Automated Malware Analysis Report For
Total Page:16
File Type:pdf, Size:1020Kb
ID: 284663 Cookbook: browseurl.jbs Time: 21:18:59 Date: 11/09/2020 Version: 29.0.0 Ocean Jasper Table of Contents Table of Contents 2 Analysis Report https://webexfix.cabanova.com/index.html 4 Overview 4 General Information 4 Detection 4 Signatures 4 Classification 4 Startup 4 Malware Configuration 4 Yara Overview 4 Sigma Overview 4 Signature Overview 4 Phishing: 5 Mitre Att&ck Matrix 5 Behavior Graph 5 Screenshots 6 Thumbnails 6 Antivirus, Machine Learning and Genetic Malware Detection 7 Initial Sample 7 Dropped Files 7 Unpacked PE Files 7 Domains 7 URLs 7 Domains and IPs 8 Contacted Domains 8 URLs from Memory and Binaries 8 Contacted IPs 9 Public 9 General Information 9 Simulations 10 Behavior and APIs 10 Joe Sandbox View / Context 11 IPs 11 Domains 11 ASN 11 JA3 Fingerprints 11 Dropped Files 11 Created / dropped Files 11 Static File Info 21 No static file info 21 Network Behavior 21 Network Port Distribution 21 TCP Packets 21 UDP Packets 23 DNS Queries 24 DNS Answers 24 HTTPS Packets 24 Code Manipulations 26 Statistics 26 Behavior 26 System Behavior 27 Analysis Process: iexplore.exe PID: 3228 Parent PID: 808 27 General 27 File Activities 27 Registry Activities 27 Copyright null 2020 Page 2 of 28 Analysis Process: iexplore.exe PID: 6032 Parent PID: 3228 27 General 27 File Activities 28 Registry Activities 28 Disassembly 28 Copyright null 2020 Page 3 of 28 Analysis Report https://webexfix.cabanova.com/index.h…tml Overview General Information Detection Signatures Classification Sample URL: https://webexfix.caba nova.com/index.html PPhhiiisshhiiinngg ssiiitttee ddeettteeccttteedd (((bbaasseedd oonn llloogg… Analysis ID: 284663 HPHThTiMshLLi n bbgoo dsdyiyt e cc odonentttaeaiciinntses d llloo (wwb a nnsuuemdb boeenrrr loofffg … Most interesting Screenshot: HHTTMLL ttbtiiittotllleed ydd ocoeoesns t nanoionttt s m loaawtttcc hhn uUUmRRbLLer of Ransomware HTML title does not match URL HTML title does not match URL Miner Spreading mmaallliiiccciiioouusss malicious Evader Phishing sssuusssppiiiccciiioouusss suspicious cccllleeaann clean Exploiter Banker Spyware Trojan / Bot Adware Score: 21 Range: 0 - 100 Whitelisted: false Confidence: 80% Startup System is w10x64 iexplore.exe (PID: 3228 cmdline: 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding MD5: 6465CB92B25A7BC1DF8E01D8AC5E7596) iexplore.exe (PID: 6032 cmdline: 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:3228 CREDAT:17410 /prefetch:2 MD5: 071277CC2E3DF41EEEA8013E2AB58D5A) cleanup Malware Configuration No configs have been found Yara Overview No yara matches Sigma Overview No Sigma rule has matched Signature Overview Copyright null 2020 Page 4 of 28 • Phishing • Networking • System Summary Click to jump to signature section Phishing: Phishing site detected (based on logo template match) Mitre Att&ck Matrix Command Remote Initial Privilege Defense Credential Lateral and Network Service Access Execution Persistence Escalation Evasion Access Discovery Movement Collection Exfiltration Control Effects Effects Impact Valid Windows Path Process Masquerading 1 OS File and Remote Data from Exfiltration Encrypted Eavesdrop on Remotely Modify Accounts Management Interception Injection 1 Credential Directory Services Local Over Other Channel 2 Insecure Track Device System Instrumentation Dumping Discovery 1 System Network Network Without Partition Medium Communication Authorization Default Scheduled Boot or Boot or Process LSASS Application Remote Data from Exfiltration Non- Exploit SS7 to Remotely Device Accounts Task/Job Logon Logon Injection 1 Memory Window Desktop Removable Over Application Redirect Phone Wipe Data Lockout Initialization Initialization Discovery Protocol Media Bluetooth Layer Calls/SMS Without Scripts Scripts Protocol 1 Authorization Domain At (Linux) Logon Script Logon Obfuscated Files Security Query SMB/Windows Data from Automated Application Exploit SS7 to Obtain Delete Accounts (Windows) Script or Information Account Registry Admin Shares Network Exfiltration Layer Track Device Device Device (Windows) Manager Shared Protocol 2 Location Cloud Data Drive Backups Behavior Graph Copyright null 2020 Page 5 of 28 Hide Legend Behavior Graph Legend: ID: 284663 Process URL: https://webexfix.cabanova.c... Signature Startdate: 11/09/2020 Architecture: WINDOWS Created File Score: 21 DNS/IP Info Is Dropped Is Windows Process webexfix.cabanova.com Number of created Registry Values Number of created Files started Visual Basic Phishing site detected (based on logo template Delphi match) Java .Net C# or VB.NET C, C++ or other language iexplore.exe Is malicious Internet 12 85 started iexplore.exe 1 52 webexfix.cabanova.com sitebuilder.cabanova.com 94.130.246.164, 443, 49731, 49732 35.186.205.126, 443, 49740, 49741 HETZNER-ASDE GOOGLEUS Germany United States Screenshots Thumbnails This section contains all screenshots as thumbnails, including those not shown in the slideshow. Copyright null 2020 Page 6 of 28 Antivirus, Machine Learning and Genetic Malware Detection Initial Sample Source Detection Scanner Label Link https://webexfix.cabanova.com/index.html 0% Virustotal Browse https://webexfix.cabanova.com/index.html 0% Avira URL Cloud safe Dropped Files No Antivirus matches Unpacked PE Files No Antivirus matches Domains No Antivirus matches URLs Source Detection Scanner Label Link www.asual.com/swfaddress/ 1% Virustotal Browse www.asual.com/swfaddress/ 0% Avira URL Cloud safe delicious.com/save?v=5&noui&jump=close&url=__URL__ 0% Avira URL Cloud safe Copyright null 2020 Page 7 of 28 Source Detection Scanner Label Link https://delicious.com/save?v=5&noui&jump=close&url=__URL__ 0% Avira URL Cloud safe www.formspring.me/share?url=__URL__ 0% Avira URL Cloud safe https://www.google.%/ads/ga-audiences? 0% URL Reputation safe https://www.google.%/ads/ga-audiences? 0% URL Reputation safe https://www.google.%/ads/ga-audiences? 0% URL Reputation safe https://www.formspring.me/share?url=__URL__ 0% Avira URL Cloud safe www.wikipedia.com/ 0% Virustotal Browse www.wikipedia.com/ 0% URL Reputation safe www.wikipedia.com/ 0% URL Reputation safe www.wikipedia.com/ 0% URL Reputation safe Domains and IPs Contacted Domains Name IP Active Malicious Antivirus Detection Reputation webexfix.cabanova.com 94.130.246.164 true false high sitebuilder.cabanova.com 35.186.205.126 true false high URLs from Memory and Binaries Name Source Malicious Antivirus Detection Reputation www.asual.com/swfaddress/ swfaddress[1].js.3.dr false 1%, Virustotal, Browse unknown Avira URL Cloud: safe delicious.com/save? topbanner[1].js.3.dr false Avira URL Cloud: safe unknown v=5&noui&jump=close&url=__URL__ www.apache.org/licenses/LICENSE-2.0 webfont[1].js.3.dr false high twitter.com/share?original_referer=__URL__ topbanner[1].js.3.dr false high www.nytimes.com/ msapplication.xml4.2.dr false high https://use.typekit.net webfont[1].js.3.dr false high https://digg.com/submit?url=__URL__ render[1].js.3.dr false high https://webexfix.cabanova.com/index.htmlr ~DF6D521EADF3FB3866.TMP.2.dr false high https://webexfix.cabanova.com/index.htmlRoot {32304745-F4AF-11EA-90E2-ECF4B false high B862DED}.dat.2.dr https://delicious.com/save? render[1].js.3.dr false Avira URL Cloud: safe unknown v=5&noui&jump=close&url=__URL__ https://www.myspace.com/Modules/PostTo/Pages/? render[1].js.3.dr false high u=__URL__ https://www.blogger.com/blog_this.pyra? render[1].js.3.dr false high t=&u=__URL__?sms_ss=blogger&n=__URL__ www.amazon.com/ msapplication.xml.2.dr false high sitebuilder.cabanova.com/action/fallback?d= util[1].js.3.dr false high index[1].htm.3.dr false high https://sitebuilder.cabanova.com/action/form/html5/e157f5159 46ee6dd161a62e808261c82 www.formspring.me/share?url=__URL__ topbanner[1].js.3.dr false Avira URL Cloud: safe unknown www.twitter.com/ msapplication.xml6.2.dr false high digg.com/submit?url=__URL__ topbanner[1].js.3.dr false high www.blogger.com/blog_this.pyra?t=&u=__URL__? topbanner[1].js.3.dr false high sms_ss=blogger&n=__URL__ https://www.google.%/ads/ga-audiences? ga[1].js.3.dr false URL Reputation: safe low URL Reputation: safe URL Reputation: safe www.opensource.org/licenses/mit-license.php swfaddress[1].js.3.dr, swfobject2[1].js. false high 3.dr, common[1].js.3.dr https://www.formspring.me/share?url=__URL__ render[1].js.3.dr false Avira URL Cloud: safe unknown https://twitter.com/share?original_referer=__URL__ render[1].js.3.dr false high https://sitebuilder.cabanova.com/ index[1].htm.3.dr false high https://stats.g.doubleclick.net/j/collect? ga[1].js.3.dr false high www.linkedin.com/shareArticle?mini=true&url=__URL__ topbanner[1].js.3.dr false high www.stumbleupon.com/submit?url=__URL__ topbanner[1].js.3.dr false high www.youtube.com/ msapplication.xml8.2.dr false high https://www.linkedin.com/shareArticle? render[1].js.3.dr false high mini=true&url=__URL__ https://www.stumbleupon.com/submit?url=__URL__ render[1].js.3.dr false high Copyright null 2020 Page 8 of 28 Name Source Malicious Antivirus Detection Reputation www.wikipedia.com/ msapplication.xml7.2.dr false 0%, Virustotal, Browse unknown URL Reputation: safe URL Reputation: safe URL Reputation: safe sitebuilder.cabanova.com/action/topbanner/ topbanner[1].js.3.dr false high www.live.com/ msapplication.xml3.2.dr false high www.myspace.com/Modules/PostTo/Pages/? topbanner[1].js.3.dr false high u=__URL__ www.reddit.com/ msapplication.xml5.2.dr false high https://webexfix.cabanova.com/index.html ~DF6D521EADF3FB3866.TMP.2.dr false high Contacted IPs No. of IPs < 25% 25% < No. of IPs < 50% 50% < No. of IPs < 75% 75% < No. of IPs Public IP Country