MALICIOUS — ad7a156e576888b7d9449126f967b5c26b1da18e3baba84ced9300e008f877e0
MALICIOUS — ad7a156e576888b7d9449126f967b5c26b1da18e3baba84ced9300e008f877e0 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Mira family. 4 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ad7a156e576888b7d9449126f967b5c26b1da18e3baba84ced9300e008f877e0 - SHA-1:
7cbedea6bb05e0913660313a0c95df0813676abd - MD5:
530735d3055549f70b764471aaee59ad - imphash:
044fa07aef4575da982ff3317702d6b1 - ssdeep:
12288:ljwqr+D5V4EwO6Fz0sK+oPmG9jnbGYqvAYokDvdUC1TgwyhsR+ExJpcEi0/3IWVZ:dwqr+D5V4poPmG5bY+6/p - TLSH:
T1494AD951614C7616CEB7C5E9EC0CAE2C97F3D89615BAD3CC8612E15B82E25F309204AF - Submitted as: ad7a156e576888b7d9449126f967b5c26b1da18e3baba84ced9300e008f877e0
- File type: pe · Size: 465478 bytes
- Verdict: malicious (89/100) · Family: Mira
Detections (4 of 52 engines)
- ClamAV (daily): Win.Malware.Mira-6717565-0
- Microsoft Defender: Trojan:Win32/Ymacco
- Emsisoft (Emergency Kit): Generic.Mira.0B48A3A8
- Kaspersky (KVRT): Trojan.Win32.Agent.nezvfi
MITRE ATT&CK
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Malware.Mira-6717565-0 (rule
Win.Malware.Mira-6717565-0) - engine signal, weight 0.90, confidence 0.95 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- fstream-inst.cc
- ostream-inst.cc
- istream-inst.cc
- io-inst.cc
- string-inst.cc
- tinfo.cc
- streambuf-inst.cc
- codecvt.cc
- ios.cc
- functexcept.cc
- locale.cc
- locale-inst.cc
- ctype.cc
- atomicity.cc
- pure.cc
- stdexcept.cc
- locale-misc-inst.cc
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report