Analysis Report exchangeserver_frontend_httpproxy_owa_auth_signin.aspx
Overview
General Information
Sample Name: | exchangeserver_frontend_httpproxy_owa_auth_signin.aspx |
Analysis ID: | 366002 |
MD5: | 0061d327e1ddbb82cc7dbab58834585a |
SHA1: | b03c388e21ebdd5721abec17cb71e2b9bb76555d |
SHA256: | 1462db256a9646f4c35f49f626a9042d0f993b0e11508d824348e3eacec9bb56 |
Infos: | |
Most interesting Screenshot: | |
Errors
|
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Malware Configuration |
---|
No configs have been found |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
IronTiger_ASPXSpy | ASPXSpy detection. It might be used by other fraudsters | Cyber Safety Solutions, Trend Micro |
| |
IronPanda_Webshell_JSP | Iron Panda Malware JSP | Florian Roth |
| |
webshell_asp_generic_eval | Generic ASP webshell which uses any eval/exec function directly on user input | Arnim Rupp |
| |
webshell_csharp_generic | Webshell in c# | Arnim Rupp |
| |
webshell_generic_os_strings | typical webshell strings | Arnim Rupp |
| |
Click to see the 1 entries |
Sigma Overview |
---|
No Sigma rule has matched |
---|
Signature Overview |
---|
Click to jump to signature section
Source: | String found in binary or memory: |
System Summary: |
---|
Malicious sample detected (through community Yara rule) |
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Mitre Att&ck Matrix |
---|
No Mitre Att&ck techniques found |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
No Antivirus matches |
---|
No Antivirus matches |
---|
No Antivirus matches |
---|
No Antivirus matches |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe |
No contacted domains info |
---|
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
No contacted IP infos |
---|
General Information |
---|
Joe Sandbox Version: | 31.0.0 Emerald |
Analysis ID: | 366002 |
Start date: | 10.03.2021 |
Start time: | 09:54:02 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 1m 47s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | exchangeserver_frontend_httpproxy_owa_auth_signin.aspx |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 3 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.winASPX@0/0@0/0 |
Cookbook Comments: |
|
Warnings: | Show All
|
Errors: |
|
No simulations |
---|
No context |
---|
No context |
---|
No context |
---|
No context |
---|
No context |
---|
No created / dropped files found |
---|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 5.493144485168071 |
TrID: |
|
File name: | exchangeserver_frontend_httpproxy_owa_auth_signin.aspx |
File size: | 92962 |
MD5: | 0061d327e1ddbb82cc7dbab58834585a |
SHA1: | b03c388e21ebdd5721abec17cb71e2b9bb76555d |
SHA256: | 1462db256a9646f4c35f49f626a9042d0f993b0e11508d824348e3eacec9bb56 |
SHA512: | bcebe35c3a524fb253e1595116fe9f9b5396be06d63f90b1bb9c187475930bfb943074fa2910448c3d14b4d7f48ab68b2fd4669e7b7dd59e92f9bb4c4188cdf3 |
SSDEEP: | 1536:L9UToBXN7aC5zimqgFagDDDPLFWGB7AL8X7OyXI7PdxUFbEoM/ct73G8r6zWS52v:+oBXN7a+jqGvyL8X7OyXI7PdxUFbEoMm |
File Content Preview: | <%@ Page Language="C#" Debug="false" trace="false" validateRequest="false" EnableViewStateMac="false" EnableViewState="true"%>.<%@ import Namespace="System.IO"%>.<%@ import Namespace="System.IO.Compression"%>.<%@ import Namespace="System.Diagnostics"%>.<% |
File Icon |
---|
Icon Hash: | 74f0e4e4e4e4e0e4 |
Network Behavior |
---|
No network behavior found |
---|
Code Manipulations |
---|
Statistics |
---|
System Behavior |
---|
Disassembly |
---|