MALICIOUS — 174bf4c86f1cfc69a2189d38f595f753f001a773cefeea9d697c0e90ad68cc98
MALICIOUS — 174bf4c86f1cfc69a2189d38f595f753f001a773cefeea9d697c0e90ad68cc98 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
174bf4c86f1cfc69a2189d38f595f753f001a773cefeea9d697c0e90ad68cc98 - SHA-1:
63e27b0be19c99143989da5db4572e78b22035d9 - MD5:
feede4534f24af510f6ccf2ac6c54c47 - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Dynamic analysis (windows)
6342 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- settings-win.data.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
- tas02.sls.update.microsoft.com
- www.bing.com
Dropped files
- /opt/CAPEv2/storage/analyses/14218/files/fc0e06d968602cca6e1c0dad7b3f9fff782c9005607c758ac087f06e8e0982f7 —
fc0e06d968602cca6e1c0dad7b3f9fff782c9005607c758ac087f06e8e0982f7 - /opt/CAPEv2/storage/analyses/14218/files/7b16ef5121f88b1926a66fa34f79cb4c6d9402f3f30ba8c1bc788797816de0bf —
7b16ef5121f88b1926a66fa34f79cb4c6d9402f3f30ba8c1bc788797816de0bf - /opt/CAPEv2/storage/analyses/14218/files/3fe9d6bd8487067bc709af61e7b396b230032f600e982ca7dd55d3a7288b3a08 —
3fe9d6bd8487067bc709af61e7b396b230032f600e982ca7dd55d3a7288b3a08 - /opt/CAPEv2/storage/analyses/14218/files/07b26a67afcd62d3a243ea20ba176d93c6d50d396f2813f3f1616ec569700c5f —
07b26a67afcd62d3a243ea20ba176d93c6d50d396f2813f3f1616ec569700c5f - /opt/CAPEv2/storage/analyses/14218/files/b35ba455ea9dddb1a052d225765933f791ac3a5d160d4811320c1f31470d3059 —
b35ba455ea9dddb1a052d225765933f791ac3a5d160d4811320c1f31470d3059 - /opt/CAPEv2/storage/analyses/14218/files/f68ed493e88ac9862d73b993ecae6cb46fcda004e9660a34d1bc0730a3654489 —
f68ed493e88ac9862d73b993ecae6cb46fcda004e9660a34d1bc0730a3654489 - /opt/CAPEv2/storage/analyses/14218/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/14218/files/ba2c3fbcbf501ae5221ce3453fb0e2edbac3b44ecf81a4879f87bdcbbb783500 —
ba2c3fbcbf501ae5221ce3453fb0e2edbac3b44ecf81a4879f87bdcbbb783500 - /opt/CAPEv2/storage/analyses/14218/files/d9fe1d3e764f83f416cd740f84b7e2f4dd54aed534fcd9a3bea2fa7a73c1b57a —
d9fe1d3e764f83f416cd740f84b7e2f4dd54aed534fcd9a3bea2fa7a73c1b57a - /opt/CAPEv2/storage/analyses/14218/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - /opt/CAPEv2/storage/analyses/14218/files/7a7031ea822cd9f2b7b93e8290f2023a1a19817b9f127b06ff50310a18498eac —
7a7031ea822cd9f2b7b93e8290f2023a1a19817b9f127b06ff50310a18498eac - /opt/CAPEv2/storage/analyses/14218/files/c1f6bcc0e92354cd282616acda120f45ebe85ee038ce18a51cfe9babbf812491 —
c1f6bcc0e92354cd282616acda120f45ebe85ee038ce18a51cfe9babbf812491 - /opt/CAPEv2/storage/analyses/14218/files/72375af0ba794cbe0fa04d47b23f251bfd3a8c750489a823a85c39f763625d92 —
72375af0ba794cbe0fa04d47b23f251bfd3a8c750489a823a85c39f763625d92 - /opt/CAPEv2/storage/analyses/14218/files/a42e57db93b93ecb2224fdb1276f4ebb0b6705cc4a95ec1899772df8dc47a684 —
a42e57db93b93ecb2224fdb1276f4ebb0b6705cc4a95ec1899772df8dc47a684 - /opt/CAPEv2/storage/analyses/14218/files/f54196c29c577b93b4def2ca5c3b3fa8ebb397bc4c7173500c9474d289f2ce88 —
f54196c29c577b93b4def2ca5c3b3fa8ebb397bc4c7173500c9474d289f2ce88
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786568769&P2=404&P3=2&P4=CpVJvSBVQ2qsUtp5kF%2bihvi4rYZYAO7Di4y1G4KSSIQwKPPU%2bg8Rdk12fASUu2b3fFQ7z2bJEiWKneQw2LUrZg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786568846&P2=404&P3=2&P4=R50WkXbZpNklzDu8p9dOeiR4acigQL7TWNdhZRLrxkcXgdmsz5XhZ6uDjNan9iAzBf%2buIjr4D5P%2f0CXuSW1ylg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 52.178.17.234
- 20.42.179.204
- 4.230.171.124
- 20.247.184.142
- 20.165.94.63
- 135.233.95.135
- 4.150.223.105
- 74.178.76.128
- 172.178.240.161
- 92.223.78.30
- 203.26.79.13
- 162.159.142.9
- 20.165.94.46
- 184.84.165.136
- 85.210.196.11
- 72.154.7.112
- 52.148.114.188
- 52.110.12.38
- 52.110.12.19
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report