MALICIOUS — bb48b3fab190552206db2929506fdb7e74b05dbb3bd22a411cf2b427b040998f
MALICIOUS — bb48b3fab190552206db2929506fdb7e74b05dbb3bd22a411cf2b427b040998f is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
bb48b3fab190552206db2929506fdb7e74b05dbb3bd22a411cf2b427b040998f - SHA-1:
481b62ba8c79a549812205e2832e14b27bdf395c - MD5:
66965c608cac06cfe8b0d63f1f94e6fc - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
MITRE ATT&CK
Dynamic analysis (windows)
6117 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- settings-win.data.microsoft.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/14071/files/5f6128a63954c25df3bcc2927172263da33f3d3e503a654707e7227dbbdcc80d —
5f6128a63954c25df3bcc2927172263da33f3d3e503a654707e7227dbbdcc80d - /opt/CAPEv2/storage/analyses/14071/files/07d7b38551851e8c7a785ad93ab0021746336c2ae9d7d5a006f7c14bb45880ad —
07d7b38551851e8c7a785ad93ab0021746336c2ae9d7d5a006f7c14bb45880ad - /opt/CAPEv2/storage/analyses/14071/files/aa0c8390fac87ea39c1dbc795f06e5937f87dd43256c5d382f8a4cbd60777ecc —
aa0c8390fac87ea39c1dbc795f06e5937f87dd43256c5d382f8a4cbd60777ecc - /opt/CAPEv2/storage/analyses/14071/files/811db7a4c07dd35876a76f3ec657aa876684346d0775bc34a199416bb7fc6908 —
811db7a4c07dd35876a76f3ec657aa876684346d0775bc34a199416bb7fc6908 - /opt/CAPEv2/storage/analyses/14071/files/d365fe8c531e3ac7be8a42d8fac4113ac3c76c33c23e1c85d07e5393807f4c2d —
d365fe8c531e3ac7be8a42d8fac4113ac3c76c33c23e1c85d07e5393807f4c2d - /opt/CAPEv2/storage/analyses/14071/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/14071/files/c242f280c7bb1aace64327056c94ed57c7a0397fcc0f705a3ec9f05219b8c1c9 —
c242f280c7bb1aace64327056c94ed57c7a0397fcc0f705a3ec9f05219b8c1c9 - /opt/CAPEv2/storage/analyses/14071/files/57d2f25ddbc06586e25cd674c7efbdf90ed7608607db6e6e04cbc90b90c93245 —
57d2f25ddbc06586e25cd674c7efbdf90ed7608607db6e6e04cbc90b90c93245 - /opt/CAPEv2/storage/analyses/14071/files/4ba2347d10bc8bac747a63c1c3234b366d94bed3de67f7f5d843e605101a3c05 —
4ba2347d10bc8bac747a63c1c3234b366d94bed3de67f7f5d843e605101a3c05 - /opt/CAPEv2/storage/analyses/14071/files/525ade06594e52eb543c59fd1b02d0ac2254b448d97a33eb949f8fad9cba95cb —
525ade06594e52eb543c59fd1b02d0ac2254b448d97a33eb949f8fad9cba95cb - /opt/CAPEv2/storage/analyses/14071/files/75437301e1af1634a7d977a4b7bf4ad6142ea00e0c7fb9632eaee6f592337ee9 —
75437301e1af1634a7d977a4b7bf4ad6142ea00e0c7fb9632eaee6f592337ee9 - /opt/CAPEv2/storage/analyses/14071/files/103ae851d3b1dda4c18f41b382fda4da8c654c05268dc94d9808d7cb6c17f138 —
103ae851d3b1dda4c18f41b382fda4da8c654c05268dc94d9808d7cb6c17f138 - /opt/CAPEv2/storage/analyses/14071/files/05c17cf921762939c2c83bce72dcce33036b558ffc43f7264c40d44380394ff0 —
05c17cf921762939c2c83bce72dcce33036b558ffc43f7264c40d44380394ff0 - /opt/CAPEv2/storage/analyses/14071/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - /opt/CAPEv2/storage/analyses/14071/files/18c50f2e7bae85461bc297e85ad870112bf9dd9a1ef3dceb8e0659ff42cbb3ec —
18c50f2e7bae85461bc297e85ad870112bf9dd9a1ef3dceb8e0659ff42cbb3ec
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786564835&P2=404&P3=2&P4=ijUgfOeAeW1PQpGMM9W8m%2bepKKXfJkiH%2bXNAWSNuCcTZJIACp5pY6lq80thzKgN3L9g7gi7lujXM2wfQzqS5DA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786564872&P2=404&P3=2&P4=L7GgWcglnpeEZyZuixXBCYt6f5d7qHRv7oR6RnsY%2bB9HbJhU%2fm4HbaTbdq68XM9ZHRtFi9cNobkMBAD5sEiLdQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 57.154.63.210
- 184.84.165.136
- 20.42.73.26
- 52.123.252.222
- 4.230.171.124
- 4.247.188.224
- 52.230.59.222
- 72.154.7.114
- 74.178.76.128
- 135.233.95.135
- 20.184.175.20
- 13.89.179.15
- 135.233.45.221
- 74.178.232.29
- 203.26.79.13
- 52.110.12.37
- 52.110.12.3
- 20.165.94.46
- 52.123.252.219
- 20.184.175.3
- 184.84.165.171
- 162.159.142.9
- 72.145.35.116
- 52.148.114.188
- 52.110.12.28
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report