MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8b74d8fb258ece023d9305e2faecb5d223204bc1a7ae888601d5ff7c1fa8a3da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments 1

SHA256 hash: 8b74d8fb258ece023d9305e2faecb5d223204bc1a7ae888601d5ff7c1fa8a3da
SHA3-384 hash: 2acb04670b9aaa7973e2673a99e81c471c4cd0b0179e663f474cdeccd028139fd0b7527ae5014c6244a08d147e0e1c21
SHA1 hash: da59867c4bb6193febe5d86cafed1a2715831ab4
MD5 hash: 89fbc7c541d9104bc0bbc67dcb721c3e
humanhash: robin-east-missouri-network
File name:89fbc7c541d9104bc0bbc67dcb721c3e
Download: download sample
Signature Mirai
File size:30'204 bytes
First seen:2022-01-10 12:37:25 UTC
Last seen:2022-01-10 14:52:24 UTC
File type: elf
MIME type:application/x-executable
ssdeep 768:zUhFhsBry9UNzP/2jPejvop1VQC4Dw9/bUYq3UI+V:z48vzGjPejApQCN/of4
TLSH T16DD2E062EB28BD17C5F10F72E6FE060877181C5CAAFE3B6712550A25AC9114BDA9D036
Reporter zbetcheckin
Tags:32 arm elf mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
228
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
arm
Packer:
UPX
Botnet:
unknown
Number of open files:
0
Number of processes launched:
0
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Verdict:
MALICIOUS
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
52 / 100
Signature
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Behaviour
Behavior Graph:
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2022-01-10 12:38:11 UTC
File Type:
ELF32 Little (Exe)
AV detection:
12 of 28 (42.86%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 8b74d8fb258ece023d9305e2faecb5d223204bc1a7ae888601d5ff7c1fa8a3da

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2022-01-10 12:37:27 UTC

url : hxxp://95.181.161.60/bins/yakuza.arm6