MALICIOUS — $Recycle.Bin .exe
MALICIOUS — $Recycle.Bin .exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 4 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
e1e526e1002e01709055a5be59b976fd03ce2172a8d936a554c7955909446a59 - SHA-1:
dfe9bd388eb370020bbdd73e934f9217eca016e6 - MD5:
f5f6bf263fea21fe97a686229aba4199 - imphash:
3a2003ea545fe942681da9e7683ebb58 - ssdeep:
6144:6BxIK3CTW8TMjp41u6nyHwnZk+bHVr6scVRhJzTQcAhjwvcp28Ov:CxIK9V14ImyHYk+bHFubAhjh2Xv - TLSH:
T1F149AEDC3FD3E965CAE7AD166456ADCF6000E366F986824B6085680F22FB533792344C - Submitted as: $Recycle.Bin .exe
- File type: pe · Size: 420286 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Packed.Mira-7330891-0
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
- Microsoft Defender: Trojan:Win32/Krap!pz
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Packed.Mira-7330891-0 (rule
Win.Packed.Mira-7330891-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Dropped a suspicious payload (Persistence): scoobe-fix.cmd - dynamic signal, weight 0.40, confidence 0.90
- Contacted 27 external host(s) at runtime (22 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497.001 - dynamic signal, weight 0.40, confidence 0.75
- Packing/obfuscation: high-entropy-sections:.lol 1 - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
5978 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
Dropped files
- C:\804.ini .exe -
c2d0cd0513812af18f03fde60b6dd0f628ed6773bdca7077e2fe4bf8f2cd905e - 319ed3c7457d90e38608335c68c44b6b443a276dfdb047c45f9a8e2e40eea554 -
319ed3c7457d90e38608335c68c44b6b443a276dfdb047c45f9a8e2e40eea554 - C:\Windows .exe -
1dd59c19afbe82fe3374fe962175dfe379396e882475131b191a4a6a91286909 - C:\PPLFaultTemp .exe -
19b24f4ab8297767722c2a2cffc8803cf5d7486142475519de0a48af07967009 - C:\inetpub .exe -
89a7c30a44efc0ebd4f1debabc5cee24de9a870d864a948cbffa21d87f09bfe7 - C:\ProgramData .exe -
737a2154ac836fd7a7a3ca131075363551e1467fbbec9b9fea1f980d6ff845ed - C:\p.ps1 .exe -
080fa53bc7fa3fbb16dc7c9832de995365759462629fe0b7e440540b42b24d89 - C:\scoobe-fix.cmd .exe -
0f8532a5cdeef91f1dfb16ec953ba6a6239089cddab121da1840451e902004bf - C:\$WinREAgent .exe -
a98070e4adee352cdc8237fdc4c6903c250c54e4e67042b4e0cf4258603790a8 - C:\System Volume Information .exe -
cdc2bc4fb8f66d0d3aaf3de4b6176f7a87710195ac1036afdf7671da7a6ecc95 - C:\Program Files (x86) .exe -
a47036913de3e4290398002305d9e0931bd09b15c9bad16e2d978f69f0a9e790 - C:\ProgramData\hhfkq.exe -
67770a4c752aefdf733b483fb2a0be3b86cb27b7c7c6cb766df7145195280393 - C:\Sysmon64.exe .exe -
8a44b001c9df8d834e011817551afadd334985b488844cc7be5eefc667491f39 - C:\swapfile.sys .exe -
0bf50697e2161474664a8754a5970b92fee7a23665f7ae3cb9bc30c98f07c7da - C:\Users .exe -
27f3ce6510a22898831e750c46486f5145bf2e28643a83eb608e09cbc7aca98d
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787725388&P2=404&P3=2&P4=Zbrb5%2fs%2fg5I7M0l3WQIUoKfTdF9fkbvigE0OwOh%2bz%2fUQg22d2c7o0R22KMxzx37JyJRcZuay6iLujTnu%2bKYNOA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787725490&P2=404&P3=2&P4=W6DCgvhlji1Q2gygMFJ27uJ3AKIUeu0Vc4Yvz5T5xXHsSBgMGafr%2bzqL30VwL7IupLjDkFBrZrKB9OIw0YMiGw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 52.110.12.56
- 4.150.223.109
- 52.110.12.3
- 52.123.252.240
- 52.230.59.222
- 4.230.171.124
- 172.215.188.232
- 74.178.76.128
- 13.89.179.15
- 20.165.94.54
- 20.236.44.162
- 52.123.128.14
- 40.99.134.18
- 52.123.129.14
- 135.234.160.245
- 203.26.79.13
- 85.210.193.152
- 57.154.63.210
- 52.148.114.188
- 135.233.95.80
- 4.150.223.108
- 51.104.15.253
- 72.154.7.98
- 52.123.252.226
- 74.179.71.159
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report