2015-08-07 - Traffic Analysis Report
Executive Summary
On Wednesday 2015-08-07, Degrando Rustlyn’s computer was infected by a Banking Trojan via opening a malicious link in an email, which downloaded a .rar
achieve containing malware. After the infection occurred, the SOC team immediately contacted Degrando Rustlyn to start investigating the incident.
Details
Infected computer’s host name: PERTRUIDE-PC
. Infected computer’s IP address: 192.168.137.113
. Infected computer’s MAC address: 00:1e:4f:6c:ba:05 (Dell_6c:ba:05)
.
The malicious email that caused the infection:
- Date/Time:
Tue, 4 Aug 2015 20:16:47 +0000 (UTC)
. - Subject line:
Voce recebeu comentario de voz em sua foto - 3192132
. - Sender:
Facebook.com <accounts@passport.com>
(spoofed sender).
Domain and IP addresses of the related traffic:
- www.ica.ufmg.br - 150.16.130.253
- australiano2015.com.br - 69.49.115.40
- downloadpdf.demojoomla.com - 67.212.169.218
Malware associated with the infection:
Filename | Size | MD5 | Description |
Download.rar | 3 KB (3,205 bytes) | 6325f04a77fce24c8c43b71d817d3fe7 | Downloaded from a link in a malicious email. |
Download.vbe | 5 KB (4,804 bytes) | 50ac6b67b095aeb4e85b3f94e66d8666 | Extracted from Download.rar |
Gravar.zip | 9.3 MB (9,303,045 bytes) | e1d6e85f72d76845f9dc1c5c3d4fd469 | Downloaded via Download.vbe script. |
dmw.exe | 18.9 MB (18,925,024 bytes) | 3c3e8b9b18fb1d14095adb0a16d457d8 | Extracted from Gravar.zip |
Analysis Process
Opening a malicious email with Thunderbird
, we can see that the attach opens a link to a suspicious-looking website.
data:image/s3,"s3://crabby-images/b54e4/b54e406790336c37257fb2e03669de9b5838bf7d" alt="20150807/1.png 20150807/1.png"
Spending sometimes to inspect related traffic in the Wireshark
packet capture, we discover that it lured victim to download a file called Download.rar
.
data:image/s3,"s3://crabby-images/e8b02/e8b02b1c8c5aad5672537e35987d0889343f09c8" alt="20150807/2.png 20150807/2.png"
Extracting the RAR archieve exposed a malicious VBScript that will automatically download a ZIP named Gravar.zip
.
data:image/s3,"s3://crabby-images/d3147/d3147fbaaa56ab6dd6ceb0aa90397ca53f01eed3" alt="20150807/3.png 20150807/3.png"
Inside the ZIP contains a Windows executable called dmw.exe
, which is then executed to infect the victim system.
Here is a piece of code that demonstrates the VBScript executing dmw.exe
binary.
- Note:
SOTAR
isdmw.exe
data:image/s3,"s3://crabby-images/0e14f/0e14fbb10031703d66f4bd65bc2e19dd39d17961" alt="20150807/4.png 20150807/4.png"
If we further investigate the HTTPS artifacts, we can see that the victim had downloaded the Gravar.zip
and execute the VBScript inside it.
data:image/s3,"s3://crabby-images/4ab39/4ab3956f71dc24b78c99274d243e95dd31ba43e7" alt="20150807/5.png 20150807/5.png"
Replaying the PCAP traffic via snort
, it will trigger the alert of Banking Trojan.
$ sudo snort -q -A console --daq pcap -k none -r 2015-08-07-traffic-analysis-exercise.pcap -c /etc/nsm/securityonion-eth0/snort.conf
08/05-16:04:36.644292 [**] [1:2021439:3] ET TROJAN Win32/Bancos.AMM CnC Beacon [**] [Classification: A Network Trojan was detected] [Priority: 1] {TCP} 192.168.137.113:49311 -> 69.49.115.40:80
Looking at stream 154
, we discover some patterns that alert snort
.
data:image/s3,"s3://crabby-images/d3022/d3022450697e9fb258e64ff97a98d38ddd985fc7" alt="20150807/8.png 20150807/8.png"
or try uploading the dmw.exe
binary onto Virus Total, it also lights up as a Chrismas tree.
data:image/s3,"s3://crabby-images/4c1a0/4c1a0558280179da878efcb5ac3fc565f276f583" alt="20150807/6.png 20150807/6.png"
Now, we can safely conclude that the isolated system was infected by a Banking Trojan.