MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5cb7596e6b3c170cb647b7c0532a6aaf240097fcd9efd3eee1a3d101ce5e8c32. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments 1

SHA256 hash: 5cb7596e6b3c170cb647b7c0532a6aaf240097fcd9efd3eee1a3d101ce5e8c32
SHA3-384 hash: 07a9405721cb55f47175e1589059907ae8d4974f532636d3ced0d068962300c8e0062720246aba66ebec9f32d35f279d
SHA1 hash: 20c974eb9bd02fbb9e49448c9cf7283286d2bdab
MD5 hash: 1b8fc4a3ff82c80961e17f8d4003fdfe
humanhash: mockingbird-edward-fillet-romeo
File name:1b8fc4a3ff82c80961e17f8d4003fdfe
Download: download sample
Signature Mirai
File size:42'684 bytes
First seen:2022-04-07 23:23:42 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:ta4aeygeee+qeeFehyMioXdwt0aLiMUCr7SCrLoyK7Ceft9wB:ta4aFgzbfEPYNwt0k7ST17CU9
TLSH T126136D7AC41EAE94C0668A38E4674E740F63F118C2271FFA5EC981655087EF8F6153FA
Reporter zbetcheckin
Tags:32 elf mirai renesas

Intelligence


File Origin
# of uploads :
1
# of downloads :
216
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug mirai
Result
Verdict:
MALICIOUS
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
3 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2022-04-07 23:24:06 UTC
File Type:
ELF32 Little (Exe)
AV detection:
11 of 26 (42.31%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 5cb7596e6b3c170cb647b7c0532a6aaf240097fcd9efd3eee1a3d101ce5e8c32

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2022-04-07 23:23:48 UTC

url : hxxp://192.210.132.120/bins/vcimanagement.sh4