paladin316

IMAGE-16867_14973-705081660-T05-01569125_vbs_2019-07-03_20_30.json

Jul 3rd, 2019
2,166
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.11 KB | None | 0 0
  1.  
  2. [*] MalFamily: "Malscript"
  3.  
  4. [*] MalScore: 1.5
  5.  
  6. [*] File Name: "IMAGE-16867_14973-705081660-T05-01569125.vbs"
  7. [*] File Size: 135999
  8. [*] File Type: "ASCII text, with very long lines"
  9. [*] SHA256: "b8c2be5fb530d1d029fb8cd0da743517e4f3fa1b270e27d29494b9ab1770ee9f"
  10. [*] MD5: "2d3e368930fe11bed5e8d74230f64b3c"
  11. [*] SHA1: "8eeed09c3da633c75949ad0db659d6eef143a3db"
  12. [*] SHA512: "9e0f76e6f51657f06184f9e7cb55702200fdd65d937825a08206531d7b0e7f40f7b3af274e8fbc4c0826e3f7186674be490d962c3bbd49530bd6101c72bc6019"
  13. [*] CRC32: "D331A27E"
  14. [*] SSDEEP: "1536:AN003xMR8GSoSsj85euQbYHQtIcN3EZkYNQNbZyUaI8r4Z:mRxMR8OjKeuPcN3EOYNQOUlh"
  15.  
  16. [*] Process Execution: [
  17. "wscript.exe"
  18. ]
  19.  
  20. [*] Signatures Detected: [
  21. {
  22. "Description": "File has been identified by 6 Antiviruses on VirusTotal as malicious",
  23. "Details": [
  24. {
  25. "ESET-NOD32": "VBS/TrojanDownloader.Agent.ROR"
  26. },
  27. {
  28. "DrWeb": "Trojan.DownLoader29.17766"
  29. },
  30. {
  31. "Microsoft": "Trojan:VBS/Malscript"
  32. },
  33. {
  34. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  35. },
  36. {
  37. "Ikarus": "Win32.Outbreak"
  38. },
  39. {
  40. "Qihoo-360": "virus.vbs.crypt.c"
  41. }
  42. ]
  43. }
  44. ]
  45.  
  46. [*] Started Service: []
  47.  
  48. [*] Executed Commands: []
  49.  
  50. [*] Mutexes: []
  51.  
  52. [*] Modified Files: [
  53. "C:\\Users\\user\\AppData\\Local\\Temp\\TableOfColors.exe"
  54. ]
  55.  
  56. [*] Deleted Files: []
  57.  
  58. [*] Modified Registry Keys: []
  59.  
  60. [*] Deleted Registry Keys: []
  61.  
  62. [*] DNS Communications: [
  63. {
  64. "type": "A",
  65. "request": "artweekportland.com",
  66. "answers": []
  67. }
  68. ]
  69.  
  70. [*] Domains: [
  71. {
  72. "ip": "",
  73. "domain": "artweekportland.com"
  74. }
  75. ]
  76.  
  77. [*] Network Communication - ICMP: []
  78.  
  79. [*] Network Communication - HTTP: []
  80.  
  81. [*] Network Communication - SMTP: []
  82.  
  83. [*] Network Communication - Hosts: []
  84.  
  85. [*] Network Communication - IRC: []
  86.  
  87. [*] Static Analysis: {}
  88.  
  89. [*] Resolved APIs: [
  90. "advapi32.dll.SaferIdentifyLevel",
  91. "advapi32.dll.SaferComputeTokenFromLevel",
  92. "advapi32.dll.SaferCloseLevel",
  93. "kernel32.dll.NlsGetCacheUpdateCount",
  94. "ole32.dll.CLSIDFromProgIDEx",
  95. "ole32.dll.CoGetClassObject",
  96. "cryptsp.dll.CryptAcquireContextW",
  97. "cryptsp.dll.CryptGenRandom",
  98. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  99. "wscript.exe.#1",
  100. "sxs.dll.SxsOleAut32RedirectTypeLibrary",
  101. "advapi32.dll.RegOpenKeyW",
  102. "advapi32.dll.RegQueryValueW",
  103. "winhttp.dll.WinHttpCrackUrl",
  104. "shlwapi.dll.StrCmpNW",
  105. "winhttp.dll.WinHttpCreateUrl",
  106. "oleaut32.dll.#8",
  107. "oleaut32.dll.#12",
  108. "shlwapi.dll.StrRChrA",
  109. "oleaut32.dll.#4",
  110. "oleaut32.dll.#6",
  111. "kernel32.dll.RegQueryValueExW",
  112. "oleaut32.dll.#2",
  113. "kernel32.dll.RegCloseKey",
  114. "oleaut32.dll.#9",
  115. "ws2_32.dll.GetAddrInfoW",
  116. "oleaut32.dll.#202",
  117. "oleaut32.dll.#201",
  118. "sspicli.dll.GetUserNameExW",
  119. "xmllite.dll.CreateXmlWriter",
  120. "xmllite.dll.CreateXmlWriterOutputWithEncodingName",
  121. "rpcrt4.dll.RpcBindingFree",
  122. "oleaut32.dll.#500",
  123. "cryptsp.dll.CryptReleaseContext"
  124. ]
  125.  
  126. [*] Static Analysis: {}
Advertisement
Add Comment
Please, Sign In to add comment