MALICIOUS — 62f70d166cf7b99eb80fa650f98645ce673227db2963999ab1fea4c3e3fd4d70
MALICIOUS — 62f70d166cf7b99eb80fa650f98645ce673227db2963999ab1fea4c3e3fd4d70 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
62f70d166cf7b99eb80fa650f98645ce673227db2963999ab1fea4c3e3fd4d70 - SHA-1:
cf530ff58c529d9b67b9e271847bfe78715de0ff - MD5:
f97983e69f72d06485a0b79753ce8c54 - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405666 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
MITRE ATT&CK
Dynamic analysis (windows)
6203 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- msedge.api.cdp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- kv801.prod.do.dsp.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/13709/files/ad59c197c98dab8602bd619c148f1340dd08cb5f7fa8acb149e08634ad14576b —
ad59c197c98dab8602bd619c148f1340dd08cb5f7fa8acb149e08634ad14576b - /opt/CAPEv2/storage/analyses/13709/files/89180552ae18e498cd0400e2135b5e795539b7088697bd3deaf7d44b9fc0e678 —
89180552ae18e498cd0400e2135b5e795539b7088697bd3deaf7d44b9fc0e678 - /opt/CAPEv2/storage/analyses/13709/files/39fc10f2057b28911f0d9bdcd9d9e22f8d38b6eea1d764909fea17deee0e0b22 —
39fc10f2057b28911f0d9bdcd9d9e22f8d38b6eea1d764909fea17deee0e0b22 - /opt/CAPEv2/storage/analyses/13709/files/e3d0422fea3295106a862bfed4cfddad4cac2011917845c87193721d8a4f568a —
e3d0422fea3295106a862bfed4cfddad4cac2011917845c87193721d8a4f568a - /opt/CAPEv2/storage/analyses/13709/files/dfd403e3b660239456c3b3ba43fd5ec9502b2e86c132d0ccde0fba73d517d838 —
dfd403e3b660239456c3b3ba43fd5ec9502b2e86c132d0ccde0fba73d517d838 - /opt/CAPEv2/storage/analyses/13709/files/9ebacebbc37f2565037d8e1ed392f48ef97c536abedc769db55a2b2fbe3f1ca9 —
9ebacebbc37f2565037d8e1ed392f48ef97c536abedc769db55a2b2fbe3f1ca9 - /opt/CAPEv2/storage/analyses/13709/files/8377ab6303a8401de594a893e172ea6a877faf5adeb73cee315242cbcd218249 —
8377ab6303a8401de594a893e172ea6a877faf5adeb73cee315242cbcd218249 - /opt/CAPEv2/storage/analyses/13709/files/d8f3728fc65f4eb971b40fee40ac38473de3fb485547c8d63e0472718c97c631 —
d8f3728fc65f4eb971b40fee40ac38473de3fb485547c8d63e0472718c97c631 - /opt/CAPEv2/storage/analyses/13709/files/d7ae119b8db8eb30e6b97f9901f48e598ab0aa83c5f2c529824fbb2d028f1886 —
d7ae119b8db8eb30e6b97f9901f48e598ab0aa83c5f2c529824fbb2d028f1886 - /opt/CAPEv2/storage/analyses/13709/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/13709/files/335047febbd3002ed3c08023e19076966eb0ac3b267f1e99d657606e05547ef8 —
335047febbd3002ed3c08023e19076966eb0ac3b267f1e99d657606e05547ef8 - /opt/CAPEv2/storage/analyses/13709/files/596479675e2cfb671166e49d17b94ff4c42606f30442811f446ca4cfee9b964a —
596479675e2cfb671166e49d17b94ff4c42606f30442811f446ca4cfee9b964a - /opt/CAPEv2/storage/analyses/13709/files/306a407b875cde3b291be38e9a5ba8263f7a9f3c2061008f597ee242036da43d —
306a407b875cde3b291be38e9a5ba8263f7a9f3c2061008f597ee242036da43d - /opt/CAPEv2/storage/analyses/13709/files/08930b1aa4680f1d1120e3c22a37b4630d3109a95d11f06939209de9ab88485d —
08930b1aa4680f1d1120e3c22a37b4630d3109a95d11f06939209de9ab88485d - /opt/CAPEv2/storage/analyses/13709/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786555415&P2=404&P3=2&P4=MAoAmP4WFQ%2bhG8h6T1weIIXtF5VnOR06LSvS%2bNP9tYC%2fo4vCAYAywIx0pBhp8AjuuzDtMRcm8JdQumKBJIJFSA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786555459&P2=404&P3=2&P4=W5EoVKhdkNXoi7AZWJHlkdJ16dMBM93CGJ8WDXk0YTB8ilL8A2is0%2fbWc0sO4jg1POENZuYyHatnlf6fnu9CQQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 4.247.188.233
- 51.11.192.49
- 20.247.185.124
- 52.123.252.212
- 4.230.171.124
- 48.211.4.16
- 74.178.76.128
- 20.165.94.54
- 20.42.65.84
- 74.178.232.29
- 203.26.79.13
- 135.233.45.223
- 52.110.12.28
- 52.110.12.2
- 162.159.142.9
- 72.153.5.131
- 4.150.223.96
- 52.168.112.66
- 52.148.114.188
- 92.223.78.30
- 52.110.12.26
- 52.110.12.31
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report