MALICIOUS — 6faf86c52fa0c452fc9e8bfb048e1b17c201e9be4123b85b4ae938fefe767165
MALICIOUS — 6faf86c52fa0c452fc9e8bfb048e1b17c201e9be4123b85b4ae938fefe767165 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
6faf86c52fa0c452fc9e8bfb048e1b17c201e9be4123b85b4ae938fefe767165 - SHA-1:
da08d4bae1913db7f47712291b0981e929956397 - MD5:
31bbdc88b18949d770afff5dc35b0fe5 - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
MITRE ATT&CK
Dynamic analysis (windows)
6339 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
- officeclient.microsoft.com
- licensing.mp.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/14161/files/6ccd8f1d63b6dd10aad176609a472f72e0c6257eb31744d3185b4889f795ad39 —
6ccd8f1d63b6dd10aad176609a472f72e0c6257eb31744d3185b4889f795ad39 - /opt/CAPEv2/storage/analyses/14161/files/7b31990d9065efa937261778fd2c346c65293ae7a9a8525597baf71f9ed89072 —
7b31990d9065efa937261778fd2c346c65293ae7a9a8525597baf71f9ed89072 - /opt/CAPEv2/storage/analyses/14161/files/cd7b2158974757fe838b367cb2d88872e5c2b9d5dbafe6b289985264835a4e5b —
cd7b2158974757fe838b367cb2d88872e5c2b9d5dbafe6b289985264835a4e5b - /opt/CAPEv2/storage/analyses/14161/files/ea6564fb5e7db79a5da983a4b904f1cb4b6813ec81eac5636f400096449b11eb —
ea6564fb5e7db79a5da983a4b904f1cb4b6813ec81eac5636f400096449b11eb - /opt/CAPEv2/storage/analyses/14161/files/a343a8d1d0cfff623afbcb073211034849bd0834beb07bc2b9c88c6fe93edd88 —
a343a8d1d0cfff623afbcb073211034849bd0834beb07bc2b9c88c6fe93edd88 - /opt/CAPEv2/storage/analyses/14161/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/14161/files/7ac11d0d423a91c2ba4fdcd611de64e3f536193d500a0ce1cda800d859ab7f2a —
7ac11d0d423a91c2ba4fdcd611de64e3f536193d500a0ce1cda800d859ab7f2a - /opt/CAPEv2/storage/analyses/14161/files/7dbe45a2b0a65fee2d9ee693a1c49830cbb26d8db4acf400f05634defae67490 —
7dbe45a2b0a65fee2d9ee693a1c49830cbb26d8db4acf400f05634defae67490 - /opt/CAPEv2/storage/analyses/14161/files/13e2f2aa132d297a326c7d747b226ee01d73c448626425b19e498d7725c6f965 —
13e2f2aa132d297a326c7d747b226ee01d73c448626425b19e498d7725c6f965 - /opt/CAPEv2/storage/analyses/14161/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - /opt/CAPEv2/storage/analyses/14161/files/532afbc74855ae5ed29b7828a5ec6ab4e8f7b7790e248ed5d0b10e251e0cc50c —
532afbc74855ae5ed29b7828a5ec6ab4e8f7b7790e248ed5d0b10e251e0cc50c - /opt/CAPEv2/storage/analyses/14161/files/39b8cf775f59ecaab0b1e04c674b5ed806f505386f1f7338d73520d071b8a3b7 —
39b8cf775f59ecaab0b1e04c674b5ed806f505386f1f7338d73520d071b8a3b7 - /opt/CAPEv2/storage/analyses/14161/files/7991e429ae831c325461804f6ca37fe29b301ccea8414f0de6081a13e9f36454 —
7991e429ae831c325461804f6ca37fe29b301ccea8414f0de6081a13e9f36454 - /opt/CAPEv2/storage/analyses/14161/files/5c5b09e8054aeb4d29360951815f62e3423b9a4fd2d3dea1ee28ba054da2888e —
5c5b09e8054aeb4d29360951815f62e3423b9a4fd2d3dea1ee28ba054da2888e - /opt/CAPEv2/storage/analyses/14161/files/4571e13d86ceaaa7fa8e4e6041c7212cb5deb27313cb464a59effbfe94d5c571 —
4571e13d86ceaaa7fa8e4e6041c7212cb5deb27313cb464a59effbfe94d5c571
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786567276&P2=404&P3=2&P4=S1h3KBeYPU%2f6pbzAufvYGxKJekmCgLeA3KdqAqLb4Qjlj%2blVHC445yeeOe4ZYneUBWgnyeyQ%2f8eQhPluaylwAw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786567295&P2=404&P3=2&P4=BqWNBk228cKUkqP7gCzLmcGC01vs76Ktk3gbNwflk7kO6J8QqITrKl%2fDlZDwXXUmCW283PBtSX%2btjjoWl7yIUA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 13.69.116.109
- 57.155.101.212
- 20.247.185.124
- 4.230.171.124
- 74.178.76.128
- 74.179.77.164
- 52.168.117.170
- 20.184.175.7
- 172.178.240.163
- 52.110.12.2
- 92.223.78.30
- 52.110.12.20
- 52.123.252.193
- 74.178.76.44
- 203.26.79.13
- 57.154.63.210
- 51.116.253.170
- 172.66.2.5
- 52.148.114.188
- 72.145.35.99
- 52.110.12.56
- 52.110.12.40
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report