MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9e8755348f8c2bd8751be7fd4dc148993a7d6def3e5b2dbef2e1cba28f9337b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 9e8755348f8c2bd8751be7fd4dc148993a7d6def3e5b2dbef2e1cba28f9337b9
SHA3-384 hash: e901edf0096a40292693668bd330744c99e68896b494b6e37d77f935b8cb1322095d9efdd35054e56ec8303a0fb4ff2d
SHA1 hash: 63b1f495258dd2aa4e7bde8a24c61ed257ca3080
MD5 hash: 1e57a98da7ed7c9ee216cf4109db6411
humanhash: mexico-cold-diet-uranus
File name:meerkat.arm
Download: download sample
Signature Mirai
File size:28'892 bytes
First seen:2021-11-25 09:00:07 UTC
Last seen:2021-11-25 10:42:13 UTC
File type: elf
MIME type:application/x-executable
ssdeep 384:YsXTsXqPPk1zzqnZu/k32+3A1u2UxSKTgHPYsNKfS/bMU/QQNDRhymdGUop5hf:Y3akDaW1unxSKTRObvzNFs3UozZ
TLSH T18AD2D0F8C22D16BB87109C35B99883865B670BB921EF7415106129D8FA83C5FE9E5E0B
Reporter tolisec
Tags:mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
110
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
arm
Packer:
UPX
Botnet:
107.189.8.97:80/bins
Number of open files:
0
Number of processes launched:
2
Processes remaning?
false
Remote TCP ports scanned:
2323,23
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
107.189.8.97:34129
UDP botnet C2(s):
not identified
Result
Verdict:
UNKNOWN
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
68 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 528450 Sample: meerkat.arm Startdate: 25/11/2021 Architecture: LINUX Score: 68 18 Malicious sample detected (through community Yara rule) 2->18 20 Multi AV Scanner detection for submitted file 2->20 22 Yara detected Mirai 2->22 24 Sample is packed with UPX 2->24 8 meerkat.arm 2->8         started        process3 process4 10 meerkat.arm 8->10         started        12 meerkat.arm 8->12         started        process5 14 meerkat.arm 10->14         started        process6 16 meerkat.arm 14->16         started       
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2021-11-25 09:01:11 UTC
File Type:
ELF32 Little (Exe)
AV detection:
13 of 27 (48.15%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 9e8755348f8c2bd8751be7fd4dc148993a7d6def3e5b2dbef2e1cba28f9337b9

(this sample)

  
Delivery method
Distributed via web download

Comments