Automated Malware Analysis Report For
Total Page:16
File Type:pdf, Size:1020Kb
ID: 432532 Cookbook: browseurl.jbs Time: 13:20:26 Date: 10/06/2021 Version: 32.0.0 Black Diamond Table of Contents Table of Contents 2 Analysis Report https://apkdownload.com/down_RHI-Magnesita- Gatherer/com.rhimagnesita.gatherer_mobile.html 3 Overview 3 General Information 3 Detection 3 Signatures 3 Classification 3 Process Tree 3 Malware Configuration 3 Yara Overview 3 Sigma Overview 3 Signature Overview 3 Mitre Att&ck Matrix 4 Behavior Graph 4 Screenshots 4 Thumbnails 4 Antivirus, Machine Learning and Genetic Malware Detection 5 Initial Sample 5 Dropped Files 5 Unpacked PE Files 5 Domains 6 URLs 6 Domains and IPs 7 Contacted Domains 7 URLs from Memory and Binaries 7 Contacted IPs 7 Public 7 General Information 7 Simulations 8 Behavior and APIs 8 Joe Sandbox View / Context 8 IPs 8 Domains 8 ASN 8 JA3 Fingerprints 8 Dropped Files 9 Created / dropped Files 9 Static File Info 32 No static file info 32 Network Behavior 32 Network Port Distribution 33 TCP Packets 33 UDP Packets 33 DNS Queries 33 DNS Answers 33 HTTPS Packets 34 Code Manipulations 35 Statistics 35 Behavior 35 System Behavior 36 Analysis Process: iexplore.exe PID: 4952 Parent PID: 792 36 General 36 File Activities 36 Registry Activities 36 Analysis Process: iexplore.exe PID: 4828 Parent PID: 4952 36 General 36 File Activities 36 Registry Activities 36 Disassembly 36 Copyright Joe Security LLC 2021 Page 2 of 36 Analysis Report https://apkdownload.com/down_RHI-M…agnesita-Gatherer/com.rhimagnesita.gatherer_mobile.html Overview General Information Detection Signatures Classification Sample URL: https://apkdownload. No high impact signatures. com/down_RHI-Magnesita -Gatherer/com.rhimagnesit a.gatherer_mobile.html Analysis ID: 432532 Infos: Ransomware Miner Spreading Most interesting Screenshot: mmaallliiiccciiioouusss malicious Evader Phishing sssuusssppiiiccciiioouusss suspicious cccllleeaann clean Exploiter Banker Spyware Trojan / Bot Adware Score: 0 Range: 0 - 100 Whitelisted: false Confidence: 80% Process Tree System is w10x64 iexplore.exe (PID: 4952 cmdline: 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding MD5: 6465CB92B25A7BC1DF8E01D8AC5E7596) iexplore.exe (PID: 4828 cmdline: 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:4952 CREDAT:17410 /prefetch:2 MD5: 071277CC2E3DF41EEEA8013E2AB58D5A) cleanup Malware Configuration No configs have been found Yara Overview No yara matches Sigma Overview No Sigma rule has matched Signature Overview Click to jump to signature section Copyright Joe Security LLC 2021 Page 3 of 36 There are no malicious signatures, click here to show all signatures . Mitre Att&ck Matrix Command Remote Initial Privilege Defense Credential Lateral and Network Service Access Execution Persistence Escalation Evasion Access Discovery Movement Collection Exfiltration Control Effects Effects Impact Valid Windows Path Process Masquerading 1 OS File and Remote Data from Exfiltration Encrypted Eavesdrop on Remotely Modify Accounts Management Interception Injection 1 Credential Directory Services Local Over Other Channel 2 Insecure Track Device System Instrumentation Dumping Discovery 1 System Network Network Without Partition Medium Communication Authorization Default Scheduled Boot or Boot or Process LSASS Application Remote Data from Exfiltration Non- Exploit SS7 to Remotely Device Accounts Task/Job Logon Logon Injection 1 Memory Window Desktop Removable Over Application Redirect Phone Wipe Data Lockout Initialization Initialization Discovery Protocol Media Bluetooth Layer Calls/SMS Without Scripts Scripts Protocol 1 Authorization Domain At (Linux) Logon Script Logon Obfuscated Files Security Query SMB/Windows Data from Automated Application Exploit SS7 to Obtain Delete Accounts (Windows) Script or Information Account Registry Admin Shares Network Exfiltration Layer Track Device Device Device (Windows) Manager Shared Protocol 2 Location Cloud Data Drive Backups Behavior Graph Hide Legend Behavior Graph Legend: ID: 432532 Process URL: https://apkdownload.com/dow... Signature Startdate: 10/06/2021 Created File Architecture: WINDOWS DNS/IP Info Score: 0 Is Dropped Is Windows Process Number of created Registry Values prda.aadg.msidentity.com apkdownload.com started Number of created Files Visual Basic Delphi iexplore.exe Java .Net C# or VB.NET C, C++ or other language 1 58 Is malicious Internet started iexplore.exe 5 121 play-lh.googleusercontent.com prod.pinterest.global.map.fastly.net 142.250.180.246, 443, 49738, 49739 151.101.0.84, 443, 49732, 49733 9 other IPs or domains GOOGLEUS FASTLYUS United States United States Screenshots Thumbnails This section contains all screenshots as thumbnails, including those not shown in the slideshow. Copyright Joe Security LLC 2021 Page 4 of 36 Antivirus, Machine Learning and Genetic Malware Detection Initial Sample Source Detection Scanner Label Link https://apkdownload.com/down_RHI-Magnesita-Gatherer/com.rhimagnesita.gatherer_mobile.html 0% Avira URL Cloud safe Dropped Files No Antivirus matches Unpacked PE Files No Antivirus matches Copyright Joe Security LLC 2021 Page 5 of 36 No Antivirus matches Domains Source Detection Scanner Label Link prod.pinterest.global.map.fastly.net 0% Virustotal Browse apkdownload.com 1% Virustotal Browse v1.addthisedge.com 1% Virustotal Browse z.moatads.com 2% Virustotal Browse URLs Source Detection Scanner Label Link https://apkdownload.com/Data-recovery-photo-recovery-amp-Video- 0% Avira URL Cloud safe recovery/com.fruita.view.alldatarecov https://apkdownload.com/Libra-Weight-Manager/net.cachapa.libra.html 0% Avira URL Cloud safe https://apkdownload.com/Hisn-Almuslim/com.islamix.hisnulmuslim.html 0% Avira URL Cloud safe https://apkdownload.com/Photo-Vault-PRIVARY-Hide-Photos-Videos-amp- 0% Avira URL Cloud safe Files/com.fourchars.privary.html https://apkdownload.com/Top-Anime-Wallpaper/com.ifuncreator.tanimewall.html 0% Avira URL Cloud safe https://apkdownload.com/wn_RHI-Magnesita-Gatherer/com.rhimagnesita.gatherer_mobile.html 0% Avira URL Cloud safe https://apkdownload.com/Disk-Video-Recovery-Pro/com.app.diskdoggervideopro.html 0% Avira URL Cloud safe https://apkdownload.com/PDF-Reader-amp-PDF-Viewer-eBook-Reader-PDF- 0% Avira URL Cloud safe Editor/com.ascal.pdfreader.pdfvie https://apkdownload.com/Kung-Fu-Ninja-Fighting-Shadow-Tiger-Karate- 0% Avira URL Cloud safe Games/com.sgs.Kungfu.ninja.html https://apkdownload.com/Dead-Empire-Zombie-War/com.tap4fun.invasion_zombie.gplay.html 0% Avira URL Cloud safe https://apkdownload.com/down_RHI-Magnesita- 0% Avira URL Cloud safe Gatherer/com.rhimagnesita.gatherer_mobile.htmlXRHI https://apkdownload.com/Song-Lyrics-Music-Free/com.rubenpsaav.song.lyrics.music.free.html 0% Avira URL Cloud safe https://apkdownload.com/WadZee/com.wadzee.video.html 0% Avira URL Cloud safe https://apkdownload.com/Voice-Recorder-HD/eapps.pro.voicerecorder.html 0% Avira URL Cloud safe https://apkdownload.com/Panda-Emoji/com.sayhi.plugin.pandada.html 0% Avira URL Cloud safe https://apkdownload.com/Stupid-Zombies/com.gameresort.stupidzombies.html 0% Avira URL Cloud safe https://apkdownload.com/WeightWar-Weight-Loss/com.dencreak.weightwar.html 0% Avira URL Cloud safe https://apkdownload.com/down_Ninja-Tobu/com.cerebralfix.ninjatobu.9887329.html 0% Avira URL Cloud safe https://apkdownload.com/Casanaretrade/xyz.appmaker.dvfqmk.html 0% Avira URL Cloud safe https://apkdownload.com/Chegg-Study-Homework-Help/com.chegg.html 0% Avira URL Cloud safe https://apkdownload.com/McDonald-39s-Portugal/pt.mcdonalds.html 0% Avira URL Cloud safe https://apkdownload.com/down_Ninja-Tobu/com.cerebralfix.ninjatobu.9400757.html 0% Avira URL Cloud safe https://apkdownload.com/2byCate.FINANCE_1 0% Avira URL Cloud safe https://apkdownload.com/down_Ninja-Tobu/com.cerebralfix.ninjatobu.7931469.html 0% Avira URL Cloud safe https://apkdownload.com/Photo-Comics-Super-Stickers/com.keyspice.photocomics.html 0% Avira URL Cloud safe https://apkdownload.com/AlMosaly-prayer-times-app-qibla-quran-in-Ramadan/com.moslay.html 0% Avira URL Cloud safe https://apkdownload.com/180-Caller-ID-amp-Block/com.opplysning180.no.html 0% Avira URL Cloud safe https://apkdownload.com/TQmart 0% Avira URL Cloud safe https://apkdownload.com/Magi-Magic-Video-Editor/com.video.cameramagic.html 0% Avira URL Cloud safe https://apkdownload.com/Defense-Table/com.EmpyupyuCo.DefenseTable.html 0% Avira URL Cloud safe https://apkdownload.com/Meme-Creator/com.gentoozero.memecreator.html 0% Avira URL Cloud safe https://apkdownload.com/Learn-French-free-for- 0% Avira URL Cloud safe beginners/com.gonliapps.learnfrenchfree.game.html https://apkdownload.com/Wood-Shop/com.HeroGames.WoodShop.html 0% Avira URL Cloud safe https://apkdownload.com/1byUD.2021-06-03_1 0% Avira URL Cloud safe https://apkdownload.com/FutureSeer-Aging-App-Gender-Swap-Palm- 0% Avira URL Cloud safe Scanner/com.future.me.palmreader.html https://apkdownload.com/Lock-Hot-Girl-School/com.HotGirlGame.SchoolOpenWindow.html 0% Avira URL Cloud safe https://apkdownload.com/XOS-Launcher-2020-Customized-Cool- 0% Avira URL Cloud safe Stylish/com.transsion.XOSLauncher.html https://apkdownload.com/Comi/com.comicola.app.html 0% Avira URL Cloud safe https://apkdownload.com/Pull-The-Pin-Games-Pin- 0% Avira URL Cloud safe Puzzle/com.rescuethegirl.pullpin.herorescue.savethegi https://apkdownload.com/1byFUD.2021-04_1 0% Avira URL Cloud safe https://apkdownload.com/JokesPhone-Joke-Calls/com.cashitapp.app.jokesphone.html 0% Avira URL Cloud safe https://apkdownload.com/The-Sims-Mobile/com.ea.gp.simsmobile.html 0% Avira URL Cloud safe https://apkdownload.com/1byUD.2018-05-23_1