MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d64baaf6b7b20fbc126ed7a151154aeeb068e53035cf33ef60a133479899d8a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 6d64baaf6b7b20fbc126ed7a151154aeeb068e53035cf33ef60a133479899d8a
SHA3-384 hash: 04777a08f2e5b3d4e5a99fac411ff504162e97b7cf986dfe97392aa47b44d2a062b210b5810fa6f8d6491e867f8fef97
SHA1 hash: 74f7d8fe7a5f2407f6aa335964c8f64e66be7343
MD5 hash: 82c7fb8e4c3ffd2cc55502ddddd491af
humanhash: sweet-missouri-ohio-eighteen
File name:arm
Download: download sample
Signature Mirai
File size:19'384 bytes
First seen:2021-12-11 18:50:06 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 384:KEq/3fft8F8Xq5Wm0DdPqPiSs8zzpRa1t8lOz1nRJMvG5Vz7ts1chymdGUop5ho:aftZq5g0PVsg1iyw1RJj5dtqcs3UozO
TLSH T1E592B0704557FD33CBF00476877B00410B936A75F2EE71AA4FA41236A79782BF1BA296
Reporter tolisec
Tags:mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
161
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
arm
Packer:
UPX
Botnet:
45.95.169.115:80/bins
Number of open files:
3
Number of processes launched:
3
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Process Renaming
Botnet C2s
TCP botnet C2(s):
45.95.169.115:2113
UDP botnet C2(s):
not identified
Result
Verdict:
UNKNOWN
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
evad
Score:
22 / 100
Signature
Sample is packed with UPX
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 538310 Sample: arm Startdate: 11/12/2021 Architecture: LINUX Score: 22 26 109.202.202.202, 80 INIT7CH Switzerland 2->26 28 45.95.169.115, 2113, 33822, 33824 GIGANET-HUGigaNetInternetServiceProviderCoHU Croatia (LOCAL Name: Hrvatska) 2->28 30 3 other IPs or domains 2->30 32 Sample is packed with UPX 2->32 8 arm 2->8         started        10 dash cut 2->10         started        12 dash tr 2->12         started        14 7 other processes 2->14 signatures3 process4 process5 16 arm 8->16         started        18 arm sh 8->18         started        20 arm sh 8->20         started        22 arm 8->22         started        process6 24 arm 16->24         started       
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2021-12-11 18:51:09 UTC
File Type:
ELF32 Little (Exe)
AV detection:
17 of 28 (60.71%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 6d64baaf6b7b20fbc126ed7a151154aeeb068e53035cf33ef60a133479899d8a

(this sample)

  
Delivery method
Distributed via web download

Comments