MALICIOUS — 8b5674bb5b83bf07907eb5a2eed741ec466f052395f7459ed398274844e3bbbe
MALICIOUS — 8b5674bb5b83bf07907eb5a2eed741ec466f052395f7459ed398274844e3bbbe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
8b5674bb5b83bf07907eb5a2eed741ec466f052395f7459ed398274844e3bbbe - SHA-1:
baa191dcf5739029a8b77d21f5ce7922d66dc85e - MD5:
4cc447cc2cb50cc6f1024c5de59c9064 - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
MITRE ATT&CK
Dynamic analysis (windows)
6236 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
- msedge.api.cdp.microsoft.com
- geo.prod.do.dsp.mp.microsoft.com
- kv801.prod.do.dsp.mp.microsoft.com
- cp801.prod.do.dsp.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/13787/files/780b5f068392ae82954eb27ce59e3fa36c94500d370f10fa2769762756fb3f65 —
780b5f068392ae82954eb27ce59e3fa36c94500d370f10fa2769762756fb3f65 - /opt/CAPEv2/storage/analyses/13787/files/d5d13ba5da11194ec177dff9e73e77214ed1015c9dba70b915d01d2c7255c6c6 —
d5d13ba5da11194ec177dff9e73e77214ed1015c9dba70b915d01d2c7255c6c6 - /opt/CAPEv2/storage/analyses/13787/files/46ec981ef203b80975cabe052188e0aedfe4791b020cdec10a5e5a1152b08437 —
46ec981ef203b80975cabe052188e0aedfe4791b020cdec10a5e5a1152b08437 - /opt/CAPEv2/storage/analyses/13787/files/3a8f293727c16d6a6429c9cd45773f42293e0be0b30e2e26cb3c9c195fcb0b35 —
3a8f293727c16d6a6429c9cd45773f42293e0be0b30e2e26cb3c9c195fcb0b35 - /opt/CAPEv2/storage/analyses/13787/files/b0ce7546da3660c0abb40d843aff4a07ed2d5f680a78465d0f5278d74479e086 —
b0ce7546da3660c0abb40d843aff4a07ed2d5f680a78465d0f5278d74479e086 - /opt/CAPEv2/storage/analyses/13787/files/6572c2f9c0c8faccbfef6fdc1540ebdee46c3ace540c2f5c43371290ee510228 —
6572c2f9c0c8faccbfef6fdc1540ebdee46c3ace540c2f5c43371290ee510228 - /opt/CAPEv2/storage/analyses/13787/files/a98097ec21fce1061a12c6ad0794763c0804dd4152aa25c9422ba32471e79c4f —
a98097ec21fce1061a12c6ad0794763c0804dd4152aa25c9422ba32471e79c4f - /opt/CAPEv2/storage/analyses/13787/files/71fa4cbe2f1c5598d77b35d43f5a55814ef368773d7c6faaec5474f67617d1ca —
71fa4cbe2f1c5598d77b35d43f5a55814ef368773d7c6faaec5474f67617d1ca - /opt/CAPEv2/storage/analyses/13787/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/13787/files/e6d45e471868bec8bb543e684941d82116d017a573b2c6f38e2ff13e335a7b37 —
e6d45e471868bec8bb543e684941d82116d017a573b2c6f38e2ff13e335a7b37 - /opt/CAPEv2/storage/analyses/13787/files/af691e521538435ce6255f28fe4737761259b7f24b710fa1030b5471456994a1 —
af691e521538435ce6255f28fe4737761259b7f24b710fa1030b5471456994a1 - /opt/CAPEv2/storage/analyses/13787/files/09a655ce684353a6b043ed593455f4caf4df8951a9c968215aa1c97e5902e3f4 —
09a655ce684353a6b043ed593455f4caf4df8951a9c968215aa1c97e5902e3f4 - /opt/CAPEv2/storage/analyses/13787/files/8d31a8aa7f28382f80427334ae12c015058a51f29980e3da731c8046b105ddbe —
8d31a8aa7f28382f80427334ae12c015058a51f29980e3da731c8046b105ddbe - /opt/CAPEv2/storage/analyses/13787/files/bad706a5bd1320e60f8666f6c3f2ce793e8c7c5e115d569ca3c1aba940a3bc4e —
bad706a5bd1320e60f8666f6c3f2ce793e8c7c5e115d569ca3c1aba940a3bc4e - /opt/CAPEv2/storage/analyses/13787/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786557231&P2=404&P3=2&P4=McNMRWnVMBtceHSgbljQmcVNkKQvh1zinaHe8Gdp7DVttgAy9W93%2bqmiW%2bb7yGYYIfgBvBCJYKQwxGyXg%2f8%2biA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786557254&P2=404&P3=2&P4=GDBIFkBxBG1ATpRqWsWKn3sXZNWrq5J4Bpw92%2fhxuq26ub%2fFxwfD%2fFrLI05Tk8PfT57z5ogpOSp9GTbfYsXQoA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 20.42.65.94
- 4.230.171.124
- 172.215.188.225
- 4.144.132.223
- 85.210.196.11
- 74.178.240.61
- 74.178.232.29
- 135.233.95.135
- 4.150.223.102
- 203.26.79.13
- 135.234.160.245
- 20.184.175.10
- 72.154.7.105
- 52.148.114.188
- 52.110.12.31
- 52.110.12.47
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report