MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3fa13002449ef29b8b27e9ec6f7341457ac740056bb897fdd4b0296b7d18a8d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3fa13002449ef29b8b27e9ec6f7341457ac740056bb897fdd4b0296b7d18a8d0
SHA3-384 hash: d0e9a1e1970ce3e2266e889443535097d4f39cabd5649e27bc4ef5ad7fc827739a7dbff7a2464d388aa192a00e076350
SHA1 hash: 9b503d7d066366c10898d50cd6caa657b8ce8fc1
MD5 hash: ca91a64e39eeeb789cce526b3ba7ea88
humanhash: carbon-pluto-failed-eight
File name:Mozi.m
Download: download sample
Signature Mirai
File size:307'960 bytes
First seen:2021-02-07 04:15:19 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:2glZ3FtCKXhkmHtZ9TEKzjfj/WMngyIfsJ0F7xPtoFPa5POdOQ33Q:2IIKXhZtL7jOTyIG87XlPqOJ
TLSH 9E6401D7EB11BCB6F4968170766B034CB3B0D6C9C387E240B358C5693C6D3865BAA2D6
Reporter tolisec
Tags:mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
180
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
SecuriteInfo.com.Linux.Mirai-63.UNOFFICIAL
SecuriteInfo.com.Linux.Mirai-29.UNOFFICIAL
Unix.Dropper.Botnet-6566040-0
Unix.Packed.Botnet-6566031-0
Unix.Trojan.Gafgyt-6735924-0
Unix.Trojan.Gafgyt-6748839-0
Unix.Trojan.Mirai-7100807-0
Unix.Dropper.Mirai-7135934-0
Unix.Dropper.Mirai-7136013-0
Unix.Dropper.Mirai-7136057-0
Unix.Dropper.Mirai-7136070-0
Unix.Dropper.Mirai-7358821-0
Unix.Trojan.Mirai-8025795-0
Unix.Trojan.Mirai-9762350-0
Unix.Trojan.Mirai-9763616-0
Unix.Trojan.Mirai-9769616-0
Unix.Trojan.Mirai-9774339-0
Unix.Trojan.Mirai-9774712-0
Unix.Trojan.Mirai-9774958-0
Unix.Trojan.Mirai-9778190-0
Unix.Trojan.Mirai-9778279-0
Unix.Trojan.Mirai-9778883-0
Unix.Trojan.Mirai-9786053-0
Unix.Trojan.Mirai-9786115-0
Unix.Trojan.Mirai-9786166-0
Unix.Exploit.Mirai-9795501-0
Unix.Trojan.Mirai-9819430-0
Unix.Trojan.Mirai-9819450-0
Unix.Trojan.Mirai-9821543-0
Unix.Trojan.Mirai-9822019-0
Unix.Trojan.Mirai-9822570-0
Unix.Trojan.Mirai-9823425-0
Unix.Trojan.Mirai-9823624-0
Unix.Trojan.Mirai-9823625-0
Unix.Dropper.Mirai-9825964-0
Unix.Trojan.Mirai-9826420-0
Unix.Trojan.Mirai-9826840-0
Unix.Trojan.Mirai-9827594-0
Unix.Trojan.Mirai-9828330-0
Unix.Trojan.Mirai-9828606-0
Unix.Trojan.Mirai-9829012-0
Result
Verdict:
MALICIOUS
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2020-12-18 08:47:30 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Reads system network configuration
Enumerates active TCP sockets
Reads system routing table
Modifies hosts file
Modifies the Watchdog daemon
Writes file to system bin folder
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 3fa13002449ef29b8b27e9ec6f7341457ac740056bb897fdd4b0296b7d18a8d0

(this sample)

Comments