Advertisement
paladin316

1460Genscape_Australia_vbs_2019-09-10_07_30.txt

Sep 10th, 2019
1,789
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.64 KB | None | 0 0
  1.  
  2. * ID: 1460
  3. * MalFamily: "TrojanVBS"
  4.  
  5. * MalScore: 8.5
  6.  
  7. * File Name: "Genscape Australia.vbs"
  8. * File Size: 1706857
  9. * File Type: "ASCII text, with very long lines"
  10. * SHA256: "3b59c2476def1a17c6be01fc7c864f71a0605dcb6d92d30b4a3f9c739d59d168"
  11. * MD5: "d46f3a6c72b5cc424c432ad910c47777"
  12. * SHA1: "a69e360d22903573b3bc829be1f517df2d2d414c"
  13. * SHA512: "6f25b84ade0f82a5f163e05afecd150413a7de34ac66761c5ef08b26de97a223df8c9989d8a637e7b6bfdcb118bfcb7a411519e806ca89e127305cdb815d6cf0"
  14. * CRC32: "E0D5BBD2"
  15. * SSDEEP: "49152:PTVNqlK0c1sPpNlyBCrh7ucAU8/Tn6EwtFHpR:y"
  16.  
  17. * Process Execution:
  18. "wscript.exe"
  19.  
  20.  
  21. * Executed Commands:
  22.  
  23. * Signatures Detected:
  24.  
  25. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  26. "Details":
  27.  
  28. "IP_ioc": "205.185.117.146:443 (United States)"
  29.  
  30.  
  31.  
  32.  
  33. "Description": "File has been identified by 2 Antiviruses on VirusTotal as malicious",
  34. "Details":
  35.  
  36. "NANO-Antivirus": "Trojan.Script.ExpKit.fugogz"
  37.  
  38.  
  39. "Qihoo-360": "virus.vbs.crypt.c"
  40.  
  41.  
  42.  
  43.  
  44. "Description": "Stack pivoting was detected when using a critical API",
  45. "Details":
  46.  
  47. "process": "wscript.exe:2944"
  48.  
  49.  
  50.  
  51.  
  52. "Description": "Attempts to create or modify system certificates",
  53. "Details":
  54.  
  55.  
  56.  
  57. * Started Service:
  58.  
  59. * Mutexes:
  60.  
  61. * Modified Files:
  62. "C:\\Users\\user\\AppData\\Local\\Temp\\TableOfColors.exe"
  63.  
  64.  
  65. * Deleted Files:
  66.  
  67. * Modified Registry Keys:
  68. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  69. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\\Blob"
  70.  
  71.  
  72. * Deleted Registry Keys:
  73. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DAC9024F54D8F6DF94935FB1732638CA6AD77C13"
  74.  
  75.  
  76. * DNS Communications:
  77.  
  78. "type": "A",
  79. "request": "thebaptistfoundationofcalifornia.com",
  80. "answers":
  81.  
  82. "data": "205.185.117.146",
  83. "type": "A"
  84.  
  85.  
  86.  
  87.  
  88.  
  89. * Domains:
  90.  
  91. "ip": "205.185.117.146",
  92. "domain": "thebaptistfoundationofcalifornia.com"
  93.  
  94.  
  95.  
  96. * Network Communication - ICMP:
  97.  
  98. * Network Communication - HTTP:
  99.  
  100. * Network Communication - SMTP:
  101.  
  102. * Network Communication - Hosts:
  103.  
  104. "country_name": "United States",
  105. "ip": "205.185.117.146",
  106. "inaddrarpa": "",
  107. "hostname": "thebaptistfoundationofcalifornia.com"
  108.  
  109.  
  110.  
  111. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement