MALICIOUS — 90a4d6552614071eafa2aff16768c88b791cf03e8bc5a987a56977e741614a42
MALICIOUS — 90a4d6552614071eafa2aff16768c88b791cf03e8bc5a987a56977e741614a42 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the Lmir family. 9 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
90a4d6552614071eafa2aff16768c88b791cf03e8bc5a987a56977e741614a42 - SHA-1:
cb160039c88f5d98cbdb1a9383a82dfb4a15f655 - MD5:
d5fb3b65dfe9cd4b20274b99a3cdf1af - imphash:
5124cd999a2e4c567a9a25b581fe72b3 - ssdeep:
6144:bvrb22uGLbWhTjYVM9IOIs6qUWslyPlxPDHt/OE9:bDb22DShTEe9IllyfPD3 - TLSH:
T130459DB78406FE07E871D56A6830932C681FE8B7786F6D4C0346C05EA4E296371B71AD - Submitted as: 90a4d6552614071eafa2aff16768c88b791cf03e8bc5a987a56977e741614a42
- File type: pe · Size: 287204 bytes
- Verdict: malicious (96/100) · Family: Lmir
Detections (9 of 55 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Lmir-24
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Virus:Win32/Viking.KI
- Emsisoft (Emergency Kit): Trojan.Agent.CGVL
- Kaspersky (KVRT): Trojan-GameThief.Win32.Lmir.oa
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Lmir-24 (rule
Win.Trojan.Lmir-24) - engine signal, weight 0.90, confidence 0.95 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, Turbo Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://go.microsoft.com/fwlink/?LinkId=154498
- http://crl.verisign.com/tss-ca.crl0
- http://crl.verisign.com/pca3.crl0
- https://www.verisign.com/cps0
- http://logo.verisign.com/vslogo.gif04
- https://www.verisign.com/rpa
- http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
- http://csc3-2010-aia.verisign.com/CSC3-2010.cer0
- https://www.verisign.com/cps0*
- https://www.verisign.com/rpa0
- http://crl.verisign.com/pca3-g5.crl04
Embedded domains
- go.microsoft.com
- crl.verisign.com
- www.verisign.com
- logo.verisign.com
- csc3-2010-crl.verisign.com
- csc3-2010-aia.verisign.com
File paths
- S:\:
- X:\:`:d:h:l:p:t:x:
More Lmir samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report