paladin316

VBS_f4dfbded8cd4d2a9b6e8b7555da1fb14_php_2019-07-03_21_30.json

Jul 3rd, 2019
2,118
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.00 KB | None | 0 0
  1.  
  2. [*] MalFamily: ""
  3.  
  4. [*] MalScore: 0.0
  5.  
  6. [*] File Name: "VBS_f4dfbded8cd4d2a9b6e8b7555da1fb14.php"
  7. [*] File Size: 90015
  8. [*] File Type: "Zip archive data, at least v2.0 to extract"
  9. [*] SHA256: "7dca6b9cd2ebb88985fd10fe3963eb343da9590cdb17c31307b7ba2905e6c17e"
  10. [*] MD5: "f4dfbded8cd4d2a9b6e8b7555da1fb14"
  11. [*] SHA1: "f556d48ef499796703a2b454cdfccba968c777c2"
  12. [*] SHA512: "00c14d7c5c4e03accf7d80285eee4d8e93b07def31727309b15ea90cc91741242f71395a1729399faf8d8760f61cdc948700492651ab751b1414ab106987396e"
  13. [*] CRC32: "922D3C41"
  14. [*] SSDEEP: "1536:R95Pd0IyTdK7DpjgQ1wkGNRhlTgHPtuDZospNlf95c0PvZG0VWh0rAlVJyQgYQw3:/AEcQ1IbhyvtO5T1K05jwnHv3"
  15.  
  16. [*] Process Execution: [
  17. "wscript.exe"
  18. ]
  19.  
  20. [*] Signatures Detected: []
  21.  
  22. [*] Started Service: []
  23.  
  24. [*] Executed Commands: []
  25.  
  26. [*] Mutexes: []
  27.  
  28. [*] Modified Files: []
  29.  
  30. [*] Deleted Files: []
  31.  
  32. [*] Modified Registry Keys: []
  33.  
  34. [*] Deleted Registry Keys: []
  35.  
  36. [*] DNS Communications: [
  37. {
  38. "type": "A",
  39. "request": "pouyas.com",
  40. "answers": []
  41. }
  42. ]
  43.  
  44. [*] Domains: [
  45. {
  46. "ip": "64.37.52.189",
  47. "domain": "pouyas.com"
  48. }
  49. ]
  50.  
  51. [*] Network Communication - ICMP: []
  52.  
  53. [*] Network Communication - HTTP: []
  54.  
  55. [*] Network Communication - SMTP: []
  56.  
  57. [*] Network Communication - Hosts: []
  58.  
  59. [*] Network Communication - IRC: []
  60.  
  61. [*] Static Analysis: {
  62. "office": {
  63. "Metadata": {
  64. "HasMacros": "No"
  65. }
  66. }
  67. }
  68.  
  69. [*] Resolved APIs: [
  70. "advapi32.dll.SaferIdentifyLevel",
  71. "advapi32.dll.SaferComputeTokenFromLevel",
  72. "advapi32.dll.SaferCloseLevel",
  73. "ole32.dll.CLSIDFromProgIDEx",
  74. "ole32.dll.CoGetClassObject",
  75. "wscript.exe.#1",
  76. "urlmon.dll.#326",
  77. "urlmon.dll.#327",
  78. "shell32.dll.#685",
  79. "shell32.dll.#688",
  80. "urlmon.dll.#395",
  81. "cryptsp.dll.CryptAcquireContextW",
  82. "cryptsp.dll.CryptGenRandom",
  83. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  84. "winhttp.dll.WinHttpCheckPlatform",
  85. "winhttp.dll.WinHttpOpen",
  86. "winhttp.dll.WinHttpConnect",
  87. "winhttp.dll.WinHttpOpenRequest",
  88. "winhttp.dll.WinHttpCloseHandle",
  89. "winhttp.dll.WinHttpSendRequest",
  90. "winhttp.dll.WinHttpReceiveResponse",
  91. "winhttp.dll.WinHttpAddRequestHeaders",
  92. "winhttp.dll.WinHttpQueryHeaders",
  93. "winhttp.dll.WinHttpReadData",
  94. "winhttp.dll.WinHttpWriteData",
  95. "winhttp.dll.WinHttpQueryDataAvailable",
  96. "winhttp.dll.WinHttpQueryOption",
  97. "winhttp.dll.WinHttpSetOption",
  98. "winhttp.dll.WinHttpSetTimeouts",
  99. "winhttp.dll.WinHttpCrackUrl",
  100. "winhttp.dll.WinHttpCreateUrl",
  101. "oleaut32.dll.#8",
  102. "oleaut32.dll.#12",
  103. "shlwapi.dll.StrRChrA",
  104. "shlwapi.dll.StrCmpNW",
  105. "oleaut32.dll.#4",
  106. "oleaut32.dll.#6",
  107. "kernel32.dll.RegQueryValueExW",
  108. "oleaut32.dll.#2",
  109. "kernel32.dll.RegCloseKey",
  110. "oleaut32.dll.#9",
  111. "ws2_32.dll.GetAddrInfoW",
  112. "oleaut32.dll.#202",
  113. "oleaut32.dll.#201",
  114. "rpcrt4.dll.RpcBindingFree",
  115. "oleaut32.dll.#500",
  116. "cryptsp.dll.CryptReleaseContext"
  117. ]
  118.  
  119. [*] Static Analysis: {
  120. "office": {
  121. "Metadata": {
  122. "HasMacros": "No"
  123. }
  124. }
  125. }
Advertisement
Add Comment
Please, Sign In to add comment