MALICIOUS — d1f16070134d2f9fc2fd9407f075a603413f8ba2cefa0824e709278525f9800b
MALICIOUS — d1f16070134d2f9fc2fd9407f075a603413f8ba2cefa0824e709278525f9800b is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mira family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
d1f16070134d2f9fc2fd9407f075a603413f8ba2cefa0824e709278525f9800b - SHA-1:
f5e9d97f5a2f0c263e2895cc9a596491d97e30bb - MD5:
e092c02590c31ac5c09f9817ff80197a - imphash:
3a2003ea545fe942681da9e7683ebb58 - File type: pe · Size: 405668 bytes
- Verdict: malicious (99/100) · Family: Mira
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.lol 1
- ClamAV (daily): Win.Malware.Mira-7407830-0
- Detect It Easy (packer/type): DIE:VMProtect 2.0.3-2.13
- Microsoft Defender: Worm:Win32/Mira!pz
- Emsisoft (Emergency Kit): Gen:Heur.Minggy.1
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Dynamic analysis (windows)
6214 behavior events · 1 ATT&CK techniques · 34 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/14074/files/819c697b5f3592af0d223e6c567b9b1fc79ef030662498cce05eb533154009d3 —
819c697b5f3592af0d223e6c567b9b1fc79ef030662498cce05eb533154009d3 - /opt/CAPEv2/storage/analyses/14074/files/c45760be03c6d00231eed83a7a98da08e5f9d00dc0afda8df7a61368f10829ad —
c45760be03c6d00231eed83a7a98da08e5f9d00dc0afda8df7a61368f10829ad - /opt/CAPEv2/storage/analyses/14074/files/bf794d3b46fa8d4efb933f89eeebb6cba457586f1f8eebe52f5109f345898dcb —
bf794d3b46fa8d4efb933f89eeebb6cba457586f1f8eebe52f5109f345898dcb - /opt/CAPEv2/storage/analyses/14074/files/9ba0773222d511bcae2d9158321e5ae5d33d2850b746d1ad1d15b6c74b44ca9e —
9ba0773222d511bcae2d9158321e5ae5d33d2850b746d1ad1d15b6c74b44ca9e - /opt/CAPEv2/storage/analyses/14074/files/37ba2d89c6fd8763e795525e5cbc1192aec0a25b416574973a10ef76a8e75c86 —
37ba2d89c6fd8763e795525e5cbc1192aec0a25b416574973a10ef76a8e75c86 - /opt/CAPEv2/storage/analyses/14074/files/ed4e37f06c975131ac5de2b587b14a98367fd48c73dc4e39875db9c9ea883103 —
ed4e37f06c975131ac5de2b587b14a98367fd48c73dc4e39875db9c9ea883103 - /opt/CAPEv2/storage/analyses/14074/files/3b8bd8e3834a97ed9bc74b70dde62554faca6c3bc91171da7aff035e27824171 —
3b8bd8e3834a97ed9bc74b70dde62554faca6c3bc91171da7aff035e27824171 - /opt/CAPEv2/storage/analyses/14074/files/9584a000a879ca20333ddabb572a694f3d221e57458ba5a72e3b5dbdbdd3162b —
9584a000a879ca20333ddabb572a694f3d221e57458ba5a72e3b5dbdbdd3162b - /opt/CAPEv2/storage/analyses/14074/files/f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 —
f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 - /opt/CAPEv2/storage/analyses/14074/files/5d57fdcb991b31852729a884cb4889ca9bac62fdf4d7cec66fa7de5ec9447b10 —
5d57fdcb991b31852729a884cb4889ca9bac62fdf4d7cec66fa7de5ec9447b10 - /opt/CAPEv2/storage/analyses/14074/files/ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a —
ad38b76382f56940b22fc920702dbd4bff308a93bf3ad3b0b705686aa4245e9a - /opt/CAPEv2/storage/analyses/14074/files/94b275380872ebe9436dbf2222b37cfc034418c6ba633ef94ee236e2d0c08a54 —
94b275380872ebe9436dbf2222b37cfc034418c6ba633ef94ee236e2d0c08a54 - /opt/CAPEv2/storage/analyses/14074/files/d1002b64831e1e1470139f36a782172fe3cc8febfa6581ce780d971f5a4bf2f2 —
d1002b64831e1e1470139f36a782172fe3cc8febfa6581ce780d971f5a4bf2f2 - /opt/CAPEv2/storage/analyses/14074/files/8c531baeaa07130640b3ce7ccf56729ead5ab5e8c46efc39b8e8e6b1c635ab33 —
8c531baeaa07130640b3ce7ccf56729ead5ab5e8c46efc39b8e8e6b1c635ab33 - /opt/CAPEv2/storage/analyses/14074/files/fe42f397424aeabc47e546dc19fa33bef7e5c94fcab5e25b45cba47a9dfa9fb8 —
fe42f397424aeabc47e546dc19fa33bef7e5c94fcab5e25b45cba47a9dfa9fb8
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786565061&P2=404&P3=2&P4=c8W0qh9jR74V13p5jF3Y7G7ZsbCGpoTKwXN%2bbT6OVO8DRvmH6qUuGgl8nEzPaijnsGokSx0QyvtNTD2%2bswuOdw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786565160&P2=404&P3=2&P4=U8w92eDgWi7Xjr93dwMT2rdsL0bKDKLjtiq51j0RG8aQ9oKcuZQFkwlLCEz3BB%2bEsLMpEDXS3qaR4yJUMM26gg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 52.110.12.52
- 52.110.12.28
- 4.150.223.99
- 52.123.252.238
- 20.42.179.192
- 4.144.132.114
- 4.230.171.124
- 172.215.188.232
- 135.232.92.137
- 20.165.94.54
- 52.178.17.234
- 20.184.175.23
- 135.233.45.222
- 203.26.79.13
- 162.159.142.9
- 20.165.94.46
- 184.84.165.171
- 184.84.165.136
- 52.110.12.38
- 52.110.12.40
- 72.145.35.114
- 74.178.76.44
- 52.148.114.188
- 52.110.12.4
- 52.110.12.21
More Mira samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report