MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d58b8f0e4d0496202a7612d1a6bc5ad69e2fc8d4e1e3891536aad548ca25626. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 6d58b8f0e4d0496202a7612d1a6bc5ad69e2fc8d4e1e3891536aad548ca25626
SHA3-384 hash: 3e35ee2a9a6317a68e0d659c28224533b69bb569c56bf56715a2a9996c992cbd70a4b74edbdb0db94ed9e32993a5b171
SHA1 hash: a2d5f05421672f78653a98e88a51f416c75e1782
MD5 hash: fd3b9b33d1ae6ba444349d05b828ba37
humanhash: illinois-virginia-alaska-north
File name:bot.arm
Download: download sample
Signature Mirai
File size:28'108 bytes
First seen:2022-06-11 20:50:05 UTC
Last seen:2022-06-14 04:46:29 UTC
File type: elf
MIME type:application/x-executable
ssdeep 768:KwxlCM2NWBVw6g+dPGzCpR1zm0s3Uozho:K0lCTNWBVl34WpRFUzq
TLSH T18BC2D01053CB98B5EBF00478D95F8399029A6FF525FD3A7A1A18C3D8B7809CA4C6C1DE
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Reporter tolisec
Tags:mirai

Intelligence


File Origin
# of uploads :
5
# of downloads :
470
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
arm
Packer:
UPX
Botnet:
62.197.136.92:80/pumaxnxx
Number of open files:
54
Number of processes launched:
6
Processes remaning?
false
Remote TCP ports scanned:
23
Behaviour
Information Gathering
Botnet C2s
TCP botnet C2(s):
62.197.136.92:9506
UDP botnet C2(s):
not identified
Result
Verdict:
MALICIOUS
Result
Threat name:
Unknown
Detection:
malicious
Classification:
troj.evad
Score:
56 / 100
Signature
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Uses known network protocols on non-standard ports
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 643997 Sample: bot.arm Startdate: 11/06/2022 Architecture: LINUX Score: 56 22 116.98.79.244, 23 VIETTEL-AS-VNViettelCorporationVN Viet Nam 2->22 24 152.225.164.176, 23 UUNETUS United States 2->24 26 98 other IPs or domains 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 Uses known network protocols on non-standard ports 2->30 32 Sample is packed with UPX 2->32 8 bot.arm 2->8         started        signatures3 process4 process5 10 bot.arm 8->10         started        12 bot.arm 8->12         started        14 bot.arm 8->14         started        process6 16 bot.arm 10->16         started        18 bot.arm 10->18         started        20 bot.arm 10->20         started       
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2022-06-11 06:28:22 UTC
File Type:
ELF32 Little (Exe)
AV detection:
12 of 41 (29.27%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 6d58b8f0e4d0496202a7612d1a6bc5ad69e2fc8d4e1e3891536aad548ca25626

(this sample)

  
Delivery method
Distributed via web download

Comments