Resubmissions

02-07-2024 20:34

240702-zch3msxhlc 4

02-07-2024 20:33

240702-zbzn1axhja 4

Analysis

  • max time kernel
    21s
  • max time network
    13s
  • platform
    ubuntu-20.04_amd64
  • resource
    ubuntu2004-amd64-20240508-en
  • resource tags

    arch:amd64arch:i386image:ubuntu2004-amd64-20240508-enkernel:5.4.0-169-genericlocale:en-usos:ubuntu-20.04-amd64system
  • submitted
    02-07-2024 20:34

General

  • Target

    http://108.174.58.28/exploit

Score
4/10

Malware Config

Signatures

  • Changes its process name 64 IoCs
  • Checks CPU configuration 1 TTPs 1 IoCs

    Checks CPU information which indicate if the system is a virtual machine.

  • Reads CPU attributes 1 TTPs 12 IoCs
  • Enumerates kernel/hardware configuration 1 TTPs 64 IoCs

    Reads contents of /sys virtual filesystem to enumerate system information.

  • Reads runtime system information 64 IoCs

    Reads data from /proc virtual filesystem.

  • Writes file to tmp directory 2 IoCs

    Malware often drops required files in the /tmp directory.

Processes

  • /usr/bin/firefox
    firefox -new-tab http://108.174.58.28/exploit
    1⤵
      PID:1404
      • /usr/bin/which
        which /usr/bin/firefox
        2⤵
          PID:1405
      • /usr/lib/firefox/firefox
        /usr/lib/firefox/firefox -new-tab http://108.174.58.28/exploit
        1⤵
        • Checks CPU configuration
        • Reads CPU attributes
        • Enumerates kernel/hardware configuration
        • Reads runtime system information
        • Writes file to tmp directory
        PID:1404
        • /usr/local/sbin/dbus-launch
          dbus-launch "--autolaunch=4816dd152e8c48ff97e9117d197c13d8" --binary-syntax --close-stderr
          2⤵
            PID:1448
          • /usr/local/bin/dbus-launch
            dbus-launch "--autolaunch=4816dd152e8c48ff97e9117d197c13d8" --binary-syntax --close-stderr
            2⤵
              PID:1448
            • /usr/sbin/dbus-launch
              dbus-launch "--autolaunch=4816dd152e8c48ff97e9117d197c13d8" --binary-syntax --close-stderr
              2⤵
                PID:1448
              • /usr/bin/dbus-launch
                dbus-launch "--autolaunch=4816dd152e8c48ff97e9117d197c13d8" --binary-syntax --close-stderr
                2⤵
                  PID:1448
                  • /usr/bin/dbus-daemon
                    /usr/bin/dbus-daemon --syslog-only --fork --print-pid 5 --print-address 7 --session
                    3⤵
                    • Enumerates kernel/hardware configuration
                    • Reads runtime system information
                    PID:1450
                    • /usr/libexec/xdg-desktop-portal
                      /usr/libexec/xdg-desktop-portal
                      4⤵
                        PID:1492
                      • /usr/libexec/xdg-document-portal
                        /usr/libexec/xdg-document-portal
                        4⤵
                        • Reads runtime system information
                        PID:1497
                      • /usr/libexec/xdg-permission-store
                        /usr/libexec/xdg-permission-store
                        4⤵
                        • Reads runtime system information
                        PID:1503
                      • /usr/libexec/xdg-desktop-portal-gtk
                        /usr/libexec/xdg-desktop-portal-gtk
                        4⤵
                        • Reads runtime system information
                        PID:1512
                      • /usr/libexec/gvfsd
                        /usr/libexec/gvfsd
                        4⤵
                        • Reads runtime system information
                        PID:1516
                        • /usr/libexec/gvfsd-trash
                          /usr/libexec/gvfsd-trash --spawner :1.6 /org/gtk/gvfs/exec_spaw/0
                          5⤵
                          • Reads runtime system information
                          PID:1548
                      • /usr/libexec/dconf-service
                        /usr/libexec/dconf-service
                        4⤵
                        • Reads runtime system information
                        PID:1539
                      • /usr/bin/nautilus
                        /usr/bin/nautilus --gapplication-service
                        4⤵
                        • Reads CPU attributes
                        PID:1545
                  • /usr/lib/firefox/glxtest
                    /usr/lib/firefox/glxtest -f 13
                    2⤵
                    • Enumerates kernel/hardware configuration
                    • Reads runtime system information
                    PID:1455
                  • /usr/bin/lsb_release
                    /usr/bin/lsb_release -idrc
                    2⤵
                      PID:1467
                    • /usr/local/sbin/dbus-launch
                      dbus-launch "--autolaunch=4816dd152e8c48ff97e9117d197c13d8" --binary-syntax --close-stderr
                      2⤵
                        PID:1477
                      • /usr/local/bin/dbus-launch
                        dbus-launch "--autolaunch=4816dd152e8c48ff97e9117d197c13d8" --binary-syntax --close-stderr
                        2⤵
                          PID:1477
                        • /usr/sbin/dbus-launch
                          dbus-launch "--autolaunch=4816dd152e8c48ff97e9117d197c13d8" --binary-syntax --close-stderr
                          2⤵
                            PID:1477
                          • /usr/bin/dbus-launch
                            dbus-launch "--autolaunch=4816dd152e8c48ff97e9117d197c13d8" --binary-syntax --close-stderr
                            2⤵
                              PID:1477
                            • /usr/lib/firefox/firefox
                              /usr/lib/firefox/firefox -contentproc -parentBuildID 20240108143603 -prefsLen 20982 -prefMapSize 234904 -appDir /usr/lib/firefox/browser "{3231b0d9-7e4e-4a08-abbd-4dbf8dcbeaec}" 1404 true socket
                              2⤵
                              • Reads CPU attributes
                              • Enumerates kernel/hardware configuration
                              • Reads runtime system information
                              PID:1489
                            • /usr/lib/firefox/firefox
                              /usr/lib/firefox/firefox -contentproc -childID 1 -isForBrowser -prefsLen 20185 -prefMapSize 234904 -jsInitLen 229864 -parentBuildID 20240108143603 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appDir /usr/lib/firefox/browser "{a80ec28c-cd23-47ec-865f-f1abd370bc1f}" 1404 true tab
                              2⤵
                              • Reads CPU attributes
                              • Enumerates kernel/hardware configuration
                              • Reads runtime system information
                              PID:1562
                            • /usr/lib/firefox/firefox
                              /usr/lib/firefox/firefox -contentproc -childID 2 -isForBrowser -prefsLen 28686 -prefMapSize 234904 -jsInitLen 229864 -parentBuildID 20240108143603 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appDir /usr/lib/firefox/browser "{d5eafb3c-57ab-42ff-aec8-89d058b31dcf}" 1404 true tab
                              2⤵
                              • Reads CPU attributes
                              • Enumerates kernel/hardware configuration
                              • Reads runtime system information
                              PID:1602
                            • /usr/lib/firefox/firefox
                              /usr/lib/firefox/firefox -contentproc -parentBuildID 20240108143603 -sandboxingKind 0 -prefsLen 29364 -prefMapSize 234904 -appDir /usr/lib/firefox/browser "{7050ca21-8375-495c-87d3-1eebe3792b97}" 1404 true utility
                              2⤵
                              • Reads CPU attributes
                              • Enumerates kernel/hardware configuration
                              • Reads runtime system information
                              PID:1629
                            • /usr/lib/firefox/firefox
                              /usr/lib/firefox/firefox -contentproc -childID 3 -isForBrowser -prefsLen 25649 -prefMapSize 234904 -jsInitLen 229864 -parentBuildID 20240108143603 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appDir /usr/lib/firefox/browser "{8ebe6c76-b645-476c-bf72-ef04110ea6f4}" 1404 true tab
                              2⤵
                              • Reads CPU attributes
                              • Enumerates kernel/hardware configuration
                              • Reads runtime system information
                              PID:1630
                            • /usr/lib/firefox/firefox
                              /usr/lib/firefox/firefox -contentproc -childID 4 -isForBrowser -prefsLen 25649 -prefMapSize 234904 -jsInitLen 229864 -parentBuildID 20240108143603 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appDir /usr/lib/firefox/browser "{4246d8f9-7e71-4d17-9b18-410b223eb27c}" 1404 true tab
                              2⤵
                              • Reads CPU attributes
                              • Enumerates kernel/hardware configuration
                              • Reads runtime system information
                              PID:1635
                            • /usr/lib/firefox/firefox
                              /usr/lib/firefox/firefox -contentproc -childID 5 -isForBrowser -prefsLen 25649 -prefMapSize 234904 -jsInitLen 229864 -parentBuildID 20240108143603 -greomni /usr/lib/firefox/omni.ja -appomni /usr/lib/firefox/browser/omni.ja -appDir /usr/lib/firefox/browser "{b3702e9e-85e4-4ba2-94f0-9812633de171}" 1404 true tab
                              2⤵
                              • Reads CPU attributes
                              • Enumerates kernel/hardware configuration
                              • Reads runtime system information
                              PID:1664
                          • /usr/libexec/gvfsd-fuse
                            /usr/libexec/gvfsd-fuse /root/.cache/gvfs -f -o big_writes
                            1⤵
                            • Reads runtime system information
                            PID:1521

                          Network

                          MITRE ATT&CK Matrix ATT&CK v13

                          Defense Evasion

                          Virtualization/Sandbox Evasion

                          1
                          T1497

                          Discovery

                          Virtualization/Sandbox Evasion

                          1
                          T1497

                          System Information Discovery

                          2
                          T1082

                          Replay Monitor

                          Loading Replay Monitor...

                          Downloads

                          • /root/Downloads/ZAzy1sLx.part
                            Filesize

                            12KB

                            MD5

                            703bb99d64fc55d412c182c4c4e6b555

                            SHA1

                            0bb7ce87cc64cccc2389dee091eb891731be457c

                            SHA256

                            7de5e5366c8b62aca1877e88f2d1536deea02876bf28bd0a201553feca4d7569

                            SHA512

                            618c18c8b5fbe588353bf3d67274f3edc8095241f42ee80fdabbe7f7f946ce04d37dd05f77b08b08bba74d1097b689fe2a60f233c3511ff8dfa1dea8ca9c2f46

                          • /root/Downloads/exploit.f3PoznU6.part
                            Filesize

                            25KB

                            MD5

                            4d8b897811ac8bf4f4b155fe670bd2bb

                            SHA1

                            104e291bcea7ab21ada04ad457b757479e11adfd

                            SHA256

                            0ba7da4e9489b3e35dca9ed4cc15d20017db8991537a1453270e64e27921deea

                            SHA512

                            5c9828ab5328f89f8ce026556f56ee1e2c75e543a7138bdfaae82d38e72fc50254fecdad44bf9f36c76d84ef5c37cfc2976187d54dd7806467a51ade5f1cd525