Automated Malware Analysis Report for Keepassxc-2.5.4-Win64.Msi
Total Page:16
File Type:pdf, Size:1020Kb
ID: 228573 Sample Name: KeePassXC- 2.5.4-Win64.msi Cookbook: default.jbs Time: 13:23:43 Date: 08/05/2020 Version: 28.0.0 Lapis Lazuli Table of Contents Table of Contents 2 Analysis Report KeePassXC-2.5.4-Win64.msi 5 Overview 5 General Information 5 Detection 5 Confidence 6 Classification Spiderchart 6 Analysis Advice 6 Mitre Att&ck Matrix 7 Signature Overview 7 Spreading: 7 Networking: 7 System Summary: 8 Persistence and Installation Behavior: 8 Hooking and other Techniques for Hiding and Protection: 8 Malware Analysis System Evasion: 8 Anti Debugging: 8 HIPS / PFW / Operating System Protection Evasion: 8 Language, Device and Operating System Detection: 8 Malware Configuration 8 Behavior Graph 9 Simulations 9 Behavior and APIs 9 Antivirus, Machine Learning and Genetic Malware Detection 9 Initial Sample 9 Dropped Files 9 Unpacked PE Files 10 Domains 10 URLs 10 Yara Overview 10 Initial Sample 10 PCAP (Network Traffic) 10 Dropped Files 10 Memory Dumps 10 Unpacked PEs 10 Sigma Overview 10 Joe Sandbox View / Context 10 IPs 11 Domains 11 ASN 11 JA3 Fingerprints 11 Dropped Files 11 Screenshots 11 Thumbnails 11 Startup 12 Created / dropped Files 12 Domains and IPs 14 Contacted Domains 14 URLs from Memory and Binaries 14 Contacted IPs 16 Static File Info 16 General 16 File Icon 16 Static OLE Info 16 General 16 Authenticode Signature 16 OLE File "KeePassXC-2.5.4-Win64.msi" 17 Indicators 17 Summary 17 Copyright Joe Security LLC 2020 Page 2 of 32 Streams 17 Stream Path: \x5DigitalSignature, File Type: data, Stream Size: 8615 17 General 17 Stream Path: \x5MsiDigitalSignatureEx, File Type: data, Stream Size: 32 17 General 17 Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 532 17 General 18 Stream Path: \x16786\x17522\x15998\x17589\x17959\x17894\x16786\x17522\x17214\x17574, File Type: MS Windows icon resource - 7 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel, Stream Size: 125408 18 General 18 Stream Path: \x16944\x17191\x14436\x16830\x16740, File Type: Microsoft Cabinet archive data, 43194054 bytes, 363 files, Stream Size: 43194054 18 General 18 Stream Path: \x17163\x16689\x18229\x16446\x18156\x14988, File Type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, Stream Size: 216496 18 General 18 Stream Path: \x17163\x16689\x18229\x16446\x18156\x15518\x15103\x17648\x15103\x17508\x16945\x18485, File Type: PC bitmap, Windows 3.x format, 493 x 58 x 24, Stream Size: 85894 18 General 19 Stream Path: \x17163\x16689\x18229\x16446\x18156\x15518\x15103\x17648\x15231\x16684\x17583\x18474, File Type: PC bitmap, Windows 3.x format, 493 x 312 x 24, Stream Size: 461814 19 General 19 Stream Path: \x17163\x16689\x18229\x16446\x18156\x15518\x15103\x17648\x15871\x18088, File Type: MS Windows icon resource - 1 icon, 16x16, 16 colors, Stream Size: 318 General 1919 Stream Path: \x17163\x16689\x18229\x16446\x18156\x15518\x15103\x17648\x16319\x18483, File Type: MS Windows icon resource - 1 icon, 16x16, 16 colors, Stream Size: 318 General 1919 Stream Path: \x17163\x16689\x18229\x16446\x18156\x15518\x15551\x17574\x15295\x16827\x16687\x18480, File Type: MS Windows icon resource - 1 icon, 32x32, 16 colors, Stream Size: 766 20 General 20 Stream Path: \x17163\x16689\x18229\x16446\x18156\x15518\x15551\x17574\x15551\x17009\x18482, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 16x16, 16 colors, Stream Size: 1078 20 General 20 Stream Path: \x17163\x16689\x18229\x16446\x18156\x15518\x17184\x16827\x18468, File Type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, Stream Size: 116144 General 2020 Stream Path: \x18496\x15167\x17394\x17464\x17841, File Type: data, Stream Size: 1496 20 General 20 Stream Path: \x18496\x15518\x16925\x17915, File Type: data, Stream Size: 204 21 General 21 Stream Path: \x18496\x16191\x17783\x17516\x15210\x17892\x18468, File Type: ASCII text, with very long lines, with CRLF, LF line terminators, Stream Size: 106181 21 General 21 Stream Path: \x18496\x16191\x17783\x17516\x15978\x17586\x18479, File Type: data, Stream Size: 9488 21 General 21 Stream Path: \x18496\x16255\x16740\x16943\x18486, File Type: data, Stream Size: 72 21 General 21 Stream Path: \x18496\x16383\x17380\x16876\x17892\x17580\x18481, File Type: data, Stream Size: 4536 21 General 21 Stream Path: \x18496\x16661\x17528\x17126\x17548\x16881\x17900\x17580\x18481, File Type: ISO-8859 text, with no line terminators, with overstriking, Stream Size: 4 22 General 22 Stream Path: \x18496\x16667\x17191\x15090\x17912\x17591\x18481, File Type: VAX-order 68k Blit mpx/mux executable, Stream Size: 36 22 General 22 Stream Path: \x18496\x16786\x17522, File Type: Applesoft BASIC program data, first line number 1, Stream Size: 4 22 General 22 Stream Path: \x18496\x16842\x17200\x15281\x16955\x17958\x16951\x16924\x17972\x17512\x16934, File Type: data, Stream Size: 48 22 General 22 Stream Path: \x18496\x16842\x17200\x16305\x16146\x17704\x16952\x16817\x18472, File Type: data, Stream Size: 42 22 General 22 Stream Path: \x18496\x16842\x17913\x18126\x16808\x17912\x16168\x17704\x16952\x16817\x18472, File Type: data, Stream Size: 48 23 General 23 Stream Path: \x18496\x16911\x17892\x17784\x15144\x17458\x17587\x16945\x17905\x18486, File Type: data, Stream Size: 1460 23 General 23 Stream Path: \x18496\x16911\x17892\x17784\x18472, File Type: data, Stream Size: 16 23 General 23 Stream Path: \x18496\x16918\x17191\x18468, File Type: MIPSEB Ucode, Stream Size: 14 23 General 23 Stream Path: \x18496\x16923\x15722\x16818\x17892\x17778, File Type: data, Stream Size: 10 23 General 23 Stream Path: \x18496\x16923\x17194\x17910\x18229, File Type: 370 sysV executable, Stream Size: 84 24 General 24 Stream Path: \x18496\x16923\x17584\x16953\x17167\x16943, File Type: data, Stream Size: 10 24 General 24 Stream Path: \x18496\x16925\x17915\x17884\x17404\x18472, File Type: data, Stream Size: 36 24 General 24 Stream Path: \x18496\x17100\x16808\x15086\x18162, File Type: data, Stream Size: 8 24 General 24 Stream Path: \x18496\x17116\x17778\x16823\x17912, File Type: data, Stream Size: 32 24 General 24 Stream Path: \x18496\x17163\x16689\x18229, File Type: data, Stream Size: 32 24 General 24 Stream Path: \x18496\x17165\x16949\x17894\x17778\x18492, File Type: data, Stream Size: 312 25 General 25 Stream Path: \x18496\x17165\x17380\x17074, File Type: data, Stream Size: 484 25 General 25 Stream Path: \x18496\x17167\x16943, File Type: data, Stream Size: 7260 25 General 25 Stream Path: \x18496\x17490\x17910\x17380\x15279\x16955\x17958\x16951\x16924\x17972\x17512\x16934, File Type: data, Stream Size: 186 25 General 25 Stream Path: \x18496\x17490\x17910\x17380\x16303\x16146\x17704\x16952\x16817\x18472, File Type: data, Stream Size: 108 26 General 26 Stream Path: \x18496\x17548\x17648\x17522\x17512\x18487, File Type: 370 XA sysV pure executable not stripped, Stream Size: 4380 26 General 26 Stream Path: \x18496\x17548\x17905\x17589\x15151\x17522\x17191\x17207\x17522, File Type: x86 executable not stripped, Stream Size: 504 26 General 26 Stream Path: \x18496\x17548\x17905\x17589\x15279\x16953\x17905, File Type: data, Stream Size: 1548 26 General 26 Stream Path: \x18496\x17548\x17905\x17589\x18479, File Type: data, Stream Size: 5590 27 Copyright Joe Security LLC 2020 Page 3 of 32 General 27 Stream Path: \x18496\x17610\x16179\x16680\x16821\x18475, File Type: data, Stream Size: 4 27 General 27 Stream Path: \x18496\x17630\x17770\x16868\x18472, File Type: data, Stream Size: 32 27 General 27 Stream Path: \x18496\x17740\x16680\x16951\x17551\x16879\x17768, File Type: data, Stream Size: 4 27 General 27 Stream Path: \x18496\x17753\x17650\x17768\x18231, File Type: data, Stream Size: 84 27 General 27 Stream Path: \x18496\x17814\x15340\x17388\x15464\x17828\x18475, File Type: data, Stream Size: 6660 28 General 28 Stream Path: \x18496\x17932\x17910\x17458\x16778\x17207\x17522, File Type: data, Stream Size: 96 28 General 28 Stream Path: \x18496\x17998\x17512\x15799\x17636\x17203\x17073, File Type: data, Stream Size: 40 28 General 28 Network Behavior 28 Code Manipulations 28 Statistics 28 Behavior 28 System Behavior 29 Analysis Process: msiexec.exe PID: 5148 Parent PID: 5500 29 General 29 File Activities 29 Registry Activities 29 Analysis Process: msiexec.exe PID: 5648 Parent PID: 1108 29 General 29 File Activities 30 Analysis Process: msiexec.exe PID: 5908 Parent PID: 1108 30 General 30 File Activities 30 Analysis Process: taskkill.exe PID: 5952 Parent PID: 5908 30 General 30 File Activities 30 Analysis Process: conhost.exe PID: 5968 Parent PID: 5952 31 General 31 Analysis Process: taskkill.exe PID: 5324 Parent PID: 5908 31 General 31 File Activities 31 Analysis Process: conhost.exe PID: 5172 Parent PID: 5324 31 General 31 Analysis Process: KeePassXC.exe PID: 3976 Parent PID: 5648 31 General 31 File Activities 32 Disassembly 32 Code Analysis 32 Copyright Joe Security LLC 2020 Page 4 of 32 Analysis Report KeePassXC-2.5.4-Win64.msi Overview General Information Joe Sandbox Version: 28.0.0 Lapis Lazuli Analysis ID: 228573 Start date: 08.05.2020 Start time: 13:23:43 Joe Sandbox Product: CloudBasic Overall analysis duration: 0h 7m 9s Hypervisor based Inspection enabled: false Report type: light Sample file name: KeePassXC-2.5.4-Win64.msi Cookbook file name: default.jbs Analysis system description: Windows 10 64 bit (version 1803) with Office 2016, Adobe Reader DC 19, Chrome 70, Firefox 63, Java 8.171, Flash 30.0.0.113 Number of analysed new started processes analysed: 11 Number of new started drivers analysed: 0 Number of existing processes analysed: 0 Number of existing drivers analysed: 0 Number of injected processes analysed: 0 Technologies: HCA enabled EGA enabled HDC enabled AMSI enabled Analysis Mode: default Analysis stop reason: Timeout Detection: CLEAN Classification: clean2.winMSI@11/5@0/0 EGA Information: Successful, ratio: 50% HDC Information: Failed HCA Information: Failed Cookbook Comments: Adjust boot time Enable AMSI Found application associated with file extension: .msi Warnings: Show All Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe Report size getting too big, too many NtOpenKeyEx calls found.