MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 951911dff3f6aeeef60f38f1d19bddfb6328c797d5cfbcca414c97b15312435e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments 1

SHA256 hash: 951911dff3f6aeeef60f38f1d19bddfb6328c797d5cfbcca414c97b15312435e
SHA3-384 hash: 8c03d9e0cdbe6d88f1bc6ab7431a8d5484f41696555c1ce04d9234060eb5fdcbf9391c1adc8e5d74ee9d4cf09e5bd04e
SHA1 hash: c76ef8a049023f35e31ff44c574d5723f310d264
MD5 hash: b1ba6a99fe97d98c00abb694fc06ae58
humanhash: april-helium-lemon-lemon
File name:b1ba6a99fe97d98c00abb694fc06ae58
Download: download sample
Signature Mirai
File size:26'292 bytes
First seen:2021-12-24 00:36:30 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:xRSa8ZS/L6rze3OX9uV1uGCcuNdpz6s3UozYW:vSjFJX9uVUGCc8p7z1
TLSH T1B4C2E13624509471C371157CFBBCC1938AE648F4C1E432E6281896FA755BBCE61BAACF
Reporter zbetcheckin
Tags:32 arm elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
arm
Packer:
UPX
Botnet:
unknown
Number of open files:
0
Number of processes launched:
0
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
76 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Yara detected Mirai
Behaviour
Behavior Graph:
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2021-12-23 22:39:58 UTC
File Type:
ELF32 Little (Exe)
AV detection:
16 of 25 (64.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 951911dff3f6aeeef60f38f1d19bddfb6328c797d5cfbcca414c97b15312435e

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-12-24 00:36:30 UTC

url : hxxp://205.185.117.54/d/xd.arm5