paladin316

ShareFile_vbs_2019-06-28_16_30.json

Jun 28th, 2019
2,167
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.79 KB | None | 0 0
  1.  
  2. [*] MalFamily: ""
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "ShareFile.vbs"
  7. [*] File Size: 135858
  8. [*] File Type: "ASCII text, with very long lines"
  9. [*] SHA256: "a4374fc1fffabfcbfccebab3b79cd22bc731ba97fc3ab68929efe15e080e0619"
  10. [*] MD5: "043f22e0c24f80287f1170d3d82e3ab9"
  11. [*] SHA1: "964ac91e134164b66ad316eb269eee938411bd01"
  12. [*] SHA512: "3c4c6cd9da6a18c1a2fca2c5871183eb449ffe1655edcce2a90658fc34092d7c9840fc1c1a9daaea9d1f45abae4b509c53ef361ab49e6df4d57ea711281ca46e"
  13. [*] CRC32: "BCBD0DC6"
  14. [*] SSDEEP: "3072:m2yOtkojznaewbBpwvxeyjVySEP5mAgpJJXzyMHQ97wvb7L5u50T0anMrkyefC+3:m2IjqkZeGA"
  15.  
  16. [*] Process Execution: [
  17. "wscript.exe"
  18. ]
  19.  
  20. [*] Signatures Detected: [
  21. {
  22. "Description": "Attempts to connect to a dead IP:Port (3 unique times)",
  23. "Details": [
  24. {
  25. "IP": "192.35.177.64:80"
  26. },
  27. {
  28. "IP": "69.162.117.130:443"
  29. },
  30. {
  31. "IP": "8.253.110.120:80"
  32. }
  33. ]
  34. },
  35. {
  36. "Description": "Performs some HTTP requests",
  37. "Details": [
  38. {
  39. "url": "http://apps.identrust.com/roots/dstrootcax3.p7c"
  40. },
  41. {
  42. "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
  43. }
  44. ]
  45. },
  46. {
  47. "Description": "File has been identified by 12 Antiviruses on VirusTotal as malicious",
  48. "Details": [
  49. {
  50. "MicroWorld-eScan": "VB:Trojan.VBS.Agent.BIS"
  51. },
  52. {
  53. "BitDefender": "VB:Trojan.VBS.Agent.BIS"
  54. },
  55. {
  56. "Ad-Aware": "VB:Trojan.VBS.Agent.BIS"
  57. },
  58. {
  59. "DrWeb": "Trojan.DownLoader29.8085"
  60. },
  61. {
  62. "FireEye": "VB:Trojan.VBS.Agent.BIS"
  63. },
  64. {
  65. "Emsisoft": "VB:Trojan.VBS.Agent.BIS (B)"
  66. },
  67. {
  68. "Arcabit": "VB:Trojan.VBS.Agent.BIS"
  69. },
  70. {
  71. "ZoneAlarm": "HEUR:Trojan.VBS.SAgent.gen"
  72. },
  73. {
  74. "GData": "VB:Trojan.VBS.Agent.BIS"
  75. },
  76. {
  77. "ALYac": "VB:Trojan.VBS.Agent.BIS"
  78. },
  79. {
  80. "Ikarus": "Win32.Outbreak"
  81. },
  82. {
  83. "Qihoo-360": "virus.vbs.crypt.c"
  84. }
  85. ]
  86. }
  87. ]
  88.  
  89. [*] Started Service: []
  90.  
  91. [*] Executed Commands: []
  92.  
  93. [*] Mutexes: []
  94.  
  95. [*] Modified Files: [
  96. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  97. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  98. "C:\\Users\\user\\AppData\\Local\\Temp\\CabEEDF.tmp",
  99. "C:\\Users\\user\\AppData\\Local\\Temp\\TarEEE0.tmp",
  100. "C:\\Users\\user\\AppData\\Local\\Temp\\CabEF10.tmp",
  101. "C:\\Users\\user\\AppData\\Local\\Temp\\TarEF11.tmp",
  102. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
  103. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
  104. "C:\\Users\\user\\AppData\\Local\\Temp\\CabF1B2.tmp",
  105. "C:\\Users\\user\\AppData\\Local\\Temp\\TarF1B3.tmp",
  106. "C:\\Users\\user\\AppData\\Local\\Temp\\TableOfColors.exe"
  107. ]
  108.  
  109. [*] Deleted Files: [
  110. "C:\\Users\\user\\AppData\\Local\\Temp\\CabEEDF.tmp",
  111. "C:\\Users\\user\\AppData\\Local\\Temp\\TarEEE0.tmp",
  112. "C:\\Users\\user\\AppData\\Local\\Temp\\CabEF10.tmp",
  113. "C:\\Users\\user\\AppData\\Local\\Temp\\TarEF11.tmp",
  114. "C:\\Users\\user\\AppData\\Local\\Temp\\CabF1B2.tmp",
  115. "C:\\Users\\user\\AppData\\Local\\Temp\\TarF1B3.tmp"
  116. ]
  117.  
  118. [*] Modified Registry Keys: [
  119. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList"
  120. ]
  121.  
  122. [*] Deleted Registry Keys: []
  123.  
  124. [*] DNS Communications: [
  125. {
  126. "type": "A",
  127. "request": "persiangulfyachtclub.com",
  128. "answers": [
  129. {
  130. "data": "69.162.117.130",
  131. "type": "A"
  132. }
  133. ]
  134. },
  135. {
  136. "type": "A",
  137. "request": "apps.identrust.com",
  138. "answers": [
  139. {
  140. "data": "192.35.177.64",
  141. "type": "A"
  142. },
  143. {
  144. "data": "apps.digsigtrust.com",
  145. "type": "CNAME"
  146. }
  147. ]
  148. }
  149. ]
  150.  
  151. [*] Domains: [
  152. {
  153. "ip": "69.162.117.130",
  154. "domain": "persiangulfyachtclub.com"
  155. },
  156. {
  157. "ip": "192.35.177.64",
  158. "domain": "apps.identrust.com"
  159. }
  160. ]
  161.  
  162. [*] Network Communication - ICMP: []
  163.  
  164. [*] Network Communication - HTTP: [
  165. {
  166. "count": 1,
  167. "body": "",
  168. "uri": "http://apps.identrust.com/roots/dstrootcax3.p7c",
  169. "user-agent": "Microsoft-CryptoAPI/6.1",
  170. "method": "GET",
  171. "host": "apps.identrust.com",
  172. "version": "1.1",
  173. "path": "/roots/dstrootcax3.p7c",
  174. "data": "GET /roots/dstrootcax3.p7c HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: apps.identrust.com\r\n\r\n",
  175. "port": 80
  176. },
  177. {
  178. "count": 1,
  179. "body": "",
  180. "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  181. "user-agent": "Microsoft-CryptoAPI/6.1",
  182. "method": "GET",
  183. "host": "www.download.windowsupdate.com",
  184. "version": "1.1",
  185. "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  186. "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86403\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Feb 2019 16:53:13 GMT\r\nIf-None-Match: \"80e22c19cfcad41:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
  187. "port": 80
  188. }
  189. ]
  190.  
  191. [*] Network Communication - SMTP: []
  192.  
  193. [*] Network Communication - Hosts: []
  194.  
  195. [*] Network Communication - IRC: []
  196.  
  197. [*] Static Analysis: {}
  198.  
  199. [*] Resolved APIs: [
  200. "advapi32.dll.SaferIdentifyLevel",
  201. "advapi32.dll.SaferComputeTokenFromLevel",
  202. "advapi32.dll.SaferCloseLevel",
  203. "kernel32.dll.NlsGetCacheUpdateCount",
  204. "ole32.dll.CLSIDFromProgIDEx",
  205. "ole32.dll.CoGetClassObject",
  206. "cryptsp.dll.CryptAcquireContextW",
  207. "cryptsp.dll.CryptGenRandom",
  208. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  209. "wscript.exe.#1",
  210. "sxs.dll.SxsOleAut32RedirectTypeLibrary",
  211. "advapi32.dll.RegOpenKeyW",
  212. "advapi32.dll.RegQueryValueW",
  213. "winhttp.dll.WinHttpCrackUrl",
  214. "shlwapi.dll.StrCmpNW",
  215. "winhttp.dll.WinHttpCreateUrl",
  216. "oleaut32.dll.#8",
  217. "oleaut32.dll.#12",
  218. "shlwapi.dll.StrRChrA",
  219. "oleaut32.dll.#4",
  220. "oleaut32.dll.#6",
  221. "kernel32.dll.RegQueryValueExW",
  222. "oleaut32.dll.#2",
  223. "kernel32.dll.RegCloseKey",
  224. "oleaut32.dll.#9",
  225. "ws2_32.dll.GetAddrInfoW",
  226. "ws2_32.dll.WSASocketW",
  227. "ws2_32.dll.#2",
  228. "ws2_32.dll.#21",
  229. "ws2_32.dll.#9",
  230. "ws2_32.dll.WSAIoctl",
  231. "ws2_32.dll.FreeAddrInfoW",
  232. "ws2_32.dll.#6",
  233. "ws2_32.dll.#5",
  234. "schannel.dll.SpUserModeInitialize",
  235. "advapi32.dll.RegCreateKeyExW",
  236. "advapi32.dll.RegQueryValueExW",
  237. "advapi32.dll.RegCloseKey",
  238. "ws2_32.dll.WSASend",
  239. "ws2_32.dll.WSARecv",
  240. "secur32.dll.FreeContextBuffer",
  241. "ncrypt.dll.SslOpenProvider",
  242. "ncrypt.dll.GetSChannelInterface",
  243. "bcryptprimitives.dll.GetHashInterface",
  244. "ncrypt.dll.SslIncrementProviderReferenceCount",
  245. "ncrypt.dll.SslImportKey",
  246. "bcryptprimitives.dll.GetCipherInterface",
  247. "ncrypt.dll.SslLookupCipherSuiteInfo",
  248. "user32.dll.LoadStringW",
  249. "ncrypt.dll.BCryptOpenAlgorithmProvider",
  250. "ncrypt.dll.BCryptGetProperty",
  251. "ncrypt.dll.BCryptCreateHash",
  252. "ncrypt.dll.BCryptHashData",
  253. "ncrypt.dll.BCryptFinishHash",
  254. "ncrypt.dll.BCryptDestroyHash",
  255. "crypt32.dll.CertGetCertificateChain",
  256. "userenv.dll.GetUserProfileDirectoryW",
  257. "sechost.dll.ConvertSidToStringSidW",
  258. "sechost.dll.ConvertStringSidToSidW",
  259. "userenv.dll.RegisterGPNotification",
  260. "gpapi.dll.RegisterGPNotificationInternal",
  261. "sechost.dll.OpenSCManagerW",
  262. "sechost.dll.OpenServiceW",
  263. "sechost.dll.CloseServiceHandle",
  264. "sechost.dll.QueryServiceConfigW",
  265. "cryptnet.dll.CryptGetObjectUrl",
  266. "cryptnet.dll.CryptRetrieveObjectByUrlW",
  267. "cryptnet.dll.I_CryptNetGetConnectivity",
  268. "sensapi.dll.IsNetworkAlive",
  269. "rpcrt4.dll.RpcBindingFromStringBindingW",
  270. "rpcrt4.dll.RpcBindingSetAuthInfoExW",
  271. "rpcrt4.dll.NdrClientCall2",
  272. "winhttp.dll.WinHttpOpen",
  273. "winhttp.dll.WinHttpSetTimeouts",
  274. "winhttp.dll.WinHttpSetOption",
  275. "winhttp.dll.WinHttpConnect",
  276. "winhttp.dll.WinHttpOpenRequest",
  277. "winhttp.dll.WinHttpSetStatusCallback",
  278. "winhttp.dll.WinHttpGetDefaultProxyConfiguration",
  279. "winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser",
  280. "winhttp.dll.WinHttpSendRequest",
  281. "winhttp.dll.WinHttpReceiveResponse",
  282. "winhttp.dll.WinHttpQueryHeaders",
  283. "shlwapi.dll.StrStrIW",
  284. "winhttp.dll.WinHttpQueryDataAvailable",
  285. "winhttp.dll.WinHttpReadData",
  286. "cryptsp.dll.CryptAcquireContextA",
  287. "winhttp.dll.WinHttpCloseHandle",
  288. "cryptsp.dll.CryptCreateHash",
  289. "cryptsp.dll.CryptHashData",
  290. "cryptsp.dll.CryptVerifySignatureA",
  291. "cryptsp.dll.CryptDestroyKey",
  292. "cryptsp.dll.CryptDestroyHash",
  293. "setupapi.dll.SetupIterateCabinetW",
  294. "kernel32.dll.RegOpenKeyExW",
  295. "cabinet.dll.#20",
  296. "cabinet.dll.#22",
  297. "devrtl.dll.DevRtlGetThreadLogToken",
  298. "cabinet.dll.#23",
  299. "cryptsp.dll.CryptSetHashParam",
  300. "sechost.dll.QueryServiceConfigA",
  301. "sechost.dll.QueryServiceStatus",
  302. "rpcrt4.dll.RpcStringBindingComposeA",
  303. "rpcrt4.dll.RpcBindingFromStringBindingA",
  304. "rpcrt4.dll.RpcEpResolveBinding",
  305. "sechost.dll.LookupAccountSidLocalW",
  306. "rpcrt4.dll.RpcStringFreeA",
  307. "rpcrt4.dll.RpcBindingFree",
  308. "winhttp.dll.WinHttpTimeFromSystemTime",
  309. "cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo",
  310. "cryptnet.dll.I_CryptNetSetUrlCachePreFetchInfo",
  311. "bcryptprimitives.dll.GetAsymmetricEncryptionInterface",
  312. "ncrypt.dll.BCryptImportKeyPair",
  313. "ncrypt.dll.BCryptVerifySignature",
  314. "ncrypt.dll.BCryptDestroyKey",
  315. "crypt32.dll.CertVerifyCertificateChainPolicy",
  316. "crypt32.dll.CertFreeCertificateChain",
  317. "crypt32.dll.CertDuplicateCertificateContext",
  318. "ncrypt.dll.SslEncryptPacket",
  319. "ncrypt.dll.SslDecryptPacket",
  320. "ole32.dll.CreateStreamOnHGlobal",
  321. "oleaut32.dll.#411",
  322. "oleaut32.dll.#23",
  323. "oleaut32.dll.#24",
  324. "ole32.dll.GetHGlobalFromStream",
  325. "sspicli.dll.GetUserNameExW",
  326. "xmllite.dll.CreateXmlWriter",
  327. "xmllite.dll.CreateXmlWriterOutputWithEncodingName",
  328. "crypt32.dll.CertFreeCertificateContext",
  329. "oleaut32.dll.#500",
  330. "ncrypt.dll.SslFreeObject",
  331. "cryptsp.dll.CryptReleaseContext"
  332. ]
  333.  
  334. [*] Static Analysis: {}
Advertisement
Add Comment
Please, Sign In to add comment