MALICIOUS — 6ecd7801497396085646d579ede5420b2aa70edc27049ab55813bedf0b12a7f5
MALICIOUS — 6ecd7801497396085646d579ede5420b2aa70edc27049ab55813bedf0b12a7f5 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
6ecd7801497396085646d579ede5420b2aa70edc27049ab55813bedf0b12a7f5 - SHA-1:
7080d39a4cd245fe1224be116332582f34579e2a - MD5:
2117b79d2d436f94e6b2154f80e49bb8 - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Dynamic analysis (windows)
6157 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- msedge.api.cdp.microsoft.com
- settings-win.data.microsoft.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- geo.prod.do.dsp.mp.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
- kv801.prod.do.dsp.mp.microsoft.com
- cp801.prod.do.dsp.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/13776/files/33dfa3769cdf89d2d82afc44806fa2b47da7610231d6ae604075321fe975cc27 —
33dfa3769cdf89d2d82afc44806fa2b47da7610231d6ae604075321fe975cc27 - /opt/CAPEv2/storage/analyses/13776/files/41013d3e357b2316a98c777b595708f295798b63f64b9f9ab9ac8f3559496466 —
41013d3e357b2316a98c777b595708f295798b63f64b9f9ab9ac8f3559496466 - /opt/CAPEv2/storage/analyses/13776/files/8632fa2c2b942a6128b96f9fc998482c0f7cc1a95e72ed7011f420752288c05f —
8632fa2c2b942a6128b96f9fc998482c0f7cc1a95e72ed7011f420752288c05f - /opt/CAPEv2/storage/analyses/13776/files/27a861b6b481ed0ee1eebe4bc8b71867d2b5f2f9fb53281252d02456deb2a823 —
27a861b6b481ed0ee1eebe4bc8b71867d2b5f2f9fb53281252d02456deb2a823 - /opt/CAPEv2/storage/analyses/13776/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/13776/files/eaca8919442060378d24c01f8ca28bc74017702ac96e16d11d289cd9f6d1c229 —
eaca8919442060378d24c01f8ca28bc74017702ac96e16d11d289cd9f6d1c229 - /opt/CAPEv2/storage/analyses/13776/files/22d8dabaae32761caffebf7a448e43c5785e0799eba54bbda36a405e820e7dc6 —
22d8dabaae32761caffebf7a448e43c5785e0799eba54bbda36a405e820e7dc6 - /opt/CAPEv2/storage/analyses/13776/files/816becf64e7dc004431ea938b16cf2fe02a0e8b1c2a1a85ae4862beae173956a —
816becf64e7dc004431ea938b16cf2fe02a0e8b1c2a1a85ae4862beae173956a - /opt/CAPEv2/storage/analyses/13776/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - /opt/CAPEv2/storage/analyses/13776/files/5fb41e7f292e9665ad11c27161deeba1861f1204634346fe8851978500e6182d —
5fb41e7f292e9665ad11c27161deeba1861f1204634346fe8851978500e6182d - /opt/CAPEv2/storage/analyses/13776/files/a42e57db93b93ecb2224fdb1276f4ebb0b6705cc4a95ec1899772df8dc47a684 —
a42e57db93b93ecb2224fdb1276f4ebb0b6705cc4a95ec1899772df8dc47a684 - /opt/CAPEv2/storage/analyses/13776/files/6cd3d18b904c001f4b1ec5ffa6adc80fc1b4a2da9f47a983af48fd019826060d —
6cd3d18b904c001f4b1ec5ffa6adc80fc1b4a2da9f47a983af48fd019826060d - /opt/CAPEv2/storage/analyses/13776/files/a17185407f2d595f5cb08f44b35a960ac363498ec38df4e950f36043cbcc329e —
a17185407f2d595f5cb08f44b35a960ac363498ec38df4e950f36043cbcc329e - /opt/CAPEv2/storage/analyses/13776/files/e67282065291084c9ab91dc3ca231142f61af8e654ad511bc4dcfe4dc28e1fe0 —
e67282065291084c9ab91dc3ca231142f61af8e654ad511bc4dcfe4dc28e1fe0 - /opt/CAPEv2/storage/analyses/13776/files/2731bad4684babf91d11f21ba56f8ae32b6d6a864c4c0972425c340d591ad40f —
2731bad4684babf91d11f21ba56f8ae32b6d6a864c4c0972425c340d591ad40f
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786556901&P2=404&P3=2&P4=gfhvVlI2P6tNGuQfIVFC5nXQtQQ%2fwdPxYmVeSPm%2fSNIlOgtWz9N96PZtoP%2b67jZhv%2f20ODPGhN6lq1vT04Wp1g%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786556959&P2=404&P3=2&P4=Hj2qjxUCVbB8%2bkFG7g%2bVG7s4mOnPByy%2fyRAaHzBg9rXqT4dniNou8GE2t0jOySlJQLupmFmoqcyogHz7Xorymw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 20.42.73.31
- 4.247.188.224
- 4.230.171.124
- 4.144.132.223
- 74.178.76.128
- 51.104.15.253
- 74.178.76.54
- 104.46.162.231
- 20.165.94.46
- 203.26.79.13
- 135.234.160.245
- 72.145.35.99
- 52.110.12.14
- 52.110.12.50
- 74.178.76.44
- 52.110.12.3
- 52.148.114.188
- 52.110.12.16
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report