MALICIOUS — a96522d087e773f82ebd61bd2f7832d11599ae3bd958637d8e9220699365d05a
MALICIOUS — a96522d087e773f82ebd61bd2f7832d11599ae3bd958637d8e9220699365d05a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
a96522d087e773f82ebd61bd2f7832d11599ae3bd958637d8e9220699365d05a - SHA-1:
d504a255fd54507fbbe81bbf7aa5d72a92097800 - MD5:
8cc536bef2798cb06f7305104803dd18 - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (100/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Dynamic analysis (windows)
6369 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- settings-win.data.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
- fe3cr.delivery.mp.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/13745/files/9303da8b1284318540a037e59b52e17256174d87dec399a5011070c8e7b25d28 —
9303da8b1284318540a037e59b52e17256174d87dec399a5011070c8e7b25d28 - /opt/CAPEv2/storage/analyses/13745/files/18a36efdf2efd7b92e6ee71b5280b08e2f22b36dd95911f00652419b13687562 —
18a36efdf2efd7b92e6ee71b5280b08e2f22b36dd95911f00652419b13687562 - /opt/CAPEv2/storage/analyses/13745/files/4d476aa80b903bfafc8896d116d6ed763801207dabaa64f3bf205953b964487e —
4d476aa80b903bfafc8896d116d6ed763801207dabaa64f3bf205953b964487e - /opt/CAPEv2/storage/analyses/13745/files/b4550ea7506c832b38dbb8da5a799fd568431c96a9f0d535ec91814896cbd568 —
b4550ea7506c832b38dbb8da5a799fd568431c96a9f0d535ec91814896cbd568 - /opt/CAPEv2/storage/analyses/13745/files/611349aca2ef8e5b3d870824aea1ba98d108e11ae3e6ee50e2f5f8bfd3f73531 —
611349aca2ef8e5b3d870824aea1ba98d108e11ae3e6ee50e2f5f8bfd3f73531 - /opt/CAPEv2/storage/analyses/13745/files/40496f991eccbd9bbd85970ed92b02315ed308180045ac8e81d6de84af7b8145 —
40496f991eccbd9bbd85970ed92b02315ed308180045ac8e81d6de84af7b8145 - /opt/CAPEv2/storage/analyses/13745/files/a8a134643a3b0b7f8893ccc41530a71a992a61d611fad6dfce18d47a24255f63 —
a8a134643a3b0b7f8893ccc41530a71a992a61d611fad6dfce18d47a24255f63 - /opt/CAPEv2/storage/analyses/13745/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/13745/files/bf6992f29ddacf13f7b2e47ac9ac0d084d8392a84eb1957d05088f06631ef9e9 —
bf6992f29ddacf13f7b2e47ac9ac0d084d8392a84eb1957d05088f06631ef9e9 - /opt/CAPEv2/storage/analyses/13745/files/5e0ada8c07842f5063d165dbdeaf62d50288519809b3337ed62252b78954b1d4 —
5e0ada8c07842f5063d165dbdeaf62d50288519809b3337ed62252b78954b1d4 - /opt/CAPEv2/storage/analyses/13745/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - /opt/CAPEv2/storage/analyses/13745/files/1d411dceeb1b6257f169635fdbcff45cd6008b3971c48c478b66300135f17cd9 —
1d411dceeb1b6257f169635fdbcff45cd6008b3971c48c478b66300135f17cd9 - /opt/CAPEv2/storage/analyses/13745/files/6ac3112e0af833323d4484b2c35ed71f68773d297044ed836cd40ea989102bc7 —
6ac3112e0af833323d4484b2c35ed71f68773d297044ed836cd40ea989102bc7 - /opt/CAPEv2/storage/analyses/13745/files/83e6e7e02e7bf2b8c7b57ed19ad8c717a0986840e989d4e6989ba3149831129b —
83e6e7e02e7bf2b8c7b57ed19ad8c717a0986840e989d4e6989ba3149831129b - /opt/CAPEv2/storage/analyses/13745/files/631f94f4acdd09e806b9b65397018e53b7d6281003fff64e6e8f1389cd5a41f9 —
631f94f4acdd09e806b9b65397018e53b7d6281003fff64e6e8f1389cd5a41f9
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786556233&P2=404&P3=2&P4=W%2fNREO4ipXX56qxM5JFXdHlZf%2fmenpCoPsYksTlKJrxu%2ftftLHaqEcJoXyrBAkPqMK1UpBOFcxrK%2fqgged%2fTJw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786556285&P2=404&P3=2&P4=fi9F8aW6PwE7nVScf5rfD1AtwGpcEA3uBP18E0x3GDnp0l4XKczf51zAleSeoWkNCThkN4EKO2PpeZ0lK1Xbxw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 4.150.223.113
- 135.233.95.80
- 52.123.252.212
- 40.84.97.4
- 4.230.171.124
- 20.247.184.197
- 135.232.92.137
- 20.184.175.16
- 74.178.240.51
- 20.50.73.14
- 20.184.175.14
- 20.42.65.89
- 135.233.45.221
- 203.26.79.13
- 135.232.92.34
- 52.148.114.188
- 72.145.35.96
- 52.110.12.2
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report