MALICIOUS — 4a63b116cbc8ebfeedd0e5d81ec8e8d1d8cf4ea36ee37881da5f2bc9774b6b27
MALICIOUS — 4a63b116cbc8ebfeedd0e5d81ec8e8d1d8cf4ea36ee37881da5f2bc9774b6b27 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
4a63b116cbc8ebfeedd0e5d81ec8e8d1d8cf4ea36ee37881da5f2bc9774b6b27 - SHA-1:
b93065de305fb3180e43f5af3360d5628cb716c7 - MD5:
c1257c67a2d565a00b685a159e4bac99 - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Dynamic analysis (windows)
6232 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- assets.msn.com
- licensing.mp.microsoft.com
- msedge.api.cdp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- www.bing.com
- tas02.sls.update.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/13769/files/6c15e1d343a5896be4ba8b31827cfa43bd51316970a5192c54ab52e3eeaa418e —
6c15e1d343a5896be4ba8b31827cfa43bd51316970a5192c54ab52e3eeaa418e - /opt/CAPEv2/storage/analyses/13769/files/955fca722125f283074f1eb1b88fec02284302e5784f0e15197beb6436279336 —
955fca722125f283074f1eb1b88fec02284302e5784f0e15197beb6436279336 - /opt/CAPEv2/storage/analyses/13769/files/eaca45cd87a05ea75bf3c523edefddee7f554a780578493268fe82002c2e7d9f —
eaca45cd87a05ea75bf3c523edefddee7f554a780578493268fe82002c2e7d9f - /opt/CAPEv2/storage/analyses/13769/files/5e12fd37430d1c10b4a533e8e3c52bb64296dfd5cd805e94b1f115e98ef0602f —
5e12fd37430d1c10b4a533e8e3c52bb64296dfd5cd805e94b1f115e98ef0602f - /opt/CAPEv2/storage/analyses/13769/files/bbe18a20910c8a67b906b661c6ff76c39212ce3f4ca8ede1c532834572fd5853 —
bbe18a20910c8a67b906b661c6ff76c39212ce3f4ca8ede1c532834572fd5853 - /opt/CAPEv2/storage/analyses/13769/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/13769/files/0a8a5401ff6a92f1d363a6478ca8ef5b74a8970ed6798800e639764ba6d69f8a —
0a8a5401ff6a92f1d363a6478ca8ef5b74a8970ed6798800e639764ba6d69f8a - /opt/CAPEv2/storage/analyses/13769/files/995ca45011100ce86ac929798727e00d6c20dc566b99e2a625bf0dabca5df9d7 —
995ca45011100ce86ac929798727e00d6c20dc566b99e2a625bf0dabca5df9d7 - /opt/CAPEv2/storage/analyses/13769/files/ffa5c9938d5aaa22d07d4a82eec79e964eb493301695be02a9a0b5d069aedfa4 —
ffa5c9938d5aaa22d07d4a82eec79e964eb493301695be02a9a0b5d069aedfa4 - /opt/CAPEv2/storage/analyses/13769/files/ce70e7a599a3a5fc08f6bbee87d5486e0fdd901c2f6259f129ebb6db1629a294 —
ce70e7a599a3a5fc08f6bbee87d5486e0fdd901c2f6259f129ebb6db1629a294 - /opt/CAPEv2/storage/analyses/13769/files/6174c7fd4e275cc1175dbb8664c415796892f6beac075d613c4012d8c6f1e40f —
6174c7fd4e275cc1175dbb8664c415796892f6beac075d613c4012d8c6f1e40f - /opt/CAPEv2/storage/analyses/13769/files/75e060147c07486f26157ea96c4a000ded38d6b1c614b51244fe59aff158a4f4 —
75e060147c07486f26157ea96c4a000ded38d6b1c614b51244fe59aff158a4f4 - /opt/CAPEv2/storage/analyses/13769/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - /opt/CAPEv2/storage/analyses/13769/files/bc37f1235a146c9f970283630b7703499def6abbf4a46431bf469fda16a956fc —
bc37f1235a146c9f970283630b7703499def6abbf4a46431bf469fda16a956fc - /opt/CAPEv2/storage/analyses/13769/files/c36c40ee9efe917c039c4dcde9985ff53332191bd4b669880d80b1a3e76c5af6 —
c36c40ee9efe917c039c4dcde9985ff53332191bd4b669880d80b1a3e76c5af6
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786556747&P2=404&P3=2&P4=n0U8FMidl5X6Ih1dIgb7MTD159GzWPeV6zeCzPXMK25Hz06vEAzVvty2NszGKJkvl7sxiycnhHBTay1pJXe5Bg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786556804&P2=404&P3=2&P4=e32KVPxiTOEZr1NnBLGny2OhgBZi4qFxGN3ii2aWt0DcNhZrSszm%2fdMjMaLC1pLmCVY6Oo1eu1Ji43ShnTiLaA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 4.150.223.100
- 4.230.171.124
- 48.211.4.16
- 20.247.184.142
- 135.233.95.144
- 4.150.223.114
- 74.178.76.54
- 52.123.252.223
- 20.165.94.46
- 203.26.79.13
- 135.234.160.245
- 4.150.223.104
- 20.50.73.5
- 72.145.35.109
- 52.148.114.188
- 92.223.78.30
- 52.110.12.19
- 52.110.12.54
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report