paladin316

ShareFile_vbs_2019-06-28_07_30.json

Jun 28th, 2019
2,187
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.57 KB | None | 0 0
  1.  
  2. [*] MalFamily: ""
  3.  
  4. [*] MalScore: 4.05
  5.  
  6. [*] File Name: "ShareFile.vbs"
  7. [*] File Size: 135858
  8. [*] File Type: "ASCII text, with very long lines"
  9. [*] SHA256: "a4374fc1fffabfcbfccebab3b79cd22bc731ba97fc3ab68929efe15e080e0619"
  10. [*] MD5: "043f22e0c24f80287f1170d3d82e3ab9"
  11. [*] SHA1: "964ac91e134164b66ad316eb269eee938411bd01"
  12. [*] SHA512: "3c4c6cd9da6a18c1a2fca2c5871183eb449ffe1655edcce2a90658fc34092d7c9840fc1c1a9daaea9d1f45abae4b509c53ef361ab49e6df4d57ea711281ca46e"
  13. [*] CRC32: "BCBD0DC6"
  14. [*] SSDEEP: "3072:m2yOtkojznaewbBpwvxeyjVySEP5mAgpJJXzyMHQ97wvb7L5u50T0anMrkyefC+3:m2IjqkZeGA"
  15.  
  16. [*] Process Execution: [
  17. "wscript.exe"
  18. ]
  19.  
  20. [*] Signatures Detected: [
  21. {
  22. "Description": "Attempts to connect to a dead IP:Port (3 unique times)",
  23. "Details": [
  24. {
  25. "IP": "205.185.216.42:80"
  26. },
  27. {
  28. "IP": "192.35.177.64:80"
  29. },
  30. {
  31. "IP": "69.162.117.130:443"
  32. }
  33. ]
  34. },
  35. {
  36. "Description": "File has been identified by 9 Antiviruses on VirusTotal as malicious",
  37. "Details": [
  38. {
  39. "MicroWorld-eScan": "VB:Trojan.VBS.Agent.BIS"
  40. },
  41. {
  42. "GData": "VB:Trojan.VBS.Agent.BIS"
  43. },
  44. {
  45. "BitDefender": "VB:Trojan.VBS.Agent.BIS"
  46. },
  47. {
  48. "Ad-Aware": "VB:Trojan.VBS.Agent.BIS"
  49. },
  50. {
  51. "FireEye": "VB:Trojan.VBS.Agent.BIS"
  52. },
  53. {
  54. "Emsisoft": "VB:Trojan.VBS.Agent.BIS (B)"
  55. },
  56. {
  57. "Arcabit": "VB:Trojan.VBS.Agent.BIS"
  58. },
  59. {
  60. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  61. },
  62. {
  63. "Qihoo-360": "virus.vbs.crypt.c"
  64. }
  65. ]
  66. },
  67. {
  68. "Description": "Performs some HTTP requests",
  69. "Details": [
  70. {
  71. "url": "http://apps.identrust.com/roots/dstrootcax3.p7c"
  72. },
  73. {
  74. "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
  75. }
  76. ]
  77. }
  78. ]
  79.  
  80. [*] Started Service: []
  81.  
  82. [*] Executed Commands: []
  83.  
  84. [*] Mutexes: []
  85.  
  86. [*] Modified Files: [
  87. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  88. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  89. "C:\\Users\\user\\AppData\\Local\\Temp\\CabE039.tmp",
  90. "C:\\Users\\user\\AppData\\Local\\Temp\\TarE03A.tmp",
  91. "C:\\Users\\user\\AppData\\Local\\Temp\\CabE07A.tmp",
  92. "C:\\Users\\user\\AppData\\Local\\Temp\\TarE07B.tmp",
  93. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
  94. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
  95. "C:\\Users\\user\\AppData\\Local\\Temp\\CabE2AE.tmp",
  96. "C:\\Users\\user\\AppData\\Local\\Temp\\TarE2AF.tmp",
  97. "C:\\Users\\user\\AppData\\Local\\Temp\\TableOfColors.exe"
  98. ]
  99.  
  100. [*] Deleted Files: [
  101. "C:\\Users\\user\\AppData\\Local\\Temp\\CabE039.tmp",
  102. "C:\\Users\\user\\AppData\\Local\\Temp\\TarE03A.tmp",
  103. "C:\\Users\\user\\AppData\\Local\\Temp\\CabE07A.tmp",
  104. "C:\\Users\\user\\AppData\\Local\\Temp\\TarE07B.tmp",
  105. "C:\\Users\\user\\AppData\\Local\\Temp\\CabE2AE.tmp",
  106. "C:\\Users\\user\\AppData\\Local\\Temp\\TarE2AF.tmp"
  107. ]
  108.  
  109. [*] Modified Registry Keys: [
  110. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList"
  111. ]
  112.  
  113. [*] Deleted Registry Keys: []
  114.  
  115. [*] DNS Communications: [
  116. {
  117. "type": "A",
  118. "request": "persiangulfyachtclub.com",
  119. "answers": [
  120. {
  121. "data": "69.162.117.130",
  122. "type": "A"
  123. }
  124. ]
  125. },
  126. {
  127. "type": "A",
  128. "request": "apps.identrust.com",
  129. "answers": [
  130. {
  131. "data": "192.35.177.64",
  132. "type": "A"
  133. },
  134. {
  135. "data": "apps.digsigtrust.com",
  136. "type": "CNAME"
  137. }
  138. ]
  139. }
  140. ]
  141.  
  142. [*] Domains: [
  143. {
  144. "ip": "192.35.177.64",
  145. "domain": "apps.identrust.com"
  146. },
  147. {
  148. "ip": "69.162.117.130",
  149. "domain": "persiangulfyachtclub.com"
  150. }
  151. ]
  152.  
  153. [*] Network Communication - ICMP: []
  154.  
  155. [*] Network Communication - HTTP: [
  156. {
  157. "count": 1,
  158. "body": "",
  159. "uri": "http://apps.identrust.com/roots/dstrootcax3.p7c",
  160. "user-agent": "Microsoft-CryptoAPI/6.1",
  161. "method": "GET",
  162. "host": "apps.identrust.com",
  163. "version": "1.1",
  164. "path": "/roots/dstrootcax3.p7c",
  165. "data": "GET /roots/dstrootcax3.p7c HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: apps.identrust.com\r\n\r\n",
  166. "port": 80
  167. },
  168. {
  169. "count": 1,
  170. "body": "",
  171. "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  172. "user-agent": "Microsoft-CryptoAPI/6.1",
  173. "method": "GET",
  174. "host": "www.download.windowsupdate.com",
  175. "version": "1.1",
  176. "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  177. "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86403\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Feb 2019 16:53:13 GMT\r\nIf-None-Match: \"80e22c19cfcad41:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
  178. "port": 80
  179. }
  180. ]
  181.  
  182. [*] Network Communication - SMTP: []
  183.  
  184. [*] Network Communication - Hosts: []
  185.  
  186. [*] Network Communication - IRC: []
  187.  
  188. [*] Static Analysis: {}
  189.  
  190. [*] Resolved APIs: [
  191. "advapi32.dll.SaferIdentifyLevel",
  192. "advapi32.dll.SaferComputeTokenFromLevel",
  193. "advapi32.dll.SaferCloseLevel",
  194. "kernel32.dll.NlsGetCacheUpdateCount",
  195. "ole32.dll.CLSIDFromProgIDEx",
  196. "ole32.dll.CoGetClassObject",
  197. "cryptsp.dll.CryptAcquireContextW",
  198. "cryptsp.dll.CryptGenRandom",
  199. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  200. "wscript.exe.#1",
  201. "sxs.dll.SxsOleAut32RedirectTypeLibrary",
  202. "advapi32.dll.RegOpenKeyW",
  203. "advapi32.dll.RegQueryValueW",
  204. "winhttp.dll.WinHttpCrackUrl",
  205. "shlwapi.dll.StrCmpNW",
  206. "winhttp.dll.WinHttpCreateUrl",
  207. "oleaut32.dll.#8",
  208. "oleaut32.dll.#12",
  209. "shlwapi.dll.StrRChrA",
  210. "oleaut32.dll.#4",
  211. "oleaut32.dll.#6",
  212. "kernel32.dll.RegQueryValueExW",
  213. "oleaut32.dll.#2",
  214. "kernel32.dll.RegCloseKey",
  215. "oleaut32.dll.#9",
  216. "ws2_32.dll.GetAddrInfoW",
  217. "ws2_32.dll.WSASocketW",
  218. "ws2_32.dll.#2",
  219. "ws2_32.dll.#21",
  220. "ws2_32.dll.#9",
  221. "ws2_32.dll.WSAIoctl",
  222. "ws2_32.dll.FreeAddrInfoW",
  223. "ws2_32.dll.#6",
  224. "ws2_32.dll.#5",
  225. "schannel.dll.SpUserModeInitialize",
  226. "advapi32.dll.RegCreateKeyExW",
  227. "advapi32.dll.RegQueryValueExW",
  228. "advapi32.dll.RegCloseKey",
  229. "ws2_32.dll.WSASend",
  230. "ws2_32.dll.WSARecv",
  231. "secur32.dll.FreeContextBuffer",
  232. "ncrypt.dll.SslOpenProvider",
  233. "ncrypt.dll.GetSChannelInterface",
  234. "bcryptprimitives.dll.GetHashInterface",
  235. "ncrypt.dll.SslIncrementProviderReferenceCount",
  236. "ncrypt.dll.SslImportKey",
  237. "bcryptprimitives.dll.GetCipherInterface",
  238. "ncrypt.dll.SslLookupCipherSuiteInfo",
  239. "user32.dll.LoadStringW",
  240. "ncrypt.dll.BCryptOpenAlgorithmProvider",
  241. "ncrypt.dll.BCryptGetProperty",
  242. "ncrypt.dll.BCryptCreateHash",
  243. "ncrypt.dll.BCryptHashData",
  244. "ncrypt.dll.BCryptFinishHash",
  245. "ncrypt.dll.BCryptDestroyHash",
  246. "crypt32.dll.CertGetCertificateChain",
  247. "userenv.dll.GetUserProfileDirectoryW",
  248. "sechost.dll.ConvertSidToStringSidW",
  249. "sechost.dll.ConvertStringSidToSidW",
  250. "userenv.dll.RegisterGPNotification",
  251. "gpapi.dll.RegisterGPNotificationInternal",
  252. "sechost.dll.OpenSCManagerW",
  253. "sechost.dll.OpenServiceW",
  254. "sechost.dll.CloseServiceHandle",
  255. "sechost.dll.QueryServiceConfigW",
  256. "cryptnet.dll.CryptGetObjectUrl",
  257. "cryptnet.dll.CryptRetrieveObjectByUrlW",
  258. "cryptnet.dll.I_CryptNetGetConnectivity",
  259. "sensapi.dll.IsNetworkAlive",
  260. "rpcrt4.dll.RpcBindingFromStringBindingW",
  261. "rpcrt4.dll.RpcBindingSetAuthInfoExW",
  262. "rpcrt4.dll.NdrClientCall2",
  263. "winhttp.dll.WinHttpOpen",
  264. "winhttp.dll.WinHttpSetTimeouts",
  265. "winhttp.dll.WinHttpSetOption",
  266. "winhttp.dll.WinHttpConnect",
  267. "winhttp.dll.WinHttpOpenRequest",
  268. "winhttp.dll.WinHttpSetStatusCallback",
  269. "winhttp.dll.WinHttpGetDefaultProxyConfiguration",
  270. "winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser",
  271. "winhttp.dll.WinHttpSendRequest",
  272. "winhttp.dll.WinHttpReceiveResponse",
  273. "winhttp.dll.WinHttpQueryHeaders",
  274. "shlwapi.dll.StrStrIW",
  275. "winhttp.dll.WinHttpQueryDataAvailable",
  276. "winhttp.dll.WinHttpReadData",
  277. "cryptsp.dll.CryptAcquireContextA",
  278. "winhttp.dll.WinHttpCloseHandle",
  279. "cryptsp.dll.CryptCreateHash",
  280. "cryptsp.dll.CryptHashData",
  281. "cryptsp.dll.CryptVerifySignatureA",
  282. "cryptsp.dll.CryptDestroyKey",
  283. "cryptsp.dll.CryptDestroyHash",
  284. "setupapi.dll.SetupIterateCabinetW",
  285. "kernel32.dll.RegOpenKeyExW",
  286. "cabinet.dll.#20",
  287. "cabinet.dll.#22",
  288. "devrtl.dll.DevRtlGetThreadLogToken",
  289. "cabinet.dll.#23",
  290. "cryptsp.dll.CryptSetHashParam",
  291. "sechost.dll.QueryServiceConfigA",
  292. "sechost.dll.QueryServiceStatus",
  293. "rpcrt4.dll.RpcStringBindingComposeA",
  294. "rpcrt4.dll.RpcBindingFromStringBindingA",
  295. "rpcrt4.dll.RpcEpResolveBinding",
  296. "sechost.dll.LookupAccountSidLocalW",
  297. "rpcrt4.dll.RpcStringFreeA",
  298. "rpcrt4.dll.RpcBindingFree",
  299. "winhttp.dll.WinHttpTimeFromSystemTime",
  300. "cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo",
  301. "cryptnet.dll.I_CryptNetSetUrlCachePreFetchInfo",
  302. "bcryptprimitives.dll.GetAsymmetricEncryptionInterface",
  303. "ncrypt.dll.BCryptImportKeyPair",
  304. "ncrypt.dll.BCryptVerifySignature",
  305. "ncrypt.dll.BCryptDestroyKey",
  306. "crypt32.dll.CertVerifyCertificateChainPolicy",
  307. "crypt32.dll.CertFreeCertificateChain",
  308. "crypt32.dll.CertDuplicateCertificateContext",
  309. "ncrypt.dll.SslEncryptPacket",
  310. "ncrypt.dll.SslDecryptPacket",
  311. "ole32.dll.CreateStreamOnHGlobal",
  312. "oleaut32.dll.#411",
  313. "oleaut32.dll.#23",
  314. "oleaut32.dll.#24",
  315. "ole32.dll.GetHGlobalFromStream",
  316. "sspicli.dll.GetUserNameExW",
  317. "xmllite.dll.CreateXmlWriter",
  318. "xmllite.dll.CreateXmlWriterOutputWithEncodingName",
  319. "crypt32.dll.CertFreeCertificateContext",
  320. "oleaut32.dll.#500",
  321. "ncrypt.dll.SslFreeObject",
  322. "cryptsp.dll.CryptReleaseContext"
  323. ]
  324.  
  325. [*] Static Analysis: {}
Advertisement
Add Comment
Please, Sign In to add comment