Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Sload"
- * MalScore: 9.85
- * File Name: "DocumentosMay020197.vbs"
- * File Size: 79652
- * File Type: "UTF-8 Unicode text, with CRLF line terminators"
- * SHA256: "66e6872398259126cc1fbaa413514d772da3b58c5b332cda6ce502e8680d6767"
- * MD5: "f81bda63fdce783486ea89415cc6457a"
- * SHA1: "ea70dc8b39e940a47418e8a08b40f50ce642b7ab"
- * SHA512: "41743176352ec5e02b32acdbf58f05f1fddc0df8e31becc226022a32ca3a1743e872d8294661886be8815343b5fe2a81fe0fe8d0bb63d97ac4142d58c2752f79"
- * CRC32: "B28F2801"
- * SSDEEP: "1536:cTHpXzEHWTHpXzEHbTHpXzEH7gP5PWDS9gP5PWDGVoB1BVoB16:cTlzEHWTlzEHbTlzEHYVbuVDVsVT"
- * Process Execution:
- "wscript.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "svchost.exe"
- * Executed Commands:
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding"
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP": "54.210.3.52:80"
- "Description": "File has been identified by 5 Antiviruses on VirusTotal as malicious",
- "Details":
- "NANO-Antivirus": "Trojan.Script.Downloader.fnqssh"
- "Kaspersky": "HEUR:Trojan-Downloader.VBS.SLoad.gen"
- "ZoneAlarm": "HEUR:Trojan-Downloader.VBS.SLoad.gen"
- "GData": "Script.Trojan-Downloader.Agent.AKA"
- "Ikarus": "Trojan-Downloader.Script.Agent"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- "suspicious_request": "http://54.210.3.52/MODAPP/BTollVideoMonitor35.jpg"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://54.210.3.52/MODAPP/BTollVideoMonitor35.jpg"
- "Description": "Attempts to restart the guest VM",
- "Details":
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\L40849798738955H.lnk"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\L40849798738955H.lnk"
- "Description": "A wscript.exe process commonly used in script or document file downloaders initiated network activity",
- "Details":
- "http_request": "wscript.exe_InternetCrackUrlW_http://54.210.3.52/modapp/btollvideomonitor35.jpg"
- "http_request_path": "wscript.exe_HttpOpenRequestW_/modapp/btollvideomonitor35.jpg"
- "http_request": "wscript.exe_InternetCrackUrlA_http://54.210.3.52"
- "Description": "Retrieves Windows ProductID, probably to fingerprint the sandbox",
- "Details":
- "Description": "Collects information to fingerprint the system",
- "Details":
- * Started Service:
- * Mutexes:
- "Local\\ZonesCounterMutex",
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\L40849798738955H.lnk",
- "C:\\Users\\user\\AppData\\Roaming\\C40166567683219S\\L40849798738955H.exe",
- "\\??\\PIPE\\samr",
- "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
- "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\PIPE\\wkssvc",
- "\\??\\PIPE\\srvsvc"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://54.210.3.52/MODAPP/BTollVideoMonitor35.jpg",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "54.210.3.52",
- "version": "1.1",
- "path": "/MODAPP/BTollVideoMonitor35.jpg",
- "data": "GET /MODAPP/BTollVideoMonitor35.jpg HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 54.210.3.52\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment