MALICIOUS — c9387ed707b32e15ef09c8a9afc33ce5192cb363bb113c5759ee2df87b70eccb
MALICIOUS — c9387ed707b32e15ef09c8a9afc33ce5192cb363bb113c5759ee2df87b70eccb is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Lmir family. 7 of 55 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
c9387ed707b32e15ef09c8a9afc33ce5192cb363bb113c5759ee2df87b70eccb - SHA-1:
aec42487bdff37ddbb65ad33d9b1e42c08e15e46 - MD5:
1e2d5d3c517512e2cbaa7d8bff57a4c6 - imphash:
aae410db5a351d384de2e35faf59497e - ssdeep:
6144:rajdMJyFRe6azHqTGXHaeaEfsYQXsnUVx4ZXvQShdrXvbGLcqBG65tuwUD:E2JylsKTUHfjndvQSrrXvbGIqBGz - TLSH:
T1AE499E6E574E6B47EB77C71814801F1F4062F8BA50BE18CC26D7D12EA3F9C8BA915218 - Submitted as: c9387ed707b32e15ef09c8a9afc33ce5192cb363bb113c5759ee2df87b70eccb
- File type: pe · Size: 417746 bytes
- Verdict: malicious (100/100) · Family: Lmir
Detections (7 of 55 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Trojan.Lmir-22
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Virus:Win32/Viking.MR
- Emsisoft (Emergency Kit): Dropped:Generic.Delf.Lmir.2EC949F5
- Kaspersky (KVRT): Trojan-GameThief.Win32.Lmir.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Lmir-22 (rule
Win.Trojan.Lmir-22) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload: updater.exe - dynamic signal, weight 0.62, confidence 0.90
- 1 behavioral detection(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Memory forensics: 3 finding(s), e.g. process hidden from a listing (rule
windows.psxview.PsXView) - memory signal, weight 0.55, confidence 0.85 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 25 external host(s) at runtime (23 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
32050 behavior events · 2 ATT&CK techniques · 51 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
Dropped files
- C:\Program Files\LibreOffice\program\gengal.exe -
95e31707c3ffb64df85790b4944157c38030dc4456a6280b8ec4031526894dd8 - C:\Program Files\LibreOffice\program\minidump_upload.exe -
d9d9d28500fb4b00c08b26197f484caa731fb1cb5568a47b90398dbdb8e4b3ff - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Program Files\LibreOffice\program\python-core-3.12.13\lib\pip\_vendor\distlib\t64.exe -
57c857c042dc1ccb48dec4033f8edb3b51bb2d6704fe2b0e714a22d571ef1319 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jaccesswalker.exe -
6d72344a6f469a1dd012eba26f45e251e472b8bf371aa925c48fe72ddb37822e - C:\Program Files\LibreOffice\program\unoinfo.exe -
e1c8cf9806125d1fe8f1131abddcda60fa8e89e627fd07fc6e272a4ad53a1781 - C:\Program Files\LibreOffice\program\python-core-3.12.13\bin\pythonw.exe -
69c51db41056750cf6f747c34d422ff15bc79b6864102acda2dc4c4d1dcea7e9 - C:\Program Files\LibreOffice\program\xpdfimport.exe -
537381b4e219e3ad765f6a13c81f42673d560b429512cddd9de99c26549e32d4 - C:\Program Files\LibreOffice\program\python-core-3.12.13\lib\pip\_vendor\distlib\w32.exe -
a51534b460b92d36fd81ce21aca7f126531101a90febe239013cbd01cb0a38b4 - C:\Program Files\LibreOffice\program\senddoc.exe -
f40fd3e158765732d2fce5cb5966b47c96a9140ffb97f74a68b3426f4d9ee084 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jabswitch.exe -
9242bfdc1b1dc6ff5b8d745bc2ec08fde3011de6abcca8049867dd9e76459c03 - C:\Program Files\LibreOffice\program\sbase.exe -
2af8c5991385482a8dbc60d858c68a989d1724a140a046963ee5f2ac3c5d9567 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jfr.exe -
8e065752c6c627ee5337851ed11af52dbfc9df4f9489e0b887b1bbb639dbe9bb - C:\Program Files\LibreOffice\program\twain32shim.exe -
bb0a3ae69a8371470d5eb311bd5f0806444c7f4848edf51ee1c3da6c2d9bcac8 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jwebserver.exe -
252560857acb5c7993c66803071cc33c2ab7d9d777c496a004723b420ad0555d
Embedded URLs
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- http://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787820967&P2=404&P3=2&P4=RM77eylBNH9GYKOgNypdJbi%2bf0rEQ0TDOIkNUJeVXkLyuy7uf8iDFA8VMtHNK2YeTO6tWbgJjyfzGI3nRS1DyA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787821058&P2=404&P3=2&P4=YI7BnItVsjJcV9XTR0SFGtpnxXZWx54B6Ik5ltlVKBA9snJ8hKML2gicITdq2RgH2H61oDaDlU%2bKj1Q57IDbng%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
Embedded IP addresses
- 40.79.150.120
- 52.123.252.239
- 172.215.188.225
- 52.230.59.222
- 4.230.171.124
- 40.84.85.40
- 135.233.95.144
- 74.178.240.51
- 20.76.201.171
- 52.123.129.14
- 52.123.128.14
- 4.207.44.68
- 135.233.45.223
- 203.26.79.13
- 85.210.193.152
- 52.168.117.170
- 20.165.94.46
- 52.123.252.235
- 52.148.114.188
- 52.110.12.42
- 52.110.12.25
- 172.66.2.5
- 162.159.142.9
- 72.153.5.135
- 52.110.12.46
File paths
- X:\:`:d:h:l:p:t:x:
- D:\B\T\Acrobat\Installers\ShowAppPickerForPDF\Release\ShowAppPickerForPDF.pdb
More Lmir samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report