Automated Malware Analysis Report For
Total Page:16
File Type:pdf, Size:1020Kb
ID: 402013 Cookbook: browseurl.jbs Time: 11:41:48 Date: 01/05/2021 Version: 32.0.0 Black Diamond Table of Contents Table of Contents 2 Analysis Report https://managebooking.reservanto.cz/Account/SecretKey? type=NewAccount&secretKey=3d428529-925c-4bc2-8634-dfe869521dd8 4 Overview 4 General Information 4 Detection 4 Signatures 4 Classification 4 Startup 4 Malware Configuration 4 Yara Overview 4 Sigma Overview 4 Signature Overview 4 Mitre Att&ck Matrix 5 Behavior Graph 5 Screenshots 6 Thumbnails 6 Antivirus, Machine Learning and Genetic Malware Detection 7 Initial Sample 7 Dropped Files 7 Unpacked PE Files 7 Domains 7 URLs 7 Domains and IPs 8 Contacted Domains 8 Contacted URLs 8 URLs from Memory and Binaries 9 Contacted IPs 9 Public 10 General Information 10 Simulations 11 Behavior and APIs 11 Joe Sandbox View / Context 11 IPs 11 Domains 11 ASN 12 JA3 Fingerprints 12 Dropped Files 12 Created / dropped Files 12 Static File Info 43 No static file info 43 Network Behavior 43 Network Port Distribution 43 TCP Packets 44 UDP Packets 45 DNS Queries 47 DNS Answers 48 HTTPS Packets 49 Code Manipulations 55 Statistics 55 Behavior 55 System Behavior 55 Analysis Process: iexplore.exe PID: 3728 Parent PID: 792 55 General 55 Copyright Joe Security LLC 2021 Page 2 of 56 File Activities 55 Registry Activities 56 Analysis Process: iexplore.exe PID: 68 Parent PID: 3728 56 General 56 File Activities 56 Registry Activities 56 Disassembly 56 Copyright Joe Security LLC 2021 Page 3 of 56 Analysis Report https://managebooking.reservanto.cz/A…ccount/SecretKey?type=NewAccount&secretKey=3d428529-925c-4bc2-8634-dfe869521dd8 Overview General Information Detection Signatures Classification Sample URL: https://managebooki ng.reservanto.cz/Account/ HHTTMLL bbooddyy ccoonntttaaiiinnss lllooww nnuumbbeerrr oofff … SecretKey?type=NewAcco HTML body contains low number of unt&secretKey=3d428529- 925c-4bc2-8634-dfe86952 1dd8 Ransomware Analysis ID: 402013 Miner Spreading Infos: mmaallliiiccciiioouusss malicious Evader Phishing sssuusssppiiiccciiioouusss Most interesting Screenshot: suspicious cccllleeaann clean Exploiter Banker Spyware Trojan / Bot Adware Score: 0 Range: 0 - 100 Whitelisted: false Confidence: 80% Startup System is w10x64 iexplore.exe (PID: 3728 cmdline: 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding MD5: 6465CB92B25A7BC1DF8E01D8AC5E7596) iexplore.exe (PID: 68 cmdline: 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:3728 CREDAT:17410 /prefetch:2 MD5: 071277CC2E3DF41EEEA8013E2AB58D5A) cleanup Malware Configuration No configs have been found Yara Overview No yara matches Sigma Overview No Sigma rule has matched Signature Overview Copyright Joe Security LLC 2021 Page 4 of 56 • Phishing • Compliance • Networking • System Summary Click to jump to signature section There are no malicious signatures, click here to show all signatures . Mitre Att&ck Matrix Command Remote Initial Privilege Defense Credential Lateral and Network Service Access Execution Persistence Escalation Evasion Access Discovery Movement Collection Exfiltration Control Effects Effects Impact Valid Windows Path Process Masquerading 1 OS File and Remote Data from Exfiltration Encrypted Eavesdrop on Remotely Modify Accounts Management Interception Injection 1 Credential Directory Services Local Over Other Channel 2 Insecure Track Device System Instrumentation Dumping Discovery 1 System Network Network Without Partition Medium Communication Authorization Default Scheduled Boot or Boot or Process LSASS Application Remote Data from Exfiltration Non- Exploit SS7 to Remotely Device Accounts Task/Job Logon Logon Injection 1 Memory Window Desktop Removable Over Application Redirect Phone Wipe Data Lockout Initialization Initialization Discovery Protocol Media Bluetooth Layer Calls/SMS Without Scripts Scripts Protocol 1 Authorization Domain At (Linux) Logon Script Logon Obfuscated Files Security Query SMB/Windows Data from Automated Application Exploit SS7 to Obtain Delete Accounts (Windows) Script or Information Account Registry Admin Shares Network Exfiltration Layer Track Device Device Device (Windows) Manager Shared Protocol 2 Location Cloud Data Drive Backups Behavior Graph Copyright Joe Security LLC 2021 Page 5 of 56 Hide Legend Behavior Graph Legend: ID: 402013 Process URL: https://managebooking.reser... Signature Startdate: 01/05/2021 Created File Architecture: WINDOWS DNS/IP Info Score: 0 Is Dropped Is Windows Process Number of created Registry Values managebooking.reservanto.cz started Number of created Files Visual Basic Delphi iexplore.exe Java .Net C# or VB.NET C, C++ or other language 2 62 Is malicious Internet started iexplore.exe 7 127 managebooking.reservanto.cz c.seznam.cz 217.16.185.201, 443, 49720, 49721 77.75.78.60, 443, 49761, 49762 21 other IPs or domains VSHOSTINGCZ SEZNAM-CZ Czech Republic Czech Republic Screenshots Thumbnails This section contains all screenshots as thumbnails, including those not shown in the slideshow. Copyright Joe Security LLC 2021 Page 6 of 56 Antivirus, Machine Learning and Genetic Malware Detection Initial Sample Source Detection Scanner Label Link https://managebooking.reservanto.cz/Account/SecretKey? 0% Avira URL Cloud safe type=NewAccount&secretKey=3d428529-925c-4bc2-8634-dfe869521dd8 Dropped Files No Antivirus matches Unpacked PE Files No Antivirus matches Domains Source Detection Scanner Label Link booking.reservanto.cz 0% Virustotal Browse sni1gl.wpc.gammacdn.net 0% Virustotal Browse 1610534878.rsc.cdn77.org 0% Virustotal Browse 1746822127.rsc.cdn77.org 1% Virustotal Browse URLs Copyright Joe Security LLC 2021 Page 7 of 56 Source Detection Scanner Label Link https://managebooking.reservanto.cz/favicon.ico 0% Avira URL Cloud safe https://www.reservanto.cz 0% Avira URL Cloud safe https://merchant.reservanto.cz/Content/Settings/016000/16503/4269/51e4a9a7-b660-4911-81e8- 0% Avira URL Cloud safe dd3d825966 https://booking.reservanto.cz/favicon.ico 0% Avira URL Cloud safe https://www.reservanto.cz/Stranka/Bonus-1-100-Kc 0% Avira URL Cloud safe https://booking.reservanto.cz/Modal?id=16503cretKey?type=NewAccount&secretKey=3d428529- 0% Avira URL Cloud safe 925c-4bc2-863 https://www.reservanto.cz/anto.cz/Account/SecretKey?type=NewAccount&secretKey=3d428529- 0% Avira URL Cloud safe 925c-4bc2-863 https://www.pays.cz 0% Avira URL Cloud safe https://cct.google/taggy/agent.js 0% URL Reputation safe https://cct.google/taggy/agent.js 0% URL Reputation safe https://cct.google/taggy/agent.js 0% URL Reputation safe https://booking.reservanto.cz/Modal?id=16503z 0% Avira URL Cloud safe https://managebooking.reservanto.cz/favicon.ico~ 0% Avira URL Cloud safe https://managebooking.reservanto.cz/Account/SecretKey? 0% Avira URL Cloud safe type=NewAccount&secretKey=3d428529-925c-4bc2-8 https://www.google.%/ads/ga-audiences 0% URL Reputation safe https://www.google.%/ads/ga-audiences 0% URL Reputation safe https://www.google.%/ads/ga-audiences 0% URL Reputation safe https://booking.reservanto.cz/favicon.ico~ 0% Avira URL Cloud safe https://www.reservanto.cz/favicon.ico~ 0% Avira URL Cloud safe https://www.reservanto.cz/favicon.ico 0% Avira URL Cloud safe https://booking.reserv 0% Avira URL Cloud safe https://booking.reservanto.cz/Modal?id=16503:Online 0% Avira URL Cloud safe https://blog.reservanto.cz 0% Avira URL Cloud safe https://www.reservanto.cz/Files/TeamViewerQS-idcrksttc8.exe 0% Avira URL Cloud safe https://merchant.reservanto.cz 0% Avira URL Cloud safe Domains and IPs Contacted Domains Name IP Active Malicious Antivirus Detection Reputation www.google.de 142.250.186.35 true false high booking.reservanto.cz 217.16.185.201 true false 0%, Virustotal, Browse unknown sni1gl.wpc.gammacdn.net 152.199.21.175 true false 0%, Virustotal, Browse unknown 1610534878.rsc.cdn77.org 89.187.165.7 true false 0%, Virustotal, Browse unknown stats.l.doubleclick.net 173.194.76.155 true false high c.seznam.cz 77.75.78.60 true false high 1746822127.rsc.cdn77.org 89.187.165.7 true false 1%, Virustotal, Browse unknown merchant.reservanto.cz 217.16.185.201 true false unknown www.reservanto.cz 217.16.185.201 true false unknown managebooking.reservanto.cz 217.16.185.201 true false unknown googleads.g.doubleclick.net 142.250.185.226 true false high websocket-visitors.smartsupp.com 35.158.253.187 true false high c.imedia.cz 77.75.79.33 true false high bootstrap.smartsuppchat.com 3.120.69.250 true false unknown 1161431244.rsc.cdn77.org 89.187.165.8 true false unknown widget-v2.smartsuppcdn.com unknown unknown false unknown rec.smartlook.com unknown unknown false high stats.g.doubleclick.net unknown unknown false high www.smartsuppchat.com unknown unknown false unknown dc.services.visualstudio.com unknown unknown false high Contacted URLs Name Malicious Antivirus Detection Reputation https://www.reservanto.cz/ false unknown https://booking.reservanto.cz/Modal?id=16503 false unknown https://managebooking.reservanto.cz/Account/SecretKey? false unknown type=NewAccount&secretKey=3d428529-925c-4bc2-8634-dfe869521dd8 Copyright Joe Security LLC 2021 Page 8 of 56 URLs from Memory and Binaries Name Source Malicious Antivirus Detection Reputation www.twitter.com/reservanto 2GXCYCVG.htm.3.dr false high dev.jquery.com/ticket/2752) modal[1].js.3.dr false high https://managebooking.reservanto.cz/favicon.ico imagestore.dat.3.dr false Avira URL Cloud: safe unknown https://www.reservanto.cz SecretKey[1].htm.3.dr false Avira URL Cloud: safe unknown https://rec.smartlook.com/recorder.js 809ce55600814ee47cbdb82a46a165 false high 4879a9375f[1].json.3.dr, 2GXCY CVG.htm.3.dr www.inkscape.org/)