Automated Malware Analysis Report For
Total Page:16
File Type:pdf, Size:1020Kb
ID: 233454 Cookbook: browseurl.jbs Time: 16:56:13 Date: 27/05/2020 Version: 28.0.0 Lapis Lazuli Table of Contents Table of Contents 2 Analysis Report https://pixeldrain.com/u/8PVPE3yA 4 Overview 4 General Information 4 Detection 4 Signatures 4 Classification 4 Startup 4 Malware Configuration 4 Yara Overview 4 Sigma Overview 4 Signature Overview 4 Mitre Att&ck Matrix 5 Behavior Graph 5 Screenshots 6 Thumbnails 6 Antivirus, Machine Learning and Genetic Malware Detection 7 Initial Sample 7 Dropped Files 7 Unpacked PE Files 7 Domains 7 URLs 8 Domains and IPs 8 Contacted Domains 8 URLs from Memory and Binaries 8 Contacted IPs 11 Public 11 General Information 11 Simulations 12 Behavior and APIs 12 Joe Sandbox View / Context 13 IPs 13 Domains 13 ASN 13 JA3 Fingerprints 13 Dropped Files 13 Created / dropped Files 13 Static File Info 43 No static file info 43 Network Behavior 43 Network Port Distribution 43 TCP Packets 43 UDP Packets 45 DNS Queries 46 DNS Answers 46 HTTPS Packets 47 Code Manipulations 52 Statistics 52 Behavior 52 System Behavior 52 Analysis Process: iexplore.exe PID: 5240 Parent PID: 692 52 General 52 File Activities 53 Registry Activities 53 Analysis Process: iexplore.exe PID: 4900 Parent PID: 5240 53 Copyright Joe Security LLC 2020 Page 2 of 54 General 53 File Activities 53 Registry Activities 53 Disassembly 53 Copyright Joe Security LLC 2020 Page 3 of 54 Analysis Report https://pixeldrain.com/u/8PVPE3yA Overview General Information Detection Signatures Classification Sample URL: https://pixeldrain.com/u/8P FFoouunndd iiifffrrraameess VPE3yA Found iframes Ransomware Most interesting Screenshot: Miner Spreading mmaallliiiccciiioouusss malicious Evader Phishing sssuusssppiiiccciiioouusss suspicious cccllleeaann clean Exploiter Banker Spyware Trojan / Bot Adware Score: 0 Range: 0 - 100 Whitelisted: false Confidence: 80% Startup System is w10x64 iexplore.exe (PID: 5240 cmdline: 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding MD5: 6465CB92B25A7BC1DF8E01D8AC5E7596) iexplore.exe (PID: 4900 cmdline: 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:5240 CREDAT:17410 /prefetch:2 MD5: 071277CC2E3DF41EEEA8013E2AB58D5A) cleanup Malware Configuration No configs have been found Yara Overview No yara matches Sigma Overview No Sigma rule has matched Signature Overview Copyright Joe Security LLC 2020 Page 4 of 54 • Phishing • Networking • System Summary Click to jump to signature section Mitre Att&ck Matrix Remote Privilege Defense Credential Lateral Command Network Service Initial Access Execution Persistence Escalation Evasion Access Discovery Movement Collection Exfiltration and Control Effects Effects Drive-by Graphical User Winlogon Process Masquerading 1 Credential File and Application Data from Data Standard Eavesdrop on Remotely Compromise 1 Interface 2 Helper DLL Injection 1 Dumping Directory Deployment Local Compressed Cryptographic Insecure Track Device Discovery 1 Software System Protocol 2 Network Without Communication Authorization Replication Service Port Accessibility Process Network Application Remote Data from Exfiltration Standard Exploit SS7 to Remotely Through Execution Monitors Features Injection 1 Sniffing Window Services Removable Over Other Non- Redirect Phone Wipe Data Removable Discovery Media Network Application Calls/SMS Without Media Medium Layer Authorization Protocol 1 External Windows Accessibility Path Rootkit Input Query Windows Data from Automated Standard Exploit SS7 to Obtain Remote Management Features Interception Capture Registry Remote Network Exfiltration Application Track Device Device Services Instrumentation Management Shared Layer Location Cloud Drive Protocol 2 Backups Behavior Graph Copyright Joe Security LLC 2020 Page 5 of 54 Hide Legend Behavior Graph Legend: ID: 233454 Process URL: https://pixeldrain.com/u/8PVPE3yA Signature Startdate: 27/05/2020 Created File Architecture: WINDOWS DNS/IP Info Score: 0 Is Dropped Is Windows Process Number of created Registry Values pixeldrain.com started Number of created Files Visual Basic Delphi iexplore.exe Java .Net C# or VB.NET C, C++ or other language 3 78 Is malicious Internet started iexplore.exe 8 210 sgwidget.leaderapps.co p.ssl.fastly.net 104.26.6.105, 443, 49954, 49955 151.101.113.7, 443, 49956, 49957 13 other IPs or domains unknown unknown United States United States Screenshots Thumbnails This section contains all screenshots as thumbnails, including those not shown in the slideshow. Copyright Joe Security LLC 2020 Page 6 of 54 Antivirus, Machine Learning and Genetic Malware Detection Initial Sample Source Detection Scanner Label Link https://pixeldrain.com/u/8PVPE3yA 1% Virustotal Browse https://pixeldrain.com/u/8PVPE3yA 0% Avira URL Cloud safe Dropped Files No Antivirus matches Unpacked PE Files No Antivirus matches Domains Source Detection Scanner Label Link p.ssl.fastly.net 0% Virustotal Browse pixeldrain.com 1% Virustotal Browse www.google.co.uk 0% Virustotal Browse fathom.pixeldrain.com 0% Virustotal Browse sgwidget.leaderapps.co 0% Virustotal Browse adservice.google.co.uk 0% Virustotal Browse Copyright Joe Security LLC 2020 Page 7 of 54 URLs Source Detection Scanner Label Link robert-fleischmann.de) 0% Avira URL Cloud safe 0% Avira URL Cloud safe https://adservice.google.co.uk/ddm/fls/i/src=2542116;type=chrom322;cat=chrom01g;ord=270465861657 3;gt https://accounts.firefox.com.cn/signup?entrypoint=mozilla.org- 0% Virustotal Browse globalnav&form_type=button&utm_source= https://accounts.firefox.com.cn/signup?entrypoint=mozilla.org- 0% Avira URL Cloud safe globalnav&form_type=button&utm_source= abattis.orgCantarellLight 0% Avira URL Cloud safe https://accounts.firefox.com.cn/signup?entrypoint=mozilla.org- 0% Virustotal Browse firefoxfooter&form_type=button&utm_sou https://accounts.firefox.com.cn/signup?entrypoint=mozilla.org- 0% Avira URL Cloud safe firefoxfooter&form_type=button&utm_sou https://pixeldrain.com 1% Virustotal Browse https://pixeldrain.com 0% Avira URL Cloud safe https://about.google/ 0% Virustotal Browse https://about.google/ 0% Avira URL Cloud safe www.sansoxygen.comhttp://www.sansoxygen.comThis 0% Avira URL Cloud safe https://pixeldrain.com/historyain.com/res/img/pixeldrain.png 0% Avira URL Cloud safe https://pixeldrain.com/history6Upload 0% Avira URL Cloud safe https://accounts.firefox.com.cn/signup?entrypoint=mozilla.org- 0% Avira URL Cloud safe firefoxnav&form_type=button&utm_source https://pixeldrain.com/u/8PVPE3yARoot 0% Avira URL Cloud safe https://sketch.com 0% Virustotal Browse https://sketch.com 0% Avira URL Cloud safe https://pixeldrain.com/u/8PVPE3yAd 0% Avira URL Cloud safe https://pixeldrain.com/login$Login 0% Avira URL Cloud safe daneden.me/animate 0% Virustotal Browse daneden.me/animate 0% Avira URL Cloud safe https://pixeldrain.com/appearanceV 0% Avira URL Cloud safe https://accounts.firefox.com.cn/signup?entrypoint=mozilla.org- 0% Avira URL Cloud safe firefox_home&form_type=button&utm_sour Domains and IPs Contacted Domains Name IP Active Malicious Antivirus Detection Reputation dart.l.doubleclick.net 172.217.18.6 true false high pagead46.l.doubleclick.net 172.217.18.2 true false high p.ssl.fastly.net 151.101.113.7 true false 0%, Virustotal, Browse low stats.l.doubleclick.net 173.194.76.157 true false high pixeldrain.com 178.63.99.70 true false 1%, Virustotal, Browse unknown brave.com 151.101.193.7 true false high www.google.co.uk 216.58.212.131 true false 0%, Virustotal, Browse low fathom.pixeldrain.com 23.175.0.143 true false 0%, Virustotal, Browse unknown mozilla.org 63.245.208.195 true false high sgwidget.leaderapps.co 104.26.6.105 true false 0%, Virustotal, Browse unknown analytics.brave.com unknown unknown false high 2542116.fls.doubleclick.net unknown unknown false high adservice.google.co.uk unknown unknown false 0%, Virustotal, Browse low stats.g.doubleclick.net unknown unknown false high URLs from Memory and Binaries Name Source Malicious Antivirus Detection Reputation robert-fleischmann.de) custom.min[1].js.2.dr false Avira URL Cloud: safe low https://brave.com/the-brave-community/ H58L24HR.htm.2.dr false high https://laptop-updates.brave.com/download/ H58L24HR.htm.2.dr false high www.tumblr.com/share/link?url= T7Q2381G.htm.2.dr false high daverupert.com custom.min[1].js.2.dr false high https://github.com/rnmp/salvattore custom.min[1].js.2.dr false high Copyright Joe Security LLC 2020 Page 8 of 54 Name Source Malicious Antivirus Detection Reputation https://stats.g.doubleclick.net/r/collect? analytics[1].js.2.dr false high t=dc&aip=1&_r=3& {7B6EA7F3-A02A-11EA-AAE6-9CC1A false Avira URL Cloud: safe low https://adservice.google.co.uk/ddm/fls/i/src=2542116;type=chr 2A860C6}.dat.1.dr om322;cat=chrom01g;ord=2704658616573;gt https://brave.com/wp-content/uploads/files_2019-11- H58L24HR.htm.2.dr false high home/images/video-speedtest.webp https://analytics.brave.com/piwik.php?idsite=2 H58L24HR.htm.2.dr false high https://blog.google/products/chrome/ chrome[1].htm.2.dr false high https://wiki.gnome.org/Apps/Web/ 8PVPE3yA[1].htm.2.dr false high https://brave.com/wp-content/uploads/files_2019-11- H58L24HR.htm.2.dr false high home/images/text-takebackcontrol-small-min.webp https://brave.com/download H58L24HR.htm.2.dr false high https://pixeldrain.com/api {7B6EA7F3-A02A-11EA-AAE6-9CC1A false unknown 2A860C6}.dat.1.dr https://accounts.firefox.com.cn/signup? firefox[1].htm.2.dr false 0%, Virustotal, Browse low entrypoint=mozilla.org- Avira URL Cloud: safe globalnav&form_type=button&utm_source= https://www.youtube.com chrome[1].htm.2.dr false high https://brave.com/wp-content/uploads/files_2019-11-