MALICIOUS — 337cec34b4b229616d4cb1906f11a25c78a3b27fe1530af729af4ee3815306ce
MALICIOUS — 337cec34b4b229616d4cb1906f11a25c78a3b27fe1530af729af4ee3815306ce is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
337cec34b4b229616d4cb1906f11a25c78a3b27fe1530af729af4ee3815306ce - SHA-1:
7e9d36a0271328107dcd0abebf92fdd93ec6aa9b - MD5:
140ddb6967be7664081f40e0b6b1be80 - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
MITRE ATT&CK
Dynamic analysis (windows)
6242 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- www.bing.com
- assets.msn.com
- licensing.mp.microsoft.com
- tas02.sls.update.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/14130/files/a5d4eb499d0f2b48812dde69e77cb2df7e74382674e16397f59c283df160c65a —
a5d4eb499d0f2b48812dde69e77cb2df7e74382674e16397f59c283df160c65a - /opt/CAPEv2/storage/analyses/14130/files/fa1e131a971d936419400540a9dc09b398922374d511f8ee1b61c4eb30844340 —
fa1e131a971d936419400540a9dc09b398922374d511f8ee1b61c4eb30844340 - /opt/CAPEv2/storage/analyses/14130/files/66bf6c0fffb947f3cd393bf24afe56a60baaef6c356a5dbe8b4597e6b826fba2 —
66bf6c0fffb947f3cd393bf24afe56a60baaef6c356a5dbe8b4597e6b826fba2 - /opt/CAPEv2/storage/analyses/14130/files/cb445aba9c90699b16fd15b1056e22f575d66513a73bbce1ddbabefcc2910728 —
cb445aba9c90699b16fd15b1056e22f575d66513a73bbce1ddbabefcc2910728 - /opt/CAPEv2/storage/analyses/14130/files/c59d6a32def6981bc87474636a6aec9c3503db5fc41c549c7225392e4cf4e33d —
c59d6a32def6981bc87474636a6aec9c3503db5fc41c549c7225392e4cf4e33d - /opt/CAPEv2/storage/analyses/14130/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/14130/files/0adaf749c52a0896ab6f994dc22794d1c1ca72675a1186172698a14b66e92038 —
0adaf749c52a0896ab6f994dc22794d1c1ca72675a1186172698a14b66e92038 - /opt/CAPEv2/storage/analyses/14130/files/cbabf35dcb528dd03211005fdb4ca9873d4386671e7d8cd8596f83c17241312d —
cbabf35dcb528dd03211005fdb4ca9873d4386671e7d8cd8596f83c17241312d - /opt/CAPEv2/storage/analyses/14130/files/6740e4307c539454177af224c5ef8da96feda528dbb5886318704057240fa560 —
6740e4307c539454177af224c5ef8da96feda528dbb5886318704057240fa560 - /opt/CAPEv2/storage/analyses/14130/files/135490141eef731fd1c68144dc24e7dc9c064e003468dfe9faf202e621fe2706 —
135490141eef731fd1c68144dc24e7dc9c064e003468dfe9faf202e621fe2706 - /opt/CAPEv2/storage/analyses/14130/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - /opt/CAPEv2/storage/analyses/14130/files/1d5b64467cc1253d66fbdd11becfc9693c14381d2aea8b2cb402f59fd5af3351 —
1d5b64467cc1253d66fbdd11becfc9693c14381d2aea8b2cb402f59fd5af3351 - /opt/CAPEv2/storage/analyses/14130/files/e7cb319411d26c22014c958ce7269ddc6a782b27b9ac388fa966300005699b28 —
e7cb319411d26c22014c958ce7269ddc6a782b27b9ac388fa966300005699b28 - /opt/CAPEv2/storage/analyses/14130/files/b7631238c8a52526c266ccfbe10f455a580f2024f7814658ce04e64ac5eece70 —
b7631238c8a52526c266ccfbe10f455a580f2024f7814658ce04e64ac5eece70 - /opt/CAPEv2/storage/analyses/14130/files/2c35fdf7b86cf9ed164bf58822b07361f5bc495a7aa5acdc73c45812700bb89d —
2c35fdf7b86cf9ed164bf58822b07361f5bc495a7aa5acdc73c45812700bb89d
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786566488&P2=404&P3=2&P4=nhxXZQt6%2bL5sy6keLmZqlDay%2bhLZpiFGuhinQq1GDtw6yiuSjB%2bix50ojc6AV3Q%2bIs97XVnhygRlX0vbEIb0JA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786566569&P2=404&P3=2&P4=AkI7I%2bF17p0ekqeZwsFUbDIieTAf5bikgeVafbPW7NircXGqRQEJUM2HRwUo8tqqI0Pvku91EWTNaSu6fin75A%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 4.150.223.104
- 52.123.252.203
- 52.110.12.54
- 52.110.12.50
- 4.230.171.124
- 40.84.85.40
- 4.144.132.223
- 20.165.94.63
- 20.165.94.54
- 4.150.223.114
- 20.42.73.25
- 135.233.45.223
- 162.159.142.9
- 203.26.79.13
- 74.178.76.44
- 20.165.94.46
- 72.153.5.130
- 52.148.114.188
- 52.110.12.3
- 52.110.12.49
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report