MALICIOUS — c0f8204deafadd188e82e1c623be52f70a5bad0b544c3cd257d229b8c06a5bf2
MALICIOUS — c0f8204deafadd188e82e1c623be52f70a5bad0b544c3cd257d229b8c06a5bf2 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Lmir family. 8 of 56 detection engines flagged it, exhibiting 9 ATT&CK techniques.
Identification
- SHA-256:
c0f8204deafadd188e82e1c623be52f70a5bad0b544c3cd257d229b8c06a5bf2 - SHA-1:
7bfd4c0f365af28ec7f8f057d7e77ca27594d0c0 - MD5:
f416abefcd4d96fa9e217d943db64321 - imphash:
5124cd999a2e4c567a9a25b581fe72b3 - ssdeep:
6144:bvrb22uGLbWhTjYVMkWF69d2HgFmRxLxCc2P5LynxkNAkYaSaM2NDhXmw1SYaDYW:bDb22DShTEeS2SpSYnEvFmE - TLSH:
T1114A29D1E812E28BC7E8C61DC49544DC087EB0A9F4B6D2B44A82E25995F8D3330EF55B - Submitted as: c0f8204deafadd188e82e1c623be52f70a5bad0b544c3cd257d229b8c06a5bf2
- File type: pe · Size: 463936 bytes
- Verdict: malicious (100/100) · Family: Lmir
Detections (8 of 56 engines)
- capa (capabilities): capability:credential-access
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Lmir-24
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Virus:Win32/Viking.KI
- Emsisoft (Emergency Kit): Trojan.Agent.CGVL
- Kaspersky (KVRT): Trojan-GameThief.Win32.Lmir.oa
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 19 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Lmir-24 (rule
Win.Trojan.Lmir-24) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s) across 1 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged Virus:Win32/Viking.KI (rule
Virus:Win32/Viking.KI) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent.CGVL (rule
Trojan.Agent.CGVL) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-GameThief.Win32.Lmir.oa (rule
Trojan-GameThief.Win32.Lmir.oa) - engine signal, weight 0.55, confidence 0.85 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 2 external host(s) and 8 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:credential-access (rule
capability:credential-access) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Dropped 55 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis (windows)
31770 behavior events · 2 ATT&CK techniques · 58 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- ctldl.windowsupdate.com
- update.googleapis.com
- desktop-hsgcbep
- login.live.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
- licensing.mp.microsoft.com
Dropped files
- C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe -
b8a9d5807917687ab25ef2c5759f7f1520fda63f734924b93c86e5524d0e7f68 - C:\Program Files\Adobe\Acrobat DC\Acrobat\CPInstCU.exe -
79f0c5238a406e4865e77e37d869ca9bddc2203220dfd4e82ecada9061a66cea - C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe -
377693e2ca6eefba36f61373194f572541a409cb10808b8c71d52897a6df3e8f - C:\Program Files\Adobe\Acrobat DC\Acrobat\ShowAppPickerForPDF.exe -
e8e2387762fb250014a36d1cd7aad26b7ff36ab073eec64cc48bbf67c5acbc2e - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\klist.exe -
a7e6381e2a4ab9de0563fc98f927c8494c343107d2afdc7e9d9b98c9c94335f9 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\kinit.exe -
ce61f0cc99b97543e4cfe09a15b3a7b6e86b4fb92102bfe8352d6eaad6cf6bec - C:\Program Files\Google\Chrome\Application\151.0.7922.174\notification_helper.exe -
3b2af79f614a7510b065c742c56e2d3ffb3f11b096f60558f327aa1d3e1a8b5d - C:\Program Files\Google\Chrome\Application\chrome.exe -
2cd92d77230eebd68fc7f1bc7a141a5d8d2e99ea22fd10ba0c6b40f61d92d47d - C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe -
698f79937dc7b693633e00453acea137673a666e8b98c796d14fb8a41df1fdac - C:\Program Files\Google\Chrome\Application\151.0.7922.174\Installer\setup.exe -
5ddcfa28ba5cd1ca9c094807aa38fdaa8a33e7c7b5e9f8a0f7425652a7744b06 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\keytool.exe -
f3639161913f7443f4fe9cb18ee67092ffba922b4761f2137b2f05c7fbedf9a7 - C:\Program Files\7-Zip\7zG.exe -
9507a5d3e302719d7475fdf7dfb79f168517c3b62fb6ecb65068c0ab8f915698 - C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe -
5870f6e570d18e050b53438850fda582dafbce7d96dc6c9177eb28acd4e5bc61 - C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe -
7ab807b2f85d1de86a4ddbdc9efffe045c74d75668f9e7428999e863a062507b
Embedded URLs
- http://msdl.microsoft.com/download/symbols
- http://www.microsoft.com/msdownload/platformsdk/sdkupdate/psdkredist.htm
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
Embedded domains
- msdl.microsoft.com
- www.microsoft.com
- crl.microsoft.com
Embedded IP addresses
- 4.150.223.98
- 52.123.252.198
- 4.230.171.124
- 57.155.104.224
- 74.178.240.51
- 20.247.184.142
- 4.150.223.111
- 74.178.240.61
- 92.223.78.30
- 104.18.33.89
- 52.110.12.4
- 52.110.12.31
- 72.153.5.63
- 52.148.114.188
- 52.110.12.42
- 52.110.12.16
More Lmir samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report