thesis.yaxs.net

Examples of categorised metdata rows

Posted Dec 18, 2018 | Section 3.7

Example of a Flashback malware observation. The original VirusTotal sample can be found here.

File SHA: 1d9e9408f8ea7e0b0c8c18ce69ea6393f9324d07	

Vendor Labels: MAC.OSX.Trojan.FlashBack.L; Backdoor.MacOSX.Flashback.H; MAC.OSX.Trojan.FlashBack.L; MAC.OSX.Trojan.FlashBack.L; Trojan.Mac.Flashfake.fdclnm; MacOS/FlashBack.A; OSX.Trojan.Gen; a variant of OSX/Flashback.K; Suspicious_GEN.F47V0516; MacOS:Flashback-AC [Trj]; Win.Trojan.Flashback-16; Trojan-Downloader.OSX.Flashfake.ab; MAC.OSX.Trojan.FlashBack.L; MAC.OSX.Trojan.FlashBack.L; MAC.OSX.Trojan.FlashBack.L (B); BackDoor.Flashback.39; OSX/Flashfake.c; OSX/Flshplyr-D; MacOS/FlashBack.A; TrojanDownloader.OSXFlashfake.l; OSX/Flashback.K.26; MAC/Agent.E17A!tr; malicious (high confidence); Backdoor:MacOS_X/Flashback.H; Troj.Downloader.Osx!c; Trojan-Downloader.OSX.Flashfake.ab; OSX32-Trojan/Flashback.AD; OSX/Flashfake.c; malware (ai score=89); Win32.Trojan-downloader.Flashfake.Ozia; Trojan-Downloader.OSX.Flashfake; MAC.OSX.Trojan.FlashBack.L; MacOS:Flashback-AC [Trj]; Win32/Virus.287	

Categorisation Result: rat	

Categorisation Score: {"rat": 35.371428571428574, "miner": 18.257142857142856, "adware": 23.914285714285715, "ransomware": 21.314285714285713}

Example of Genieo Adware/PUP malware observation. The original VirusTotal sample can be found here.

File SHA: 198fe421ff686ebe30afef1f576a4e0e91573dcb

Vendor Labels: Adware.MAC.Genieo.LT; OSX/Genieo.nn; OSX.Trojan.Gen; a variant of OSX/Adware.Genieo.AR; MacOS:Genieo-BQ [Adw]; Osx.Malware.Agent-5968620-0; Adware.MAC.Genieo.LT; not-a-virus:HEUR:AdWare.OSX.Geonei.y; Adware.MAC.Genieo.LT; Riskware.Mac.Mlw.emgyht; Adware.MAC.Genieo.LT; Genieo (PUA); Mac.Trojan.Genieo.127; OSX/Genieo.nn; Adware.MAC.Genieo.LT (B); PUA.OSX.Adware; ADWARE/OSX.Genieo.ivdfr; malicious (high confidence); Adware.MAC.Genieo.LT; not-a-virus:HEUR:AdWare.OSX.Geonei.y; Adware.MAC.Genieo.LT; Win32.Adware.Genieo.Ectt; malware (ai score=60); MacOS:Genieo-BQ [Adw]; Win32/Virus.Adware.697	

Categorisation Result: adware	

Categorisation Score: {"rat": 21.96153846153846, "miner": 17.76923076923077, "adware": 66.92307692307692, "ransomware": 23.96153846153846}