paladin316

ShareFile_vbs_2019-06-27_21_30.json

Jun 27th, 2019
2,167
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.11 KB | None | 0 0
  1.  
  2. [*] MalFamily: "Sagent"
  3.  
  4. [*] MalScore: 0.8
  5.  
  6. [*] File Name: "ShareFile.vbs"
  7. [*] File Size: 135760
  8. [*] File Type: "ASCII text, with very long lines"
  9. [*] SHA256: "7e525e5cf3048c4ac984de2e69de583748abb7f809e4c33afea4d49bb39d2619"
  10. [*] MD5: "d4cf32105257aabdd26cf6e5e81400f9"
  11. [*] SHA1: "b6ecb63ddfc18c54c6030abc2d652000bdee4415"
  12. [*] SHA512: "8930c0dbaa995d140a53c4e72543a3e7a73c9ba400a77799a482b0df94f70dbcadf73866d7df85a3dfc302c296881cd9f96aef932e8863b2e3a58a0c6a95a3b0"
  13. [*] CRC32: "444BF80A"
  14. [*] SSDEEP: "1536:yGDWFNaXTNF1YAUYNrIebq1aQZLNMQypaf:y0NF1wYNrBbqBZLvR"
  15.  
  16. [*] Process Execution: [
  17. "wscript.exe"
  18. ]
  19.  
  20. [*] Signatures Detected: [
  21. {
  22. "Description": "Attempts to connect to a dead IP:Port (3 unique times)",
  23. "Details": [
  24. {
  25. "IP": "8.253.134.249:80"
  26. },
  27. {
  28. "IP": "216.245.192.219:443"
  29. },
  30. {
  31. "IP": "192.35.177.64:80"
  32. }
  33. ]
  34. },
  35. {
  36. "Description": "File has been identified by 4 Antiviruses on VirusTotal as malicious",
  37. "Details": [
  38. {
  39. "Kaspersky": "HEUR:Trojan.VBS.SAgent.gen"
  40. },
  41. {
  42. "DrWeb": "Trojan.DownLoader29.2186"
  43. },
  44. {
  45. "ZoneAlarm": "HEUR:Trojan.VBS.SAgent.gen"
  46. },
  47. {
  48. "Qihoo-360": "virus.vbs.crypt.c"
  49. }
  50. ]
  51. },
  52. {
  53. "Description": "Performs some HTTP requests",
  54. "Details": [
  55. {
  56. "url": "http://apps.identrust.com/roots/dstrootcax3.p7c"
  57. },
  58. {
  59. "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
  60. }
  61. ]
  62. }
  63. ]
  64.  
  65. [*] Started Service: []
  66.  
  67. [*] Executed Commands: []
  68.  
  69. [*] Mutexes: []
  70.  
  71. [*] Modified Files: [
  72. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  73. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  74. "C:\\Users\\user\\AppData\\Local\\Temp\\CabE133.tmp",
  75. "C:\\Users\\user\\AppData\\Local\\Temp\\TarE134.tmp",
  76. "C:\\Users\\user\\AppData\\Local\\Temp\\CabB04.tmp",
  77. "C:\\Users\\user\\AppData\\Local\\Temp\\TarB05.tmp",
  78. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
  79. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
  80. "C:\\Users\\user\\AppData\\Local\\Temp\\CabDE5.tmp",
  81. "C:\\Users\\user\\AppData\\Local\\Temp\\TarDE6.tmp",
  82. "C:\\Users\\user\\AppData\\Local\\Temp\\TableOfColors.exe"
  83. ]
  84.  
  85. [*] Deleted Files: [
  86. "C:\\Users\\user\\AppData\\Local\\Temp\\CabE133.tmp",
  87. "C:\\Users\\user\\AppData\\Local\\Temp\\TarE134.tmp",
  88. "C:\\Users\\user\\AppData\\Local\\Temp\\CabB04.tmp",
  89. "C:\\Users\\user\\AppData\\Local\\Temp\\TarB05.tmp",
  90. "C:\\Users\\user\\AppData\\Local\\Temp\\CabDE5.tmp",
  91. "C:\\Users\\user\\AppData\\Local\\Temp\\TarDE6.tmp"
  92. ]
  93.  
  94. [*] Modified Registry Keys: [
  95. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList"
  96. ]
  97.  
  98. [*] Deleted Registry Keys: []
  99.  
  100. [*] DNS Communications: [
  101. {
  102. "type": "A",
  103. "request": "tonyschopshop.com",
  104. "answers": [
  105. {
  106. "data": "216.245.192.219",
  107. "type": "A"
  108. }
  109. ]
  110. },
  111. {
  112. "type": "A",
  113. "request": "apps.identrust.com",
  114. "answers": [
  115. {
  116. "data": "192.35.177.64",
  117. "type": "A"
  118. },
  119. {
  120. "data": "apps.digsigtrust.com",
  121. "type": "CNAME"
  122. }
  123. ]
  124. }
  125. ]
  126.  
  127. [*] Domains: [
  128. {
  129. "ip": "192.35.177.64",
  130. "domain": "apps.identrust.com"
  131. },
  132. {
  133. "ip": "216.245.192.219",
  134. "domain": "tonyschopshop.com"
  135. }
  136. ]
  137.  
  138. [*] Network Communication - ICMP: []
  139.  
  140. [*] Network Communication - HTTP: [
  141. {
  142. "count": 1,
  143. "body": "",
  144. "uri": "http://apps.identrust.com/roots/dstrootcax3.p7c",
  145. "user-agent": "Microsoft-CryptoAPI/6.1",
  146. "method": "GET",
  147. "host": "apps.identrust.com",
  148. "version": "1.1",
  149. "path": "/roots/dstrootcax3.p7c",
  150. "data": "GET /roots/dstrootcax3.p7c HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: apps.identrust.com\r\n\r\n",
  151. "port": 80
  152. },
  153. {
  154. "count": 1,
  155. "body": "",
  156. "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  157. "user-agent": "Microsoft-CryptoAPI/6.1",
  158. "method": "GET",
  159. "host": "www.download.windowsupdate.com",
  160. "version": "1.1",
  161. "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  162. "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86434\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Feb 2019 16:53:13 GMT\r\nIf-None-Match: \"80e22c19cfcad41:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
  163. "port": 80
  164. }
  165. ]
  166.  
  167. [*] Network Communication - SMTP: []
  168.  
  169. [*] Network Communication - Hosts: []
  170.  
  171. [*] Network Communication - IRC: []
  172.  
  173. [*] Static Analysis: {}
  174.  
  175. [*] Resolved APIs: [
  176. "advapi32.dll.SaferIdentifyLevel",
  177. "advapi32.dll.SaferComputeTokenFromLevel",
  178. "advapi32.dll.SaferCloseLevel",
  179. "kernel32.dll.NlsGetCacheUpdateCount",
  180. "ole32.dll.CLSIDFromProgIDEx",
  181. "ole32.dll.CoGetClassObject",
  182. "cryptsp.dll.CryptAcquireContextW",
  183. "cryptsp.dll.CryptGenRandom",
  184. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  185. "wscript.exe.#1",
  186. "sxs.dll.SxsOleAut32RedirectTypeLibrary",
  187. "advapi32.dll.RegOpenKeyW",
  188. "advapi32.dll.RegQueryValueW",
  189. "winhttp.dll.WinHttpCrackUrl",
  190. "shlwapi.dll.StrCmpNW",
  191. "winhttp.dll.WinHttpCreateUrl",
  192. "oleaut32.dll.#8",
  193. "oleaut32.dll.#12",
  194. "shlwapi.dll.StrRChrA",
  195. "oleaut32.dll.#4",
  196. "oleaut32.dll.#6",
  197. "kernel32.dll.RegQueryValueExW",
  198. "oleaut32.dll.#2",
  199. "kernel32.dll.RegCloseKey",
  200. "oleaut32.dll.#9",
  201. "ws2_32.dll.GetAddrInfoW",
  202. "ws2_32.dll.WSASocketW",
  203. "ws2_32.dll.#2",
  204. "ws2_32.dll.#21",
  205. "ws2_32.dll.#9",
  206. "ws2_32.dll.WSAIoctl",
  207. "ws2_32.dll.FreeAddrInfoW",
  208. "ws2_32.dll.#6",
  209. "ws2_32.dll.#5",
  210. "schannel.dll.SpUserModeInitialize",
  211. "advapi32.dll.RegCreateKeyExW",
  212. "advapi32.dll.RegQueryValueExW",
  213. "advapi32.dll.RegCloseKey",
  214. "ws2_32.dll.WSASend",
  215. "ws2_32.dll.WSARecv",
  216. "secur32.dll.FreeContextBuffer",
  217. "ncrypt.dll.SslOpenProvider",
  218. "ncrypt.dll.GetSChannelInterface",
  219. "bcryptprimitives.dll.GetHashInterface",
  220. "ncrypt.dll.SslIncrementProviderReferenceCount",
  221. "ncrypt.dll.SslImportKey",
  222. "bcryptprimitives.dll.GetCipherInterface",
  223. "ncrypt.dll.SslLookupCipherSuiteInfo",
  224. "user32.dll.LoadStringW",
  225. "ncrypt.dll.BCryptOpenAlgorithmProvider",
  226. "ncrypt.dll.BCryptGetProperty",
  227. "ncrypt.dll.BCryptCreateHash",
  228. "ncrypt.dll.BCryptHashData",
  229. "ncrypt.dll.BCryptFinishHash",
  230. "ncrypt.dll.BCryptDestroyHash",
  231. "crypt32.dll.CertGetCertificateChain",
  232. "userenv.dll.GetUserProfileDirectoryW",
  233. "sechost.dll.ConvertSidToStringSidW",
  234. "sechost.dll.ConvertStringSidToSidW",
  235. "userenv.dll.RegisterGPNotification",
  236. "gpapi.dll.RegisterGPNotificationInternal",
  237. "sechost.dll.OpenSCManagerW",
  238. "sechost.dll.OpenServiceW",
  239. "sechost.dll.CloseServiceHandle",
  240. "sechost.dll.QueryServiceConfigW",
  241. "cryptnet.dll.CryptGetObjectUrl",
  242. "cryptnet.dll.CryptRetrieveObjectByUrlW",
  243. "cryptnet.dll.I_CryptNetGetConnectivity",
  244. "sensapi.dll.IsNetworkAlive",
  245. "rpcrt4.dll.RpcBindingFromStringBindingW",
  246. "rpcrt4.dll.RpcBindingSetAuthInfoExW",
  247. "rpcrt4.dll.NdrClientCall2",
  248. "winhttp.dll.WinHttpOpen",
  249. "winhttp.dll.WinHttpSetTimeouts",
  250. "winhttp.dll.WinHttpSetOption",
  251. "winhttp.dll.WinHttpConnect",
  252. "winhttp.dll.WinHttpOpenRequest",
  253. "winhttp.dll.WinHttpSetStatusCallback",
  254. "winhttp.dll.WinHttpGetDefaultProxyConfiguration",
  255. "winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser",
  256. "winhttp.dll.WinHttpSendRequest",
  257. "winhttp.dll.WinHttpReceiveResponse",
  258. "winhttp.dll.WinHttpQueryHeaders",
  259. "shlwapi.dll.StrStrIW",
  260. "winhttp.dll.WinHttpQueryDataAvailable",
  261. "winhttp.dll.WinHttpReadData",
  262. "cryptsp.dll.CryptAcquireContextA",
  263. "winhttp.dll.WinHttpCloseHandle",
  264. "cryptsp.dll.CryptCreateHash",
  265. "cryptsp.dll.CryptHashData",
  266. "cryptsp.dll.CryptVerifySignatureA",
  267. "cryptsp.dll.CryptDestroyKey",
  268. "cryptsp.dll.CryptDestroyHash",
  269. "setupapi.dll.SetupIterateCabinetW",
  270. "kernel32.dll.RegOpenKeyExW",
  271. "cabinet.dll.#20",
  272. "cabinet.dll.#22",
  273. "devrtl.dll.DevRtlGetThreadLogToken",
  274. "cabinet.dll.#23",
  275. "cryptsp.dll.CryptSetHashParam",
  276. "sechost.dll.QueryServiceConfigA",
  277. "sechost.dll.QueryServiceStatus",
  278. "rpcrt4.dll.RpcStringBindingComposeA",
  279. "rpcrt4.dll.RpcBindingFromStringBindingA",
  280. "rpcrt4.dll.RpcEpResolveBinding",
  281. "sechost.dll.LookupAccountSidLocalW",
  282. "rpcrt4.dll.RpcStringFreeA",
  283. "rpcrt4.dll.RpcBindingFree",
  284. "winhttp.dll.WinHttpTimeFromSystemTime",
  285. "cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo",
  286. "cryptnet.dll.I_CryptNetSetUrlCachePreFetchInfo",
  287. "bcryptprimitives.dll.GetAsymmetricEncryptionInterface",
  288. "ncrypt.dll.BCryptImportKeyPair",
  289. "ncrypt.dll.BCryptVerifySignature",
  290. "ncrypt.dll.BCryptDestroyKey",
  291. "crypt32.dll.CertVerifyCertificateChainPolicy",
  292. "crypt32.dll.CertFreeCertificateChain",
  293. "crypt32.dll.CertDuplicateCertificateContext",
  294. "ncrypt.dll.SslEncryptPacket",
  295. "ncrypt.dll.SslDecryptPacket",
  296. "ole32.dll.CreateStreamOnHGlobal",
  297. "oleaut32.dll.#411",
  298. "oleaut32.dll.#23",
  299. "oleaut32.dll.#24",
  300. "ole32.dll.GetHGlobalFromStream",
  301. "sspicli.dll.GetUserNameExW",
  302. "xmllite.dll.CreateXmlWriter",
  303. "xmllite.dll.CreateXmlWriterOutputWithEncodingName",
  304. "crypt32.dll.CertFreeCertificateContext",
  305. "oleaut32.dll.#500",
  306. "ncrypt.dll.SslFreeObject",
  307. "cryptsp.dll.CryptReleaseContext"
  308. ]
  309.  
  310. [*] Static Analysis: {}
Advertisement
Add Comment
Please, Sign In to add comment