MALICIOUS — Program Files .exe
MALICIOUS — Program Files .exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 5 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
3dd5d654277de3208cb2545260cdf8b7160c6a744126944bb842df27f048e8c0 - SHA-1:
29555b899d328699b14f289e20be92c8cbd54166 - MD5:
d74421a116e5b6e79767acafe0a28769 - imphash:
3a2003ea545fe942681da9e7683ebb58 - ssdeep:
12288:CxIK9V14ImyHYtItuKRttTtA6lLUv/hAzDGI:CJEyYtmuKxTtAcUv/hAzDx - TLSH:
T18549BE5C2185F882ED20CE2FDB0F667DAB117BB0D075F9640E2E7A5A01182671ED4CA7 - Submitted as: Program Files .exe
- File type: pe · Size: 420288 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (5 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Packed.Mira-7330891-0
- Detect It Easy (packer/type): DIE:MinGW
- Microsoft Defender: Trojan:Win32/Krap!pz
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Win.Packed.Mira-7330891-0 (rule
Win.Packed.Mira-7330891-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Dropped a suspicious payload (Persistence): scoobe-fix.cmd - dynamic signal, weight 0.40, confidence 0.90
- Contacted 19 external host(s) at runtime (22 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:MinGW (rule
DIE:MinGW) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.lol 1, MinGW - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
5972 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\DumpStack.log.tmp .exe -
e974cadcdee5c402ae6548bd800011cbb24347622ae3f26ed1ea259d9029c967 - C:\PerfLogs .exe -
c59e3fdc273c2a54a9db3bebeb6d593c61d334a372beb12ff073b7e67cbddeb9 - C:\uac-done.txt -
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - C:\Documents and Settings .exe -
de32a5a3377dea432943d5de0099aead977a996e7ca53bc2def4b574925f7756 - C:\808.ini -
ed8d007a5b3b4c94635e1166e0a0f4451881e08997d6331123a0a5415143f2df - C:\pagefile.sys .exe -
109179df3ab64a82486cc21b2edeaa5a3d488a96fd50680834e37cb6b8050834 - C:\scoobe-fix.cmd .exe -
77b15b3dbdadd48a91913ee5349265111adc9e2d05df4d0bc55f4345f5fc77f1 - C:\uac.ps1 -
a42e57db93b93ecb2224fdb1276f4ebb0b6705cc4a95ec1899772df8dc47a684 - C:\inetpub .exe -
1b7cb6f493770ef7ed18a5097f6f60d609078b322756459273dadb1db590287b - C:\p.ps1 .exe -
1657edc345a68f604f9217a404c36dc351098c4241828f57398e18d830a4d949 - C:\System Volume Information .exe -
527bb2f421838db5456511527fbfeaca0a450f1c764de12d452fcb27209f6b12 - C:\$Recycle.Bin .exe -
e94883a5bb5b68f3d8c49a952c7b8f6e40d0c54a14843708fa8ee3a92403060f - C:\Program Files .exe -
5771b4647921fdbfc9de8b617d464dafde7f9f052ca413d592826fa68e58167a - C:\ThreatLens .exe -
4dbfc658ecce7699d6db9a3edfb7bc6964e09812f6296f40d5dbfcaf54846109 - C:\ProgramData\mqbro.exe -
551b2c77f2ed025575eb05db777e565b31b4aa54fef4a65088ceccf291e555c0
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787673618&P2=404&P3=2&P4=AfhFxHA40PircknB1FNamhEKVu51mQmC1NsypkjnXFsdbEjacBk7Q10XwVsgEJjKW%2fgxTGXvjFpxx22yY0oQUw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787673646&P2=404&P3=2&P4=G9HVBBAM2g%2fQDwORzDmGWKPePASz%2f6HlMo3bYQYlEGcYdYCfQUYWrsy9o46yiX2uQLwXM7H1tzzYWmSGLCojIQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 142.250.195.142
- 4.207.44.75
- 4.247.188.224
- 4.230.171.124
- 52.230.59.222
- 135.232.92.137
- 20.165.94.54
- 20.184.175.6
- 20.112.250.133
- 52.123.129.14
- 4.207.44.76
- 20.165.94.46
- 203.26.79.13
- 172.178.240.162
- 52.148.114.188
- 52.110.12.51
- 72.154.7.106
- 52.110.12.18
- 52.110.12.20
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report