MALICIOUS — 6790aa575aed0a876a0a5f55c52eff9f3d477f721b9cc7394e6056b5cddc7228
MALICIOUS — 6790aa575aed0a876a0a5f55c52eff9f3d477f721b9cc7394e6056b5cddc7228 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
6790aa575aed0a876a0a5f55c52eff9f3d477f721b9cc7394e6056b5cddc7228 - SHA-1:
0bb24546230a12ddb7a25ee97160f1e9ad47419c - MD5:
22f8672240d253f3af00fc1d90351d0e - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Dynamic analysis (windows)
6492 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
- msedge.api.cdp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/14128/files/17591ba61d01834c8b1457a8f61ae3dca8b1c650efd58e52f072ee5dcfa78d44 —
17591ba61d01834c8b1457a8f61ae3dca8b1c650efd58e52f072ee5dcfa78d44 - /opt/CAPEv2/storage/analyses/14128/files/8a9f1d3075da6e9130b780b9a1cf4bfba16d2a74ed3f2899c77cbd1ada6ec979 —
8a9f1d3075da6e9130b780b9a1cf4bfba16d2a74ed3f2899c77cbd1ada6ec979 - /opt/CAPEv2/storage/analyses/14128/files/0a63574f5d8218d63198f49648fc517002cba8191ef8e4be56d3ddbe85025dd8 —
0a63574f5d8218d63198f49648fc517002cba8191ef8e4be56d3ddbe85025dd8 - /opt/CAPEv2/storage/analyses/14128/files/dd8b1eb6c14b80e3109fefef15bcfe8b9becc8d3395ecd826515ab46404db0d7 —
dd8b1eb6c14b80e3109fefef15bcfe8b9becc8d3395ecd826515ab46404db0d7 - /opt/CAPEv2/storage/analyses/14128/files/3cfe77a3df18c16e998220e25cdba149359e8c8d227e16717dad191eadf3e2f0 —
3cfe77a3df18c16e998220e25cdba149359e8c8d227e16717dad191eadf3e2f0 - /opt/CAPEv2/storage/analyses/14128/files/6bd6b8160e13a747d453cfb8b4d5dfa4207ff651883fda2efd8ea0c21fdecfc3 —
6bd6b8160e13a747d453cfb8b4d5dfa4207ff651883fda2efd8ea0c21fdecfc3 - /opt/CAPEv2/storage/analyses/14128/files/5c52fccd8a1ff109d12da38f19a219995659d7b97a1e1a0b234a6b99a4ebe709 —
5c52fccd8a1ff109d12da38f19a219995659d7b97a1e1a0b234a6b99a4ebe709 - /opt/CAPEv2/storage/analyses/14128/files/3068c89ce1d027f6903346ba7fa1ac2a40a98fe81e6371ba20f31b99ab472a87 —
3068c89ce1d027f6903346ba7fa1ac2a40a98fe81e6371ba20f31b99ab472a87 - /opt/CAPEv2/storage/analyses/14128/files/ad350f97e8138984f5029828fd6538093b02f0f3930f8d046fa9d2944aab2cf7 —
ad350f97e8138984f5029828fd6538093b02f0f3930f8d046fa9d2944aab2cf7 - /opt/CAPEv2/storage/analyses/14128/files/3f7be009635bc5700f0a95c6fe40fda0f737c0413ed11dc17fc8e08c9d411785 —
3f7be009635bc5700f0a95c6fe40fda0f737c0413ed11dc17fc8e08c9d411785 - /opt/CAPEv2/storage/analyses/14128/files/7e849338f22e92d64b6baaa1ca194a58023c9737785b765c677226e271ccf663 —
7e849338f22e92d64b6baaa1ca194a58023c9737785b765c677226e271ccf663 - /opt/CAPEv2/storage/analyses/14128/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/14128/files/f704bad278742ec53923235d5f0f01b2e059d08c7b9b7b387b1b1cf5004d1678 —
f704bad278742ec53923235d5f0f01b2e059d08c7b9b7b387b1b1cf5004d1678 - /opt/CAPEv2/storage/analyses/14128/files/5bf185b8d17d5c6002847580a47e387d7acb79ebd9a451478b949cb1dafc8299 —
5bf185b8d17d5c6002847580a47e387d7acb79ebd9a451478b949cb1dafc8299 - /opt/CAPEv2/storage/analyses/14128/files/9e9e7d1addd63585b1a30591f6c1631d4c3fb5650022641bd2179160355f6b1c —
9e9e7d1addd63585b1a30591f6c1631d4c3fb5650022641bd2179160355f6b1c
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786566430&P2=404&P3=2&P4=DyF7lrKWHOho44wYeG4va4HNq3LfCUeGpVpfwIASFRiAx34sbbQlDgWscbHUkW%2f5rO8nq4tlRd35XXlwdi95OQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786566446&P2=404&P3=2&P4=NcZGo%2bFM9QQ45I5rDbXl3dKNLB5rJqvJz1GR5Hf9kmwCJiwR5w%2bmzIM6%2bbOB%2bybUAPJaBE1ZOOkIMgG9CBz%2fEA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 20.42.73.24
- 52.123.252.194
- 57.155.104.224
- 4.230.171.124
- 52.253.84.76
- 74.178.240.61
- 20.165.94.54
- 20.165.94.63
- 52.168.112.66
- 4.150.223.104
- 52.123.252.203
- 74.178.76.44
- 203.26.79.13
- 172.178.240.162
- 162.159.142.9
- 20.184.175.2
- 4.150.223.100
- 72.154.7.110
- 35.201.112.186
- 34.8.38.243
- 34.117.162.98
- 35.186.224.24
- 52.148.114.188
- 52.110.12.18
- 52.110.12.26
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report