MALICIOUS — scoobe-fix.cmd .exe
MALICIOUS — scoobe-fix.cmd .exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Mira family. 4 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
877ae23476c8d5f79f76d2afc0e107dcb1bed00f08617b5d71a2767895c8e39e - SHA-1:
4c298d64ef13589f3fd31878efd30b67f1b79366 - MD5:
f68e6d2ef8a0945ee669942db33556f5 - imphash:
3a2003ea545fe942681da9e7683ebb58 - ssdeep:
6144:6BxIK3CTW8TMjp41u6nyHwnZ7er18F3Cprx4T8ho/6VPzItqFr:CxIK9V14ImyHY7er18F3+hvio9 - TLSH:
T1CC49ADDB649C643BC8B4780CC35E10DD7FC4A289916849EA21E593E9FE78E5337A0631 - Submitted as: scoobe-fix.cmd .exe
- File type: pe · Size: 420286 bytes
- Verdict: malicious (98/100) · Family: Mira
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Packed.Mira-7330891-0
- Microsoft Defender: Trojan:Win32/Krap!pz
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Packed.Mira-7330891-0 (rule
Win.Packed.Mira-7330891-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 22 external host(s) at runtime (19 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Packing/obfuscation: high-entropy-sections:.lol 1 - static signal, weight 0.25, confidence 0.55
- Dropped 29 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
Dynamic analysis (windows)
5971 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\DumpStack.log.tmp .exe -
e0bce66071bc550164b76aba94d12e080021354076f25bdd101f85acb7e1983b - C:\PPLFaultTemp .exe -
5f1736d447732a7e099c6da18b144d2ef318300c350a79beab43f00748f95ea7 - C:\uac-done.txt .exe -
993deba631e62279b35194daa07654c2afa36bc2361a5c06c7e7e6409764721f - C:\804.ini .exe -
e73fb9a154f1d624d7d42739a226e7884a0205c65e11695ce258f3f0dfab9dc5 - C:\Users .exe -
5b89b54d123fffd10c46f6967f146a28676e9401dd876bcabd644c56e6b077f1 - C:\Documents and Settings .exe -
83bf9b02da9a7d68edf44d8b32ca8646081e6e0363ba40354669c02c3e4a3692 - C:\804.ini -
5822e15c49f6e151fa147eea83a604232cce6b7d7b385947cba5b759eef10bcb - C:\ProgramData .exe -
38e07beb001809021188b7554b8c18a1094c9fad0f5b8d8a45dc9a7ecf4e1d7d - C:\scoobe-fix.cmd .exe -
55a9be868522ac97598597b879432c805ea969551c72d2f80ea14adc7b6abb0e - C:\System Volume Information .exe -
8891a88ef26d4e436232d7f0d1b662f5cdbcb23234897996dfb2a7118425c98d - C:\uac-done.txt -
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - C:\Sysmon64.exe .exe -
5536f5005476a21ce3a2dfdc9772d836fac121982ce544e8a80621bf036a4cbd - C:\Windows .exe -
d5915ff62588de08d694acf9beaeb1a094a0e0a57eb8991fb0b09e898d6e838b - C:\Config.Msi .exe -
ecd55a08ca11ffaad818456fcd9b93d2310b1b31e4ec44e7504751233009fd64 - C:\Program Files (x86) .exe -
749c6f3146bbe6ed113031cabced0e253ff6087cf6952752d5bbd6948acab990
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787721114&P2=404&P3=2&P4=BhcKWH67Gus%2fVTk%2bGN%2fCLRPomFkLZPMsMCXd9YOiwLSuxyhsKdOiQwHck9%2bi4JyyQRO5fC2EWc%2f2pvCvLzLAJA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787721200&P2=404&P3=2&P4=lZG97pgMPs%2fzr9orAPZT0dmoFG8AWafLooNlgGZH1B%2bAzUfNa80I51XIIT5nvck0KxkIz4wa7XEXVkXQp%2bB3cQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 13.89.179.15
- 4.144.132.114
- 172.215.188.225
- 4.230.171.124
- 135.232.92.137
- 135.232.92.97
- 4.207.44.72
- 52.123.129.14
- 20.112.250.133
- 52.123.128.14
- 40.99.133.242
- 135.234.160.245
- 52.110.12.56
- 52.110.12.45
- 203.26.79.13
- 52.148.114.188
- 52.123.252.242
- 20.165.94.46
- 52.123.252.224
- 72.154.7.110
- 52.110.12.31
- 52.110.12.40
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report