Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Sagent"
- [*] MalScore: 0.8
- [*] File Name: "ShareFile.vbs"
- [*] File Size: 135760
- [*] File Type: "ASCII text, with very long lines"
- [*] SHA256: "7e525e5cf3048c4ac984de2e69de583748abb7f809e4c33afea4d49bb39d2619"
- [*] MD5: "d4cf32105257aabdd26cf6e5e81400f9"
- [*] SHA1: "b6ecb63ddfc18c54c6030abc2d652000bdee4415"
- [*] SHA512: "8930c0dbaa995d140a53c4e72543a3e7a73c9ba400a77799a482b0df94f70dbcadf73866d7df85a3dfc302c296881cd9f96aef932e8863b2e3a58a0c6a95a3b0"
- [*] CRC32: "444BF80A"
- [*] SSDEEP: "1536:yGDWFNaXTNF1YAUYNrIebq1aQZLNMQypaf:y0NF1wYNrBbqBZLvR"
- [*] Process Execution: [
- "wscript.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Attempts to connect to a dead IP:Port (3 unique times)",
- "Details": [
- {
- "IP": "72.21.81.240:80"
- },
- {
- "IP": "216.245.192.219:443"
- },
- {
- "IP": "192.35.177.64:80"
- }
- ]
- },
- {
- "Description": "File has been identified by 4 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "Kaspersky": "HEUR:Trojan.VBS.SAgent.gen"
- },
- {
- "DrWeb": "Trojan.DownLoader29.2186"
- },
- {
- "ZoneAlarm": "HEUR:Trojan.VBS.SAgent.gen"
- },
- {
- "Qihoo-360": "virus.vbs.crypt.c"
- }
- ]
- },
- {
- "Description": "Performs some HTTP requests",
- "Details": [
- {
- "url": "http://apps.identrust.com/roots/dstrootcax3.p7c"
- },
- {
- "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: []
- [*] Modified Files: [
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CabDE27.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TarDE28.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cab192F.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Tar1930.tmp",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cab274A.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Tar274B.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TableOfColors.exe"
- ]
- [*] Deleted Files: [
- "C:\\Users\\user\\AppData\\Local\\Temp\\CabDE27.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\TarDE28.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cab192F.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Tar1930.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cab274A.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Tar274B.tmp"
- ]
- [*] Modified Registry Keys: [
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList"
- ]
- [*] Deleted Registry Keys: []
- [*] DNS Communications: [
- {
- "type": "A",
- "request": "tonyschopshop.com",
- "answers": [
- {
- "data": "216.245.192.219",
- "type": "A"
- }
- ]
- },
- {
- "type": "A",
- "request": "apps.identrust.com",
- "answers": [
- {
- "data": "192.35.177.64",
- "type": "A"
- },
- {
- "data": "apps.digsigtrust.com",
- "type": "CNAME"
- }
- ]
- }
- ]
- [*] Domains: [
- {
- "ip": "192.35.177.64",
- "domain": "apps.identrust.com"
- },
- {
- "ip": "216.245.192.219",
- "domain": "tonyschopshop.com"
- }
- ]
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: [
- {
- "count": 1,
- "body": "",
- "uri": "http://apps.identrust.com/roots/dstrootcax3.p7c",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "apps.identrust.com",
- "version": "1.1",
- "path": "/roots/dstrootcax3.p7c",
- "data": "GET /roots/dstrootcax3.p7c HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: apps.identrust.com\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "www.download.windowsupdate.com",
- "version": "1.1",
- "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
- "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86439\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Feb 2019 16:53:13 GMT\r\nIf-None-Match: \"80e22c19cfcad41:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
- "port": 80
- }
- ]
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {}
- [*] Resolved APIs: [
- "advapi32.dll.SaferIdentifyLevel",
- "advapi32.dll.SaferComputeTokenFromLevel",
- "advapi32.dll.SaferCloseLevel",
- "kernel32.dll.NlsGetCacheUpdateCount",
- "ole32.dll.CLSIDFromProgIDEx",
- "ole32.dll.CoGetClassObject",
- "cryptsp.dll.CryptAcquireContextW",
- "cryptsp.dll.CryptGenRandom",
- "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
- "wscript.exe.#1",
- "sxs.dll.SxsOleAut32RedirectTypeLibrary",
- "advapi32.dll.RegOpenKeyW",
- "advapi32.dll.RegQueryValueW",
- "winhttp.dll.WinHttpCrackUrl",
- "shlwapi.dll.StrCmpNW",
- "winhttp.dll.WinHttpCreateUrl",
- "oleaut32.dll.#8",
- "oleaut32.dll.#12",
- "shlwapi.dll.StrRChrA",
- "oleaut32.dll.#4",
- "oleaut32.dll.#6",
- "kernel32.dll.RegQueryValueExW",
- "oleaut32.dll.#2",
- "kernel32.dll.RegCloseKey",
- "oleaut32.dll.#9",
- "ws2_32.dll.GetAddrInfoW",
- "ws2_32.dll.WSASocketW",
- "ws2_32.dll.#2",
- "ws2_32.dll.#21",
- "ws2_32.dll.#9",
- "ws2_32.dll.WSAIoctl",
- "ws2_32.dll.FreeAddrInfoW",
- "ws2_32.dll.#6",
- "ws2_32.dll.#5",
- "schannel.dll.SpUserModeInitialize",
- "advapi32.dll.RegCreateKeyExW",
- "advapi32.dll.RegQueryValueExW",
- "advapi32.dll.RegCloseKey",
- "ws2_32.dll.WSASend",
- "ws2_32.dll.WSARecv",
- "secur32.dll.FreeContextBuffer",
- "ncrypt.dll.SslOpenProvider",
- "ncrypt.dll.GetSChannelInterface",
- "bcryptprimitives.dll.GetHashInterface",
- "ncrypt.dll.SslIncrementProviderReferenceCount",
- "ncrypt.dll.SslImportKey",
- "bcryptprimitives.dll.GetCipherInterface",
- "ncrypt.dll.SslLookupCipherSuiteInfo",
- "user32.dll.LoadStringW",
- "ncrypt.dll.BCryptOpenAlgorithmProvider",
- "ncrypt.dll.BCryptGetProperty",
- "ncrypt.dll.BCryptCreateHash",
- "ncrypt.dll.BCryptHashData",
- "ncrypt.dll.BCryptFinishHash",
- "ncrypt.dll.BCryptDestroyHash",
- "crypt32.dll.CertGetCertificateChain",
- "userenv.dll.GetUserProfileDirectoryW",
- "sechost.dll.ConvertSidToStringSidW",
- "sechost.dll.ConvertStringSidToSidW",
- "userenv.dll.RegisterGPNotification",
- "gpapi.dll.RegisterGPNotificationInternal",
- "sechost.dll.OpenSCManagerW",
- "sechost.dll.OpenServiceW",
- "sechost.dll.CloseServiceHandle",
- "sechost.dll.QueryServiceConfigW",
- "cryptnet.dll.CryptGetObjectUrl",
- "cryptnet.dll.CryptRetrieveObjectByUrlW",
- "cryptnet.dll.I_CryptNetGetConnectivity",
- "sensapi.dll.IsNetworkAlive",
- "rpcrt4.dll.RpcBindingFromStringBindingW",
- "rpcrt4.dll.RpcBindingSetAuthInfoExW",
- "rpcrt4.dll.NdrClientCall2",
- "winhttp.dll.WinHttpOpen",
- "winhttp.dll.WinHttpSetTimeouts",
- "winhttp.dll.WinHttpSetOption",
- "winhttp.dll.WinHttpConnect",
- "winhttp.dll.WinHttpOpenRequest",
- "winhttp.dll.WinHttpSetStatusCallback",
- "winhttp.dll.WinHttpGetDefaultProxyConfiguration",
- "winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser",
- "winhttp.dll.WinHttpSendRequest",
- "winhttp.dll.WinHttpReceiveResponse",
- "winhttp.dll.WinHttpQueryHeaders",
- "shlwapi.dll.StrStrIW",
- "winhttp.dll.WinHttpQueryDataAvailable",
- "winhttp.dll.WinHttpReadData",
- "cryptsp.dll.CryptAcquireContextA",
- "winhttp.dll.WinHttpCloseHandle",
- "cryptsp.dll.CryptCreateHash",
- "cryptsp.dll.CryptHashData",
- "cryptsp.dll.CryptVerifySignatureA",
- "cryptsp.dll.CryptDestroyKey",
- "cryptsp.dll.CryptDestroyHash",
- "setupapi.dll.SetupIterateCabinetW",
- "kernel32.dll.RegOpenKeyExW",
- "cabinet.dll.#20",
- "cabinet.dll.#22",
- "devrtl.dll.DevRtlGetThreadLogToken",
- "cabinet.dll.#23",
- "cryptsp.dll.CryptSetHashParam",
- "sechost.dll.QueryServiceConfigA",
- "sechost.dll.QueryServiceStatus",
- "rpcrt4.dll.RpcStringBindingComposeA",
- "rpcrt4.dll.RpcBindingFromStringBindingA",
- "rpcrt4.dll.RpcEpResolveBinding",
- "sechost.dll.LookupAccountSidLocalW",
- "rpcrt4.dll.RpcStringFreeA",
- "rpcrt4.dll.RpcBindingFree",
- "winhttp.dll.WinHttpTimeFromSystemTime",
- "cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo",
- "cryptnet.dll.I_CryptNetSetUrlCachePreFetchInfo",
- "bcryptprimitives.dll.GetAsymmetricEncryptionInterface",
- "ncrypt.dll.BCryptImportKeyPair",
- "ncrypt.dll.BCryptVerifySignature",
- "ncrypt.dll.BCryptDestroyKey",
- "crypt32.dll.CertVerifyCertificateChainPolicy",
- "crypt32.dll.CertFreeCertificateChain",
- "crypt32.dll.CertDuplicateCertificateContext",
- "ncrypt.dll.SslEncryptPacket",
- "ncrypt.dll.SslDecryptPacket",
- "ole32.dll.CreateStreamOnHGlobal",
- "oleaut32.dll.#411",
- "oleaut32.dll.#23",
- "oleaut32.dll.#24",
- "ole32.dll.GetHGlobalFromStream",
- "sspicli.dll.GetUserNameExW",
- "xmllite.dll.CreateXmlWriter",
- "xmllite.dll.CreateXmlWriterOutputWithEncodingName",
- "crypt32.dll.CertFreeCertificateContext",
- "oleaut32.dll.#500",
- "ncrypt.dll.SslFreeObject",
- "cryptsp.dll.CryptReleaseContext"
- ]
- [*] Static Analysis: {}
Advertisement
Add Comment
Please, Sign In to add comment