MALICIOUS — 21bfa97571ffc1c1ddeefe7cef46a3344b5807dc100a1b03251dec51d5864df9
MALICIOUS — 21bfa97571ffc1c1ddeefe7cef46a3344b5807dc100a1b03251dec51d5864df9 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
21bfa97571ffc1c1ddeefe7cef46a3344b5807dc100a1b03251dec51d5864df9 - SHA-1:
f1143e14684632ac767ddf86233245cc02086294 - MD5:
128e78142ff5045fcdc2bb9b4612631b - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
MITRE ATT&CK
Dynamic analysis (windows)
6199 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- www.bing.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/13766/files/fdb23abff353ded3d431aa97d2c660f41535742483e6dcef4699ce02351be4ea —
fdb23abff353ded3d431aa97d2c660f41535742483e6dcef4699ce02351be4ea - /opt/CAPEv2/storage/analyses/13766/files/44bb521832966d0f58cfd0c0da6bf73b56c385f42c974dab7706f56128f60022 —
44bb521832966d0f58cfd0c0da6bf73b56c385f42c974dab7706f56128f60022 - /opt/CAPEv2/storage/analyses/13766/files/e9c144f74115bda75f5f97cb708872a8d29a958483ee8f4efc87afb2b98b6b60 —
e9c144f74115bda75f5f97cb708872a8d29a958483ee8f4efc87afb2b98b6b60 - /opt/CAPEv2/storage/analyses/13766/files/41d06164de5ada96620598b1d0d2ff748f800a428b5c9f68fe0782b4d5365120 —
41d06164de5ada96620598b1d0d2ff748f800a428b5c9f68fe0782b4d5365120 - /opt/CAPEv2/storage/analyses/13766/files/41d1a2a902f8efb2a979ca95b1eea7ec2fbe094ed4e45830ba44460745b5603a —
41d1a2a902f8efb2a979ca95b1eea7ec2fbe094ed4e45830ba44460745b5603a - /opt/CAPEv2/storage/analyses/13766/files/7b7a1f09107e1bfec8bf97253c5b8ff485b97fedd5080f71f425f61b1902bf20 —
7b7a1f09107e1bfec8bf97253c5b8ff485b97fedd5080f71f425f61b1902bf20 - /opt/CAPEv2/storage/analyses/13766/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/13766/files/dcbf02b671cb513a9140c2e4293169d006a4070b20f8d0f0f20a72c5cd9c6ddd —
dcbf02b671cb513a9140c2e4293169d006a4070b20f8d0f0f20a72c5cd9c6ddd - /opt/CAPEv2/storage/analyses/13766/files/4e0e18c0d52d3f1a27d0f93ea9b483b59b1a100a76d09c85965763318d3bd51c —
4e0e18c0d52d3f1a27d0f93ea9b483b59b1a100a76d09c85965763318d3bd51c - /opt/CAPEv2/storage/analyses/13766/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - /opt/CAPEv2/storage/analyses/13766/files/9dcb3e10b4b7775e935baaf0debf52e93a639f175daed20743ae9ab3f50fd970 —
9dcb3e10b4b7775e935baaf0debf52e93a639f175daed20743ae9ab3f50fd970 - /opt/CAPEv2/storage/analyses/13766/files/b08b9cf894fdc76ed057ac08a3019b64d2703afa5cb9dc24ee22cbb8b85ce0a6 —
b08b9cf894fdc76ed057ac08a3019b64d2703afa5cb9dc24ee22cbb8b85ce0a6 - /opt/CAPEv2/storage/analyses/13766/files/3dd10b51f4dda10c55822f701981b9aeeea9e9d9527e51c2640e7ee91b418fc8 —
3dd10b51f4dda10c55822f701981b9aeeea9e9d9527e51c2640e7ee91b418fc8 - /opt/CAPEv2/storage/analyses/13766/files/c04128fa617d2a10cd59b63881e659b725d7ddd3a119145f6c0fbbec686c7c68 —
c04128fa617d2a10cd59b63881e659b725d7ddd3a119145f6c0fbbec686c7c68 - /opt/CAPEv2/storage/analyses/13766/files/a42e57db93b93ecb2224fdb1276f4ebb0b6705cc4a95ec1899772df8dc47a684 —
a42e57db93b93ecb2224fdb1276f4ebb0b6705cc4a95ec1899772df8dc47a684
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786556687&P2=404&P3=2&P4=YSPtBooAuy0LckfdUss64VVYDcTiz5fUGXTq2S63lNkDbBZ6PCTgz9vw1be2gkMC5%2fYJRaBaEWtVFCIQq%2fOkEg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786556729&P2=404&P3=2&P4=UNqBHzpTFRpt8D9WLUH6Ef2YLLHNxzwjHmZJNgiIsLvSm36pOzork1nh67IQQ6nOeBtJTDAV1FttJbKuh0YZRA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 35.186.224.24
- 20.184.175.11
- 34.117.162.98
- 4.230.171.124
- 48.211.4.16
- 52.230.59.222
- 135.233.95.144
- 74.178.240.51
- 20.42.65.90
- 4.150.223.114
- 172.178.240.163
- 203.26.79.13
- 135.232.92.34
- 20.42.73.26
- 72.145.35.109
- 52.148.114.188
- 20.165.94.46
- 52.110.12.50
- 52.110.12.37
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report