MALICIOUS — a961d24e35bd6e8dc7b611774b85dc0eb568e6b437ba92f099482b8a4e624d1a
MALICIOUS — a961d24e35bd6e8dc7b611774b85dc0eb568e6b437ba92f099482b8a4e624d1a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
a961d24e35bd6e8dc7b611774b85dc0eb568e6b437ba92f099482b8a4e624d1a - SHA-1:
3b67053b4f30a04ca2d04423c644b0554777fb00 - MD5:
e1f48eebf7ac8ea39fb960c4c2a50230 - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Dynamic analysis (windows)
6235 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/14455/files/2ba4c259333a64ef276ae91534829fdc141981a3fc5fb70033eb0f957b9f2468 —
2ba4c259333a64ef276ae91534829fdc141981a3fc5fb70033eb0f957b9f2468 - /opt/CAPEv2/storage/analyses/14455/files/c02c0bceb5375c4fb2b26a060669060495ec7ee3a9242af8abf131ee2183ae2c —
c02c0bceb5375c4fb2b26a060669060495ec7ee3a9242af8abf131ee2183ae2c - /opt/CAPEv2/storage/analyses/14455/files/e54623236832774da276cce050760995d0068af84f56c6e1be7950a6775a4db0 —
e54623236832774da276cce050760995d0068af84f56c6e1be7950a6775a4db0 - /opt/CAPEv2/storage/analyses/14455/files/fa065adfa71fbc6fa4f18a0087379ec365ce413f2eef2bd0a41c551a8928d6d5 —
fa065adfa71fbc6fa4f18a0087379ec365ce413f2eef2bd0a41c551a8928d6d5 - /opt/CAPEv2/storage/analyses/14455/files/a24801450d7133bd0aad52d0a4974096ead9876961dd13471fd3fa25770da9f4 —
a24801450d7133bd0aad52d0a4974096ead9876961dd13471fd3fa25770da9f4 - /opt/CAPEv2/storage/analyses/14455/files/0df84cb5d835cb8fad8be1ee232247ae7128c3769ab0d1697b1363a852bc662d —
0df84cb5d835cb8fad8be1ee232247ae7128c3769ab0d1697b1363a852bc662d - /opt/CAPEv2/storage/analyses/14455/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/14455/files/1ec1d47108e977c88f8f3dfec6155c916da599e01232983036e961d90b78d416 —
1ec1d47108e977c88f8f3dfec6155c916da599e01232983036e961d90b78d416 - /opt/CAPEv2/storage/analyses/14455/files/dd1e715a1995c62d06288bf456ab4da7f8280ac4f3dc7cb3d42d8e43b458ca94 —
dd1e715a1995c62d06288bf456ab4da7f8280ac4f3dc7cb3d42d8e43b458ca94 - /opt/CAPEv2/storage/analyses/14455/files/6026f253084f8bee710cd1c6a507f9d6d24733f6495d06cd77955726a5e82bf4 —
6026f253084f8bee710cd1c6a507f9d6d24733f6495d06cd77955726a5e82bf4 - /opt/CAPEv2/storage/analyses/14455/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - /opt/CAPEv2/storage/analyses/14455/files/372e2a9afc7d7df02b611c8acbe145af9d925918302088e2ebe57c1d20ebd991 —
372e2a9afc7d7df02b611c8acbe145af9d925918302088e2ebe57c1d20ebd991 - /opt/CAPEv2/storage/analyses/14455/files/512c293ef8e5687be33a3b99eebe00030be1f1af7ff00d98ad7fe54ab6a48020 —
512c293ef8e5687be33a3b99eebe00030be1f1af7ff00d98ad7fe54ab6a48020 - /opt/CAPEv2/storage/analyses/14455/files/c8d46c61b5643e5bcdd1fa9845ed7e55680fdd771bb477b0666b499b6cbd9fa3 —
c8d46c61b5643e5bcdd1fa9845ed7e55680fdd771bb477b0666b499b6cbd9fa3 - /opt/CAPEv2/storage/analyses/14455/files/a42e57db93b93ecb2224fdb1276f4ebb0b6705cc4a95ec1899772df8dc47a684 —
a42e57db93b93ecb2224fdb1276f4ebb0b6705cc4a95ec1899772df8dc47a684
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786575718&P2=404&P3=2&P4=KAfhWdToaRQM0s%2bvyx65NlZSyWkGC8gaPkkuOBfsM1YtxBqOYq0pLKWvWtpLpSdYKbkLAu%2bS%2fDK270AKXvr5Gg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786575756&P2=404&P3=2&P4=MTJ3vhUcgFIuuHNCmPAGykf1v6sOnFISljZTGMO%2fLIIgwciUA%2fD8gqadrb1T%2fk3kk2CD5HG4zlvTSNtv3aR3hw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 52.168.117.169
- 4.230.171.124
- 52.230.59.222
- 172.215.188.232
- 74.179.77.204
- 51.116.246.106
- 20.165.94.54
- 20.42.65.88
- 135.234.160.245
- 203.26.79.13
- 74.178.232.29
- 52.110.12.24
- 52.110.12.32
- 162.159.142.9
- 40.84.85.40
- 52.148.114.188
- 72.154.7.104
- 74.178.76.44
- 52.110.12.15
- 52.110.12.3
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report