MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a2872d8fd93f0a40feb2801b2fde19148f13c431656fdc12852021489070644d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a2872d8fd93f0a40feb2801b2fde19148f13c431656fdc12852021489070644d
SHA3-384 hash: 97913a2f50e25d9dc269b655a690d7c2af1b438c8581af0f70a0a4d818e721f2be620abfcd7d9fa9de4fc9470cee09f1
SHA1 hash: 3940a1969141078f78ca4c5747b7b038908387e8
MD5 hash: 75363f678361b6ab257c53db004f70c4
humanhash: comet-comet-pasta-angel
File name:75363f678361b6ab257c53db004f70c4
Download: download sample
Signature Mirai
File size:65'780 bytes
First seen:2021-06-19 21:03:22 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:9G6XmGH7ySwA60AoSsKI7hku+lgsrszadZZz9tgiy:s6fmuXsrpZphy
TLSH 2C530276065219708870E5BCFF2C89EB3FE729B0E5EFE573284583740A37926E2252D5
Reporter zbetcheckin
Tags:32 arm elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
arm
Packer:
UPX
Botnet:
Number of open files:
1276
Number of processes launched:
3
Processes remaning?
true
Behaviour
Persistence
Process Renaming
Botnet C2s
TCP botnet C2(s):
136.144.41.164:1
Result
Verdict:
UNKNOWN
Threat name:
Linux.Trojan.Gafgyt
Status:
Malicious
First seen:
2021-06-19 21:04:14 UTC
AV detection:
11 of 29 (37.93%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf a2872d8fd93f0a40feb2801b2fde19148f13c431656fdc12852021489070644d

(this sample)

  
Delivery method
Distributed via web download

Comments