MALICIOUS — ffafe2b75352673dbae846022f94d08b5f94e099b86f9041a7428b71f94303f5
MALICIOUS — ffafe2b75352673dbae846022f94d08b5f94e099b86f9041a7428b71f94303f5 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Lmir family. 10 of 56 detection engines flagged it, exhibiting 10 ATT&CK techniques.
Identification
- SHA-256:
ffafe2b75352673dbae846022f94d08b5f94e099b86f9041a7428b71f94303f5 - SHA-1:
a4aa5f0decb1922ee576e7f0b7b922bd000e8d57 - MD5:
ea8a63e6debe4aff6d12baa2504dfe25 - imphash:
5124cd999a2e4c567a9a25b581fe72b3 - ssdeep:
6144:bvrb22uGLbWhTjYVMupDb+5WhXmw1SYaDYXpEX1UnEv/P1UGvCpr/:bDb22DShTEe2qcpSYnEv2GvG - TLSH:
T1EF4A07C1D906A58BCBC8C65DC49194CC1C7EB0AAF8B5D2344986D2699AF8C3371EF11B - Submitted as: ffafe2b75352673dbae846022f94d08b5f94e099b86f9041a7428b71f94303f5
- File type: pe · Size: 439354 bytes
- Verdict: malicious (100/100) · Family: Lmir
Detections (10 of 56 engines)
- capa (capabilities): capability:credential-access
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Lmir-24
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Virus:Win32/Viking.KI
- Emsisoft (Emergency Kit): Trojan.Agent.CGVL
- Kaspersky (KVRT): Trojan-GameThief.Win32.Lmir.oa
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 22 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Lmir-24 (rule
Win.Trojan.Lmir-24) - engine signal, weight 0.90, confidence 0.95 - 2 behavioral detection(s) across 2 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.63, confidence 0.90 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged Virus:Win32/Viking.KI (rule
Virus:Win32/Viking.KI) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent.CGVL (rule
Trojan.Agent.CGVL) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-GameThief.Win32.Lmir.oa (rule
Trojan-GameThief.Win32.Lmir.oa) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - Contacted 2 external host(s) and 17 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:credential-access (rule
capability:credential-access) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX (rule
UPX) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, Turbo Linker - static signal, weight 0.25, confidence 0.55
- Dropped 55 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis (windows)
32046 behavior events · 3 ATT&CK techniques · 58 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- edgedl.me.gvt1.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
Dropped files
- C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_acro.exe -
b8a9d5807917687ab25ef2c5759f7f1520fda63f734924b93c86e5524d0e7f68 - C:\Users\analyst\AppData\Local\Temp\tsk_13ce90911f534fe2.tmp -
215ca01c99e864395fa2e97bca4a1b54c5f681c642638d650365e9f87851dd85 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\jaccesswalker.exe -
4561863116383621f6ebcac666de82952ef760438b782fe7cdc4a0ab425b074a - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\java.exe -
6f4f5ba4947818ecba43740b926d66bf38c51bfb6c97a9bffaef9eab18a4ca62 - C:\Program Files\Google\Chrome\Application\152.0.7977.64\Installer\setup.exe -
a63d868de8ba69dd29adc59a81cf186401f2325ef1946e2f0dca69863a2413bf - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\kinit.exe -
b744029e1464afbf48affb00adb312317597482e87ec49da353eef502d1050a6 - C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\adobe_licensing_wf_helper_acro.exe -
377693e2ca6eefba36f61373194f572541a409cb10808b8c71d52897a6df3e8f - C:\Program Files\Google\Chrome\Application\152.0.7977.64\notification_helper.exe -
326465a5f7d397f27362662b299306f46aa11e2ac82a2cc263af8d1d0f48f36c - bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 -
bd115a575e86e61cea9136c5a2c47e090ba484dc2dee8b51a34111bb094266d5 - C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe -
d41bf0063203f1fa889c95915b4e9868ad0ffe18399bcee2a3c38886302daf79 - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe -
7fcde728d009a153fc970137632e1b52d07a971724df7f6fb0b206b06dc437d6 - C:\Program Files\Google\Chrome\Application\chrome.exe -
20a3cced221e80cad8a6775faa36df27e1677c7b1ca4136ff5fe2d7569057301 - C:\Program Files\LibreOffice\program\gengal.exe -
e0d8141ec31924645d05780fdb216e897d703493e9a8760d9dae683069a1b0e4 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\bin\javaw.exe -
5ff5247bf114cd59d2b8972641bbe43c33ca9a32f40f77467914065b508e1790 - C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe -
698f79937dc7b693633e00453acea137673a666e8b98c796d14fb8a41df1fdac
Embedded URLs
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/ea98f53a-04cb-4f17-b9d9-db88a4e098c7/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/ea98f53a-04cb-4f17-b9d9-db88a4e098c7?P1=1785377842&P2=404&P3=2&P4=l1E6ID%2bdP67CJpKOjU%2fX%2fGF9WXhFVyGpnE3i5Cg1PBeyqvAXwFOIHh5%2fQdq0yf4r1ZEEidf68dZXH8WxKtak%2fA%3d%3d&cacheHostOrigin=1D.tlu.dl.delivery.mp.microsoft.com
- http://c.pki.goog/r/r1.crl
- http://x2.c.lencr.org/
- http://ye.c.lencr.org/
- http://c.pki.goog/wr2/9UVbN0w5E6Y.crl
- http://yr.c.lencr.org/
Embedded domains
- crl.microsoft.com
- www.microsoft.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 184.84.165.168
- 40.79.167.9
- 4.230.171.124
- 85.210.196.11
- 4.149.210.175
- 4.150.223.104
- 74.179.77.204
- 4.150.223.98
- 135.232.92.97
- 135.233.95.144
- 52.123.252.203
- 4.209.250.170
- 34.104.35.123
- 20.184.175.1
- 20.184.175.4
- 203.26.79.13
- 52.110.12.40
- 52.110.12.47
- 72.154.7.109
- 52.148.114.188
More Lmir samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report