Automated Malware Analysis Report for Unetbootin
Total Page:16
File Type:pdf, Size:1020Kb
ID: 236238 Sample Name: unetbootin- windows-677.exe Cookbook: default.jbs Time: 22:54:18 Date: 05/06/2020 Version: 29.0.0 Ocean Jasper Table of Contents Table of Contents 2 Analysis Report unetbootin-windows-677.exe 4 Overview 4 General Information 4 Detection 4 Signatures 4 Classification 4 Startup 4 Malware Configuration 4 Yara Overview 4 Sigma Overview 4 Signature Overview 4 Mitre Att&ck Matrix 5 Behavior Graph 5 Screenshots 6 Thumbnails 6 Antivirus, Machine Learning and Genetic Malware Detection 7 Initial Sample 7 Dropped Files 7 Unpacked PE Files 7 Domains 7 URLs 7 Domains and IPs 8 Contacted Domains 8 URLs from Memory and Binaries 8 Contacted IPs 14 General Information 14 Simulations 14 Behavior and APIs 14 Joe Sandbox View / Context 15 IPs 15 Domains 15 ASN 15 JA3 Fingerprints 15 Dropped Files 15 Created / dropped Files 15 Static File Info 15 General 15 File Icon 15 Static PE Info 16 General 16 Entrypoint Preview 16 Data Directories 17 Sections 17 Resources 17 Imports 18 Version Infos 18 Possible Origin 18 Network Behavior 18 Code Manipulations 18 Statistics 18 System Behavior 18 Analysis Process: unetbootin-windows-677.exe PID: 2212 Parent PID: 5460 18 General 18 Registry Activities 19 Key Created 19 Copyright null 2020 Page 2 of 19 Disassembly 19 Code Analysis 19 Copyright null 2020 Page 3 of 19 Analysis Report unetbootin-windows-677.exe Overview General Information Detection Signatures Classification Sample unetbootin-windows- Name: 677.exe SSaampplllee fffiiilllee iiiss ddiiiffffffeerrreennttt ttthhaann oorrriiiggiiinnaalll fff… MD5: 182b69a71a5b69… TSTrrariiiemessp tttloeo llflooilaead di s m diiisisfsfseiiinrneggn DDt LtLhLLassn original f Ransomware Miner Spreading SHA1: 9093e0e533a62e… Tries to load missing DLLs mmaallliiiccciiioouusss SHA256: malicious 7821b86a10b955… Evader Phishing sssuusssppiiiccciiioouusss suspicious Most interesting Screenshot: cccllleeaann clean Exploiter Banker Spyware Trojan / Bot Adware Score: 1 Range: 0 - 100 Whitelisted: false Confidence: 80% Startup System is w10x64 unetbootin-windows-677.exe (PID: 2212 cmdline: 'C:\Users\user\Desktop\unetbootin-windows-677.exe' MD5: 182B69A71A5B690A26ED562C8898F380) cleanup Malware Configuration No configs have been found Yara Overview No yara matches Sigma Overview No Sigma rule has matched Signature Overview • Networking Copyright null 2020 Page 4 of 19 • System Summary • Data Obfuscation • Hooking and other Techniques for Hiding and Protection • Malware Analysis System Evasion • HIPS / PFW / Operating System Protection Evasion Click to jump to signature section Mitre Att&ck Matrix Remote Initial Privilege Defense Credential Lateral Command Network Service Access Execution Persistence Escalation Evasion Access Discovery Movement Collection Exfiltration and Control Effects Effects Valid Graphical User Winlogon Process Software Credential Process Application Data from Data Data Eavesdrop on Remotely Accounts Interface 1 Helper DLL Injection 1 Packing 1 Dumping Discovery 1 Deployment Local Compressed Obfuscation Insecure Track Device Software System Network Without Communication Authorization Replication Service Port Accessibility Process Network Security Remote Data from Exfiltration Fallback Exploit SS7 to Remotely Through Execution Monitors Features Injection 1 Sniffing Software Services Removable Over Other Channels Redirect Phone Wipe Data Removable Discovery 1 Media Network Calls/SMS Without Media Medium Authorization External Windows Accessibility Path DLL Side- Input System Windows Data from Automated Custom Exploit SS7 to Obtain Remote Management Features Interception Loading 1 Capture Information Remote Network Exfiltration Cryptographic Track Device Device Services Instrumentation Discovery 1 Management Shared Protocol Location Cloud Drive Backups Drive-by Scheduled System DLL Search Obfuscated Credentials System Logon Input Data Multiband SIM Card Compromise Task Firmware Order Files or in Files Network Scripts Capture Encrypted Communication Swap Hijacking Information 1 Configuration Discovery Behavior Graph Copyright null 2020 Page 5 of 19 Hide Legend Legend: Process Signature Created File DNS/IP Info Is Dropped Is Windows Process Behavior Graph Number of created Registry Values Number of created Files ID: 236238 Visual Basic Sample: unetbootin-windows-677.exe Startdate: 05/06/2020 Delphi Architecture: WINDOWS Java Score: 1 .Net C# or VB.NET C, C++ or other language started Is malicious Internet unetbootin-windows-677.exe Screenshots Thumbnails This section contains all screenshots as thumbnails, including those not shown in the slideshow. No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version No bigger version Copyright null 2020 Page 6 of 19 Antivirus, Machine Learning and Genetic Malware Detection Initial Sample Source Detection Scanner Label Link unetbootin-windows-677.exe 3% Virustotal Browse unetbootin-windows-677.exe 5% Metadefender Browse unetbootin-windows-677.exe 6% ReversingLabs Dropped Files No Antivirus matches Unpacked PE Files No Antivirus matches Domains No Antivirus matches URLs Source Detection Scanner Label Link ftp.heanet.ie/pub/linuxmint.com/stable/%1/ 0% Avira URL Cloud safe unetbootin.sourceforge.netr) 0% Avira URL Cloud safe Copyright null 2020 Page 7 of 19 Source Detection Scanner Label Link www.slitaz.org/en 0% Virustotal Browse www.slitaz.org/en 0% Avira URL Cloud safe https://www.freedrweb.com/livecd 0% Virustotal Browse https://www.freedrweb.com/livecd 0% Avira URL Cloud safe https://www.sabayon.org 0% Virustotal Browse https://www.sabayon.org 0% Avira URL Cloud safe ftp.heanet.ie/mirrors/damnsmalllinux.org/current/ 0% Avira URL Cloud safe latestsalix.enialis.net/%1/salixlive%2-%3.iso 0% Avira URL Cloud safe gd.tuwien.ac.at/opsys/linux/damnsmall/current/ 0% Virustotal Browse gd.tuwien.ac.at/opsys/linux/damnsmall/current/ 0% Avira URL Cloud safe distro7site.org/distro-release-%1/distro-architecture%2.iso 0% Avira URL Cloud safe mirror.sov.uk.goscomb.net/linuxmint.com/stable/%1/ 0% Avira URL Cloud safe www.distro7site.org 0% Avira URL Cloud safe https://www.sabayon.org/ 0% Virustotal Browse https://www.sabayon.org/ 0% Avira URL Cloud safe ftp.surfnet.nl/pub/os/Linux/distr/dreamlinux/stable/ 0% Virustotal Browse ftp.surfnet.nl/pub/os/Linux/distr/dreamlinux/stable/ 0% Avira URL Cloud safe mirror.aarnet.edu.au/pub/SabayonLinux/iso/ 0% Avira URL Cloud safe www.gnewsense.org/ 0% Virustotal Browse www.gnewsense.org/ 0% Avira URL Cloud safe jukebox.linuxconsole.org/official/linuxconsole%1.isohttp://downloads.sourceforge.net/sourcefo 0% Avira URL Cloud safe mirror.yellowfiber.net/linuxmint/stable/%1/ 0% Avira URL Cloud safe https://linuxconsole.org 0% Avira URL Cloud safe https://linuxconsole.org/ 0% Avira URL Cloud safe download.tuxfamily.org/netbootcd/NetbootCD-current.iso 0% Avira URL Cloud safe www.distro2site.org 0% Avira URL Cloud safe cross-lfs.sabayonlinux.org/iso/ 0% Avira URL Cloud safe public.nimblex.net/Download/NimbleX-latest.iso 0% Avira URL Cloud safe distro6site.org/distro-release-%1/distro-architecture%2.iso 0% Avira URL Cloud safe hacktolive.org/download/os 1% Virustotal Browse hacktolive.org/download/os 0% Avira URL Cloud safe ftp.akl.lt/Linux/Mint/stable/%1/ 0% Avira URL Cloud safe cdimage.gnewsense.org/ 0% Virustotal Browse cdimage.gnewsense.org/ 0% Avira URL Cloud safe distro9site.org/distro-release-%1/distro-architecture%2.iso 0% Avira URL Cloud safe mirror.optus.net/linuxmint/isos/stable/%1/ 0% Avira URL Cloud safe mirror.umoss.org/sabayonlinux/iso/ 0% Avira URL Cloud safe elive.icedslash.com/isos/ 0% Avira URL Cloud safe www.distro1site.org 0% Avira URL Cloud safe elive.icedslash.com/isos/http://elive.leviathan-avc.com/http://elive.jumbef.net/http://elive. 0% Avira URL Cloud safe live.debian.net/cdimage/%1-builds/current/%2/debian-live-%1-%2-gnome-desktop.iso 0% Avira URL Cloud safe mirror.slitaz.org/iso/%1/ 0% Avira URL Cloud safe ftp.fsn.hu/pub/linux/distributions/sabayon/iso/ 0% Avira URL Cloud safe www.distro9site.org 0% Avira URL Cloud safe www.gnewsense.org 0% Virustotal Browse www.gnewsense.org 0% Avira URL Cloud safe Domains and IPs Contacted Domains No contacted domains info URLs from Memory and Binaries Name Source Malicious Antivirus Detection Reputation unetbootin-windows-677.exe, 00 false high distro.ibiblio.org/pub/linux/distributions/texstar/pclinuxos/live- 000000.00000002.1603677841.000 cd/english/preview/ 0000000E01000.00000040.0002000 0.sdmp Copyright null 2020 Page 8 of 19 Name Source Malicious Antivirus Detection Reputation ftp.heanet.ie/pub/linuxmint.com/stable/%1/ unetbootin-windows-677.exe, 00 false Avira URL Cloud: safe unknown 000000.00000002.1603677841.000 0000000E01000.00000040.0002000 0.sdmp ftp5.gwdg.de/pub/linux/debian/mint/stable/%1/ unetbootin-windows-677.exe, 00 false high 000000.00000002.1603677841.000 0000000E01000.00000040.0002000 0.sdmp unetbootin.sourceforge.netr) unetbootin-windows-677.exe false Avira URL Cloud: safe low www.slitaz.org/en unetbootin-windows-677.exe, 00 false 0%, Virustotal, Browse unknown 000000.00000002.1606054339.000 Avira URL Cloud: safe 0000003543000.00000004.0000000 1.sdmp https://www.freedrweb.com/livecd unetbootin-windows-677.exe, 00 false 0%, Virustotal, Browse unknown 000000.00000002.1606054339.000 Avira URL Cloud: safe 0000003543000.00000004.0000000 1.sdmp