MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7438b709116b26b6f2640fbf2cd530d0c27fdfdede62af6ad83141029f84df59. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments 1

SHA256 hash: 7438b709116b26b6f2640fbf2cd530d0c27fdfdede62af6ad83141029f84df59
SHA3-384 hash: ddc039f4c14560b34b3bf31e81a324f544c6591ce19c475e95bcc399834864f35474b010f26bae5ab68b8d747088c363
SHA1 hash: 48ccb0c146a703839d0c62ea91cce3b266c6f516
MD5 hash: ffa6f19caa2a312d59d625747afef33f
humanhash: blue-enemy-sierra-earth
File name:ffa6f19caa2a312d59d625747afef33f
Download: download sample
Signature Gafgyt
File size:125'444 bytes
First seen:2023-12-24 07:43:34 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:3ImSKIw4af2iBqV9qg+ZEktoQpYMlIYhY0dogZ4cVIoR4EXtznAZBLev6b30lM5U:Y3zvqptEG00l8d74YbSNwbZn2OPS
TLSH T133C33A25BA361D17C0C4A5B722F70731B2F343C926A8C65D7EB20D5EEF642406297AF9
Reporter zbetcheckin
Tags:32 elf gafgyt mirai sparc

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
FR FR
Vendor Threat Intelligence
Detection(s):
Sanesecurity.Malware.28880.LC.UNOFFICIAL
Sanesecurity.Malware.29325.LC.Pl.UNOFFICIAL
SecuriteInfo.com.Linux.Mirai-81.UNOFFICIAL
Sanesecurity.Malware.28886.LC.UNOFFICIAL
Sanesecurity.Malware.29524.LC.UNOFFICIAL
Sanesecurity.Malware.28878.LC.UNOFFICIAL
Sanesecurity.Malware.28877.LC.UNOFFICIAL
Unix.Trojan.Mirai-7100807-0
Unix.Dropper.Mirai-7135868-0
Unix.Dropper.Mirai-7135891-0
Unix.Dropper.Mirai-7135892-0
Unix.Dropper.Mirai-7136013-0
Unix.Dropper.Mirai-7136034-0
Unix.Dropper.Mirai-7136057-0
Unix.Dropper.Mirai-7540663-0
Unix.Trojan.Mirai-8025795-0
Unix.Trojan.Mirai-9441505-0
Unix.Trojan.Mirai-9858729-0
Unix.Trojan.Mirai-9945193-0
Unix.Trojan.Mirai-9946826-0
Unix.Dropper.Mirai-9977145-0
Unix.Dropper.Mirai-10008433-0
Unix.Trojan.Mirai-10011027-0
Unix.Trojan.Mirai-10011918-0
Unix.Packed.Botnet-6566031-0
Unix.Dropper.Botnet-6566040-0
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug botnet lolbin mirai mirai obfuscated remote
Result
Verdict:
MALICIOUS
Result
Threat name:
Mirai, Moobot
Detection:
malicious
Classification:
troj
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Uses known network protocols on non-standard ports
Yara detected Mirai
Yara detected Moobot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1366630 Sample: ucNsAA52u4.elf Startdate: 24/12/2023 Architecture: LINUX Score: 100 37 197.152.130.216, 37215 airtel-tz-asTZ Tanzania United Republic of 2->37 39 157.183.233.229 WVUUS United States 2->39 41 98 other IPs or domains 2->41 43 Snort IDS alert for network traffic 2->43 45 Malicious sample detected (through community Yara rule) 2->45 47 Antivirus / Scanner detection for submitted sample 2->47 49 5 other signatures 2->49 9 ucNsAA52u4.elf 2->9         started        signatures3 process4 process5 11 ucNsAA52u4.elf 9->11         started        13 ucNsAA52u4.elf sh 9->13         started        process6 15 ucNsAA52u4.elf 11->15         started        17 ucNsAA52u4.elf 11->17         started        19 ucNsAA52u4.elf 11->19         started        21 sh rm 13->21         started        23 sh mkdir 13->23         started        25 sh mv 13->25         started        27 sh chmod 13->27         started        process7 29 ucNsAA52u4.elf 15->29         started        31 ucNsAA52u4.elf 15->31         started        33 ucNsAA52u4.elf 15->33         started        35 1486 other processes 15->35
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2023-12-24 03:25:40 UTC
File Type:
ELF32 Big (Exe)
AV detection:
19 of 37 (51.35%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:mirai linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

elf 7438b709116b26b6f2640fbf2cd530d0c27fdfdede62af6ad83141029f84df59

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2023-12-24 07:43:34 UTC

url : hxxp://37.44.238.75/mont/.nekoisdaddy.spc