MALICIOUS — 3b7b124c6e52ec8b7eb680835a715e7bd7fd2a4fa14e86b78388c3e36abce763
MALICIOUS — 3b7b124c6e52ec8b7eb680835a715e7bd7fd2a4fa14e86b78388c3e36abce763 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Lmir family. 7 of 55 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
3b7b124c6e52ec8b7eb680835a715e7bd7fd2a4fa14e86b78388c3e36abce763 - SHA-1:
1384a0a9c01d9bf8131cb8e15c6c416c50e4f38b - MD5:
e0e0b45108552ada6190eebe3e17bbea - imphash:
aae410db5a351d384de2e35faf59497e - ssdeep:
6144:AajdMJb6SqIqOq2eJCdlCgyVQr1lonNQCfxUawyonuUVb5v:92JbM2yYl9yqeNvxUyonuCb5v - TLSH:
T15A488C7A571F7707DBFBCA1818106F6E4022F87A50BE188C12A3C53DB3EAC5B6651249 - Submitted as: 3b7b124c6e52ec8b7eb680835a715e7bd7fd2a4fa14e86b78388c3e36abce763
- File type: pe · Size: 354624 bytes
- Verdict: malicious (100/100) · Family: Lmir
Detections (7 of 55 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Trojan.Lmir-22
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Virus:Win32/Viking!atmnm
- Emsisoft (Emergency Kit): GenPack:Generic.Delf.Lmir.CE051F6F
- Trellix Stinger (McAfee): PWS-FCMH!E0E0B4510855
- Kaspersky (KVRT): Trojan.Win32.Patched.rv
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Lmir-22 (rule
Win.Trojan.Lmir-22) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload: updater.exe - dynamic signal, weight 0.62, confidence 0.90
- 1 behavioral detection(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Memory forensics: 4 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 25 external host(s) at runtime (19 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
33178 behavior events · 2 ATT&CK techniques · 51 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
Dropped files
- C:\Program Files\LibreOffice\program\unoinfo.exe -
733965fb2e664212efe9b70fc49f7cb9d1ec83d44e54f49681f085ab23c6cdcd - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jrunscript.exe -
e3c055a286e24be0667d822c94791c80524885a0691dc9f6053c95ccf67e2540 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jfr.exe -
6e9078f42ee6ad890870df09610127a9c16809bd268e9d642e17853e90c4d715 - C:\Program Files\LibreOffice\program\simpress.exe -
7af3ce6a6a887259bf2eb36f812935eb953a09a3238e387f4c65ebb16d3d97af - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\java.exe -
14a5cf9cad55c3168e17a113a61b17c692a5147da84aedf144a1ceb70a043636 - C:\Program Files\LibreOffice\program\twain32shim.exe -
76e75de5c18105ada115a63e9680b53fc724562c3358dd81a302e8c818732193 - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Program Files\LibreOffice\program\python-core-3.12.13\lib\pip\_vendor\distlib\w32.exe -
bc77416e82c6fa83e2ce851beb502f8d460a7d966411d00c8faf1076a4aef457 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\keytool.exe -
8fc2520ad8e033fcc4121eaa577121351b78eaebfc2101f276226ea1f0ff5ea2 - C:\Program Files\LibreOffice\program\sdraw.exe -
442a833bbc6a7790e4865ada7600af1dded9edcae8b5d19d2d389449d41e21e8 - C:\Users\analyst\AppData\Local\Temp\tsk_c427f6123d31446e.tmp -
5c1af46c7300e87a73dacf6cf41ce397e3f05df6bd9c7e227b4ac59f85769160 - C:\Program Files\LibreOffice\program\odbcconfig.exe -
d242597c68912074b5786eec291967fceee766a4eb68c0092904c4924a67845f - C:\Program Files\LibreOffice\program\smath.exe -
4385746b9903f1a39153d3012b01263b88423dbea0fdb4b25a43b694a6463ac3 - C:\Program Files\LibreOffice\program\uno.exe -
6e1e7f0de58570ceac19c560e37f41829dbe653e7d3c6926df18bd5d2b39ba84 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jwebserver.exe -
65889522e7b6fb6468a0af5aad1c65e61c696bf8129b3e0b21d19ffddd246709
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/fa5c4269-9d03-4a47-8d97-be6931f0b22c/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/fa5c4269-9d03-4a47-8d97-be6931f0b22c?P1=1787928345&P2=404&P3=2&P4=Rg7muE7wsebq1zXjoEyJcdsT6w7mNpG%2bq7uj77pnGfzrEFkLOShIDgiZO039lGIUd%2blXWg79DWZb1VEWJL91aA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/51d86688-616b-47e3-abeb-3df16a1583c5/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/51d86688-616b-47e3-abeb-3df16a1583c5?P1=1787928439&P2=404&P3=2&P4=SEnh%2fWOI0h3PZ6xlrDubx1ZbWm5FXTbZRuA8VXcgqW0EX0viNUnx6Bb5naHq8IajJl6Ud25ELqw0B2AHGTaYqA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 20.42.73.31
- 52.123.252.213
- 40.84.85.40
- 4.230.171.124
- 52.253.84.76
- 52.123.252.243
- 135.233.95.144
- 74.178.240.51
- 52.168.117.169
- 74.178.240.61
- 52.123.128.14
- 52.123.129.14
- 20.236.44.162
- 40.99.134.18
- 172.66.2.5
- 40.104.4.2
- 203.26.79.13
- 135.234.160.244
- 135.233.95.80
- 52.148.114.188
- 52.110.12.3
- 52.110.12.1
- 72.154.7.103
- 52.110.12.48
- 52.110.12.38
File paths
- X:\:`:d:r:
- J:\:
- L:\:l:
- X:\:`:d:h:l:p:t:x:
- d:\office\source\util\threadpool\src\init.cpp
- d:\office\source\util\threadpool\inc\threadpool.h
- d:\office\source\util\threadpool\src\threadpool.cpp
- d:\office\source\util\threadpool\src\primitives.cpp
- d:\office\source\util\threadpool\inc\sharedlock.h
- d:\office\source\util\threadpool\src\sharedlock.cpp
- d:\office\source\util\threadpool\src\misc.cpp
- d:\office\source\util\threadpool\src\waiterthread.cpp
- d:\office\source\util\threadpool\src\work.cpp
- d:\office\source\util\threadpool\src\threadres.cpp
- d:\office\source\util\threadpool\src\timerobj.cpp
- d:\office\source\util\threadpool\src\idle.cpp
- d:\office\source\util\threadpool\src\workerqueue.cpp
- d:\office\source\util\threadpool\src\power.cpp
More Lmir samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report