fb:28:2f:5d:1b:d1:1a:55:db:1a:61:da:a2:eb:d4:ff

request GET https://paste.ee/d/bWBGI
Skyhigh BehavesLike.VBS.Dropper.cp
Symantec ISB.Downloader!gen40
ESET-NOD32 VBS/TrojanDownloader.Agent.AABS
Avast Script:SNH-gen [Drp]
Kaspersky HEUR:Trojan.VBS.SAgent.gen
DrWeb VBS.DownLoader.3091
AVG Script:SNH-gen [Drp]
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: https://paste.ee/d/bWBGI
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 12582912
http_method: GET
referer:
path: /d/bWBGI
1 13369356 0
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: https://paste.ee/d/bWBGI
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 12582912
http_method: GET
referer:
path: /d/bWBGI
1 13369356 0

send

buffer: !
socket: 868
sent: 1
1 1 0

send

buffer: kgfÉ m¸Ù’õçªþe|¹8¤{K~—DYl©±qM€Ê/5 ÀÀÀ À 28&ÿ paste.ee  
socket: 988
sent: 112
1 112 0

send

buffer: !
socket: 868
sent: 1
1 1 0

send

buffer: FBAt"¡(YÙغ+ðå×â¼Ióè{G&Ê Çs¼ouÊöGà Ç_±Tkfa¡’_’å’vY<âã 40ÚdD5 #!]¾×~1±æE$¯ÙŠj=gWW楖—áVÙ X)E<ȸ
socket: 988
sent: 134
1 134 0

send

buffer: !
socket: 868
sent: 1
1 1 0

send

buffer: @ÞøZ5}²j¤‘–Ç•Ð4xßFÞ PϜ¤¸%›¢ÔŒz8øÐÃŒ&öQÚ÷[Kžùr­þ…·åI]Ly7»‹ ë}FæéÎ{©M§sáøãªôˆQ[ȑb‚µÛlf¤F¿hâ.g˧Êû²íÜ´›úyˆ¡K?á”ïO¼[Iš fa-®v̐t IÉZ+^¬f÷0À5YÈ£»÷¬Ÿ¯¯ƒSºiÀQñ%ÑÕ«…NÀ”¹âÀÑãoʼ—|Å¶Ñ‘Nb|öÕÊ!¦Ñ”%a8?2ێ–›£Ò|qæI1=8=u=ð¿–èSJ×.K®T֛<õ眏,̯"Ê™ž3'~eïFö{g ˜Q<·Š'ÑÔFñ25Vq‚Ò b¹WuIÅÜԐšC÷ïÞz±tkžn®@!H
socket: 988
sent: 325
1 325 0

send

buffer: !
socket: 868
sent: 1
1 1 0