MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4f93ca9d28a68c9b62dfb3d3756d1ec029e54ba881f9d3f54e9eeea976f1232a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 4f93ca9d28a68c9b62dfb3d3756d1ec029e54ba881f9d3f54e9eeea976f1232a
SHA3-384 hash: 27a20a966406526ede148fa24ce1b181928aae69763e30c03a7ffe17f1c355cfbca824c8d93f5c527d15dc032232f0c6
SHA1 hash: ab0ec601e6feba10075491712e46e771afeaa7e7
MD5 hash: 14da400c325fe207a2dfb4723cc3e87f
humanhash: batman-bulldog-kilo-bluebird
File name:jew.ppc
Download: download sample
Signature Mirai
File size:71'176 bytes
First seen:2024-12-06 13:15:49 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:EGfWJcRyNYciiv1da2PHS3g4JQsA42THyd42+I:VfNyNCivXIZ
TLSH T1B1632B023324095BE9E25EB0263F1BE183BEED4216F0724A694FEF654636E721446FDD
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
112
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Runs as daemon
Connection attempt
Receives data from a server
Opens a port
Sends data to a server
Substitutes an application name
Performs a bruteforce attack in the network
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug masquerade
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Antivirus / Scanner detection for submitted sample
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1570040 Sample: jew.ppc.elf Startdate: 06/12/2024 Architecture: LINUX Score: 48 22 13.12.234.1 XEROX-WVUS United States 2->22 24 103.47.62.165 WOOFY-ASUS United States 2->24 26 98 other IPs or domains 2->26 28 Antivirus / Scanner detection for submitted sample 2->28 8 jew.ppc.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 jew.ppc.elf 8->14         started        16 jew.ppc.elf 8->16         started        process6 18 jew.ppc.elf 14->18         started        20 jew.ppc.elf 14->20         started       
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2024-12-06 14:13:10 UTC
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:kurc linux
Verdict:
Malicious
Tags:
Unix.Dropper.Mirai-7135870-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 4f93ca9d28a68c9b62dfb3d3756d1ec029e54ba881f9d3f54e9eeea976f1232a

(this sample)

  
Delivery method
Distributed via web download

Comments