paladin316

Zips_1071d0f6bfdfde66479de4e62cdce6e9_php_2019-07-03_17_30.json

Jul 3rd, 2019
2,138
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.00 KB | None | 0 0
  1.  
  2. [*] MalFamily: ""
  3.  
  4. [*] MalScore: 0.0
  5.  
  6. [*] File Name: "Zips_1071d0f6bfdfde66479de4e62cdce6e9.php"
  7. [*] File Size: 72091
  8. [*] File Type: "Zip archive data, at least v2.0 to extract"
  9. [*] SHA256: "04099eacad34546cc7e162b66989b881bb4d07c3591d1d30899aa19fb86f96e1"
  10. [*] MD5: "1071d0f6bfdfde66479de4e62cdce6e9"
  11. [*] SHA1: "f9d16998ad2dc6741f23281be41da5a19e5c7e28"
  12. [*] SHA512: "50b4684b787ca567dc8aaa8e14a852bf4c84b1ace2d726bd0efc6c1646d07f7a1d0849b1e73ebb583bc2db2988c0c42d7ee40e1d460bb7ec2595df900b2f80f0"
  13. [*] CRC32: "2E85E736"
  14. [*] SSDEEP: "1536:jjzwA2rRAMlgwmH5FzQ8we/ZRfpKYE0M7AFD3Kl+M4a1ybP4HEv+6NnjW7WQK:jjM+HMejhKYELMKlISy/GEnjW7Wf"
  15.  
  16. [*] Process Execution: [
  17. "wscript.exe"
  18. ]
  19.  
  20. [*] Signatures Detected: []
  21.  
  22. [*] Started Service: []
  23.  
  24. [*] Executed Commands: []
  25.  
  26. [*] Mutexes: []
  27.  
  28. [*] Modified Files: []
  29.  
  30. [*] Deleted Files: []
  31.  
  32. [*] Modified Registry Keys: []
  33.  
  34. [*] Deleted Registry Keys: []
  35.  
  36. [*] DNS Communications: [
  37. {
  38. "type": "A",
  39. "request": "pouyas.com",
  40. "answers": []
  41. }
  42. ]
  43.  
  44. [*] Domains: [
  45. {
  46. "ip": "64.37.52.189",
  47. "domain": "pouyas.com"
  48. }
  49. ]
  50.  
  51. [*] Network Communication - ICMP: []
  52.  
  53. [*] Network Communication - HTTP: []
  54.  
  55. [*] Network Communication - SMTP: []
  56.  
  57. [*] Network Communication - Hosts: []
  58.  
  59. [*] Network Communication - IRC: []
  60.  
  61. [*] Static Analysis: {
  62. "office": {
  63. "Metadata": {
  64. "HasMacros": "No"
  65. }
  66. }
  67. }
  68.  
  69. [*] Resolved APIs: [
  70. "advapi32.dll.SaferIdentifyLevel",
  71. "advapi32.dll.SaferComputeTokenFromLevel",
  72. "advapi32.dll.SaferCloseLevel",
  73. "ole32.dll.CLSIDFromProgIDEx",
  74. "ole32.dll.CoGetClassObject",
  75. "wscript.exe.#1",
  76. "urlmon.dll.#326",
  77. "urlmon.dll.#327",
  78. "shell32.dll.#685",
  79. "shell32.dll.#688",
  80. "urlmon.dll.#395",
  81. "cryptsp.dll.CryptAcquireContextW",
  82. "cryptsp.dll.CryptGenRandom",
  83. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  84. "winhttp.dll.WinHttpCheckPlatform",
  85. "winhttp.dll.WinHttpOpen",
  86. "winhttp.dll.WinHttpConnect",
  87. "winhttp.dll.WinHttpOpenRequest",
  88. "winhttp.dll.WinHttpCloseHandle",
  89. "winhttp.dll.WinHttpSendRequest",
  90. "winhttp.dll.WinHttpReceiveResponse",
  91. "winhttp.dll.WinHttpAddRequestHeaders",
  92. "winhttp.dll.WinHttpQueryHeaders",
  93. "winhttp.dll.WinHttpReadData",
  94. "winhttp.dll.WinHttpWriteData",
  95. "winhttp.dll.WinHttpQueryDataAvailable",
  96. "winhttp.dll.WinHttpQueryOption",
  97. "winhttp.dll.WinHttpSetOption",
  98. "winhttp.dll.WinHttpSetTimeouts",
  99. "winhttp.dll.WinHttpCrackUrl",
  100. "winhttp.dll.WinHttpCreateUrl",
  101. "oleaut32.dll.#8",
  102. "oleaut32.dll.#12",
  103. "shlwapi.dll.StrRChrA",
  104. "shlwapi.dll.StrCmpNW",
  105. "oleaut32.dll.#4",
  106. "oleaut32.dll.#6",
  107. "kernel32.dll.RegQueryValueExW",
  108. "oleaut32.dll.#2",
  109. "kernel32.dll.RegCloseKey",
  110. "oleaut32.dll.#9",
  111. "ws2_32.dll.GetAddrInfoW",
  112. "oleaut32.dll.#202",
  113. "oleaut32.dll.#201",
  114. "rpcrt4.dll.RpcBindingFree",
  115. "oleaut32.dll.#500",
  116. "cryptsp.dll.CryptReleaseContext"
  117. ]
  118.  
  119. [*] Static Analysis: {
  120. "office": {
  121. "Metadata": {
  122. "HasMacros": "No"
  123. }
  124. }
  125. }
Advertisement
Add Comment
Please, Sign In to add comment