MALICIOUS — 9932d8af68f562c8c024070def0215e41d3ff3465d5c5363d9c4e34e97d2b55d
MALICIOUS — 9932d8af68f562c8c024070def0215e41d3ff3465d5c5363d9c4e34e97d2b55d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
9932d8af68f562c8c024070def0215e41d3ff3465d5c5363d9c4e34e97d2b55d - SHA-1:
9077fcf9c8d23f239c6b907136ad04949fcedae5 - MD5:
055764056b42dee535cff36a30a3d786 - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
MITRE ATT&CK
Dynamic analysis (windows)
6196 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- licensing.mp.microsoft.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/14033/files/b8799c6d41bcb14cb2cfe537f5b17d5df190e5db7fad1eaf02acf1a4e865d316 —
b8799c6d41bcb14cb2cfe537f5b17d5df190e5db7fad1eaf02acf1a4e865d316 - /opt/CAPEv2/storage/analyses/14033/files/f5dbfd04270347f4b02fc902bd6b14ce9652b6ef5731feca656c15c7caea01cc —
f5dbfd04270347f4b02fc902bd6b14ce9652b6ef5731feca656c15c7caea01cc - /opt/CAPEv2/storage/analyses/14033/files/36411f2109ba8cfd00e68a71f7e1cd687c854998cfe6b0529e95d508d492109b —
36411f2109ba8cfd00e68a71f7e1cd687c854998cfe6b0529e95d508d492109b - /opt/CAPEv2/storage/analyses/14033/files/718408c288765fd21e71a35057cdfe54c21a2f7f8ec32e6430a4b84c083b04ea —
718408c288765fd21e71a35057cdfe54c21a2f7f8ec32e6430a4b84c083b04ea - /opt/CAPEv2/storage/analyses/14033/files/e4505e8867a0ca20d30251ef820feec11a962f5bf826408004280801795ec6b4 —
e4505e8867a0ca20d30251ef820feec11a962f5bf826408004280801795ec6b4 - /opt/CAPEv2/storage/analyses/14033/files/73eb284b618cdcffa9306a12feeb28844dffb63ac9eb3362e8f549da587ef693 —
73eb284b618cdcffa9306a12feeb28844dffb63ac9eb3362e8f549da587ef693 - /opt/CAPEv2/storage/analyses/14033/files/48c8b7bebb56c5be0041852a905b2570b563daee79e3060f7ff8b3ade7acfe31 —
48c8b7bebb56c5be0041852a905b2570b563daee79e3060f7ff8b3ade7acfe31 - /opt/CAPEv2/storage/analyses/14033/files/df1e48a3ce7afdd5ba70904d0c7ff924f82801ba9d27cbab921f1ef7684e45bb —
df1e48a3ce7afdd5ba70904d0c7ff924f82801ba9d27cbab921f1ef7684e45bb - /opt/CAPEv2/storage/analyses/14033/files/0962f191f87b417ade6a5820189066675bc986ac707da4646a1a9cb1edeca74d —
0962f191f87b417ade6a5820189066675bc986ac707da4646a1a9cb1edeca74d - /opt/CAPEv2/storage/analyses/14033/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/14033/files/66c1bfc760c40f0292f663956814ef0546b64157834ac4effb5b39d7542d952d —
66c1bfc760c40f0292f663956814ef0546b64157834ac4effb5b39d7542d952d - /opt/CAPEv2/storage/analyses/14033/files/555713c5cc513db2643f8a6098139ca0f5545eaa6dd4508eedd3a73029552241 —
555713c5cc513db2643f8a6098139ca0f5545eaa6dd4508eedd3a73029552241 - /opt/CAPEv2/storage/analyses/14033/files/205751bbfb775ebbf383aa2bf4535edc501663ac8e2603591b62d489e05bc0a7 —
205751bbfb775ebbf383aa2bf4535edc501663ac8e2603591b62d489e05bc0a7 - /opt/CAPEv2/storage/analyses/14033/files/ad70f84094a74e1f20384d3cc67091dd837e0d9a511b7f34569697bc97811c29 —
ad70f84094a74e1f20384d3cc67091dd837e0d9a511b7f34569697bc97811c29 - /opt/CAPEv2/storage/analyses/14033/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786563885&P2=404&P3=2&P4=HJ3%2fTX%2bkm%2b8Hw7M0Ns0C9oWXuFBCEHLqOnLW41xmmxHMqwYejyG17Crh2v3v49EjBiNvC6EA4EGKZFRMwYonfA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786563949&P2=404&P3=2&P4=LuvNV0Nhxbn8GrIaR96FoHis2P5vPghfClakWjiB%2fIudQShPZIUC2YriCDmWDuxgYbryYOR7pE7Y723ZoDwxBw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 74.179.71.159
- 57.155.101.212
- 4.150.223.103
- 52.230.59.222
- 4.230.171.124
- 85.210.196.11
- 135.232.92.137
- 135.232.92.97
- 74.179.77.204
- 20.42.65.85
- 92.223.78.30
- 135.232.92.34
- 203.26.79.13
- 135.233.45.223
- 72.153.5.63
- 52.148.114.188
- 52.110.12.47
- 52.110.12.20
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report