MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 66f90d08abb9edc2bb37920eeb24d3beb3ddcc71a56cf0cc6bbbde0908d00346. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 8
| SHA256 hash: | 66f90d08abb9edc2bb37920eeb24d3beb3ddcc71a56cf0cc6bbbde0908d00346 |
|---|---|
| SHA3-384 hash: | 6a1ec1c8327eea5decdaf4a447b531dae19e1764eb94162567b7be6134d7b2f16efc7453b921a459e9074dd08b191bb4 |
| SHA1 hash: | 02faaaed558aa74bd2e2e82181e726e45de7b4ec |
| MD5 hash: | 000216f69289a2762cb5851feeeed35e |
| humanhash: | oregon-potato-chicken-nevada |
| File name: | arm926t |
| Download: | download sample |
| File size: | 480'792 bytes |
| First seen: | 2025-07-07 23:44:39 UTC |
| Last seen: | Never |
| File type: | elf |
| MIME type: | application/x-executable |
| ssdeep | 12288:ndLGtVtlmIHk6Rtx02O6R+9X8C5SGEzf:pGntlzJx02O6E9X8XG |
| TLSH | T1AAA40294E9819B62C2C801BFFF0F45BC77A31F69E1EA71068D16EB1662D745A4F7E400 |
| telfhash | t186c08c8c0fd401beba7d72a203bef2bf61a072f0be0224920404eb6f074c584028144c |
| Magika | elf |
| Reporter | |
| Tags: | elf |
Intelligence
File Origin
DEVendor Threat Intelligence
Result
Behaviour
Behaviour
Botnet C2s
type: 130.239.18.158:6881
type: 67.215.246.10:6881
type: 109.195.53.144:6881
type: 89.207.71.47:6881
type: 93.108.223.52:6881
type: 194.163.179.198:6881
type: 177.72.195.114:6881
type: 107.130.95.200:6881
type: 198.98.49.100:6881
type: 200.149.181.48:6881
type: 54.193.33.181:6881
type: 73.208.41.226:6881
type: 89.179.246.14:6881
type: 91.208.65.74:6881
type: 148.66.93.5:6881
type: 176.125.139.123:6881
type: 188.42.55.92:6881
type: 81.143.198.62:6881
type: 93.145.165.136:6881
type: 45.87.251.172:6881
type: 85.221.218.234:6881
type: 218.46.103.116:6881
type: 172.96.121.2:6881
type: 96.52.40.198:6881
type: 77.34.93.254:6881
type: 81.43.149.94:6881
type: 78.46.47.3:6881
type: 200.138.251.194:6881
type: 172.245.39.122:6881
type: 104.246.225.90:6881
type: 194.132.68.38:6881
type: 124.168.237.132:6881
type: 71.43.142.126:6881
type: 206.255.177.36:6881
type: 102.140.112.7:6881
type: 220.253.27.183:6881
type: 181.115.171.208:6881
type: 24.193.65.81:6881
type: 107.129.92.194:6881
type: 101.185.155.160:6881
type: 18.223.137.220:6881
type: 87.208.108.134:6881
type: 98.203.140.12:6881
type: 68.2.167.57:6881
type: 51.148.64.129:6881
type: 45.203.155.80:6880
type: 45.56.122.13:6880
type: 45.203.212.13:6880
type: 34.233.90.2:6880
type: 18.217.118.217:6880
type: 173.230.130.111:6880
type: 154.202.132.183:6880
type: 52.203.61.151:6880
type: 45.203.212.26:6880
type: 65.21.33.212:50000
type: 142.132.207.120:50000
type: 135.181.227.244:50000
type: 135.181.238.57:50000
type: 188.40.39.55:50000
type: 135.181.223.109:50000
type: 37.27.117.115:50000
type: 142.132.202.190:50000
type: 198.27.70.166:50000
type: 135.181.212.149:50000
type: 95.217.86.221:50000
type: 178.162.174.41:28005
type: 178.162.173.165:28005
type: 95.211.218.207:28005
type: 46.232.211.11:64038
type: 72.21.17.103:62091
type: 178.162.174.5:28015
type: 178.162.174.228:28015
type: 193.23.250.233:51413
type: 167.114.174.168:51413
type: 51.195.40.242:51413
type: 109.225.40.48:51413
type: 213.172.235.225:51413
type: 51.15.10.206:51413
type: 188.90.169.20:51413
type: 84.213.206.215:51413
type: 136.144.199.147:51413
type: 61.73.10.199:51413
type: 173.230.138.15:51413
type: 37.139.80.10:51413
type: 125.44.166.199:51413
type: 130.61.54.37:51413
type: 5.15.52.25:51413
type: 119.36.221.174:51413
type: 188.165.192.76:51413
type: 5.196.69.211:51413
type: 93.82.51.77:51413
type: 5.135.176.94:51413
type: 82.69.17.228:51413
type: 178.162.174.178:28003
type: 37.48.70.4:28010
type: 178.162.173.138:28010
type: 178.162.174.73:28010
type: 178.162.173.222:28010
type: 144.126.197.43:15717
type: 178.162.173.89:28014
type: 83.149.84.32:28014
type: 178.162.174.222:28014
type: 178.162.174.208:28014
type: 149.106.135.203:42214
type: 130.239.18.158:8539
type: 94.130.128.14:62448
type: 89.149.197.229:11889
type: 43.133.45.199:50120
type: 51.38.80.68:8646
type: 178.151.177.240:64454
type: 72.21.17.97:16052
type: 45.91.208.179:8999
type: 142.202.48.88:12052
type: 69.50.95.40:10016
type: 213.112.253.236:59450
type: 23.158.56.119:10011
type: 69.50.95.40:10075
type: 162.251.63.78:16012
type: 69.50.95.40:10040
type: 93.123.72.133:29949
type: 185.203.56.5:32512
type: 178.16.220.140:52192
type: 119.206.219.11:40787
type: 178.162.173.200:28009
type: 178.162.174.102:28009
type: 178.162.173.58:28009
type: 178.162.173.232:28004
type: 178.162.174.43:28004
type: 81.171.22.85:28002
type: 185.203.56.50:15494
type: 83.149.98.183:28006
type: 178.162.173.118:28006
type: 178.162.174.170:28008
type: 45.87.251.11:28127
type: 217.121.231.94:59625
type: 130.239.18.158:8508
type: 130.239.18.158:8521
type: 220.78.127.163:29711
type: 178.162.174.149:28001
type: 178.162.173.231:28001
type: 130.239.18.158:8524
type: 130.239.18.158:8515
type: 185.21.217.8:54488
type: 183.104.99.54:32834
type: 220.126.133.55:32870
type: 95.168.162.161:42670
type: 185.149.91.43:51065
type: 83.149.84.32:28045
type: 129.227.97.138:60020
type: 154.209.94.23:60020
type: 37.59.61.28:52172
type: 185.203.56.57:17853
type: 112.91.94.43:6889
type: 119.25.31.11:6889
type: 176.78.33.142:6889
type: 72.21.17.41:14973
type: 95.211.117.106:55653
type: 85.17.170.48:28016
type: 136.243.57.34:19701
type: 210.230.106.242:12202
type: 158.174.22.253:18315
type: 94.31.113.10:3729
type: 84.17.60.242:51356
type: 124.244.65.196:9195
type: 46.232.210.51:64267
type: 217.12.150.142:60069
type: 175.143.111.61:26229
type: 138.19.73.24:18130
type: 169.150.223.223:19359
type: 86.214.235.83:41740
type: 24.2.133.225:7840
type: 173.3.169.70:50321
type: 177.202.216.212:50321
type: 104.33.187.72:50321
type: 78.143.201.222:50321
type: 222.118.35.11:41060
type: 200.85.92.126:48896
type: 2.81.8.165:6882
type: 71.37.203.31:53455
type: 144.76.175.153:32240
type: 182.231.169.103:32848
type: 222.109.2.212:7750
type: 172.220.146.91:56420
type: 72.21.17.86:30624
type: 178.224.162.13:17392
type: 46.232.210.138:64219
type: 92.96.71.9:37097
type: 121.159.68.192:41176
type: 95.211.184.220:50204
type: 188.165.244.171:53832
type: 98.29.41.203:13553
type: 168.232.96.246:22728
type: 78.134.10.172:20484
type: 90.247.28.145:25101
type: 24.144.55.36:50838
type: 88.231.174.252:48971
type: 88.175.215.222:56818
type: 94.158.58.43:31624
type: 124.244.205.5:20748
type: 74.215.200.85:41504
type: 14.37.133.70:54444
type: 68.7.144.76:52576
type: 92.150.69.170:45386
type: 154.67.24.24:48892
type: 112.160.239.150:7584
type: 184.148.27.96:64819
type: 46.10.41.246:36147
type: 200.73.247.243:45732
type: 188.165.200.53:59029
type: 216.174.103.142:62747
type: 104.158.103.142:24688
type: 144.76.175.153:32232
type: 60.70.66.12:19343
type: 194.107.126.157:49566
type: 212.56.48.112:32564
type: 72.217.77.234:56282
type: 89.149.200.92:28022
type: 95.168.162.212:7724
type: 102.208.96.238:33282
type: 41.56.150.94:5960
type: 37.187.28.11:56789
type: 119.197.238.91:49318
type: 176.31.183.98:61748
type: 152.53.52.107:10240
type: 72.18.80.65:56881
type: 78.30.14.155:20234
type: 131.0.198.182:27667
type: 38.134.41.130:32681
type: 158.69.224.81:12393
type: 172.96.121.2:6884
type: 95.211.110.228:28012
type: 62.75.204.67:59736
type: 162.251.63.78:10013
type: 95.211.209.139:28011
type: 195.154.166.117:57731
type: 185.149.91.177:51005
type: 88.97.165.102:1857
type: 119.231.154.246:14485
type: 37.187.18.4:58490
type: 38.49.72.93:46459
type: 193.123.68.168:24258
type: 112.164.140.61:40980
type: 200.3.29.120:15821
type: 180.64.178.105:32896
type: 112.164.64.119:8228
type: 119.197.63.175:7720
type: 154.197.1.128:38468
type: 185.149.91.131:51040
type: 65.108.143.34:37777
type: 65.108.143.34:54161
Result
Signature
Behaviour
Result
Behaviour
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | enterpriseapps2 |
|---|---|
| Author: | Tim Brown @timb_machine |
| Description: | Enterprise apps |
| Rule name: | linux_generic_ipv6_catcher |
|---|---|
| Author: | @_lubiedo |
| Description: | ELF samples using IPv6 addresses |
| Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
|---|---|
| Author: | XiAnzheng |
| Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
| Rule name: | unixredflags3 |
|---|---|
| Author: | Tim Brown @timb_machine |
| Description: | Hunts for UNIX red flags |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
elf 66f90d08abb9edc2bb37920eeb24d3beb3ddcc71a56cf0cc6bbbde0908d00346
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.