MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 badc89fd1e3b4d7d2e05ff94be4c70ac032d658b0ca5fac9353e23cd245cc418. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: badc89fd1e3b4d7d2e05ff94be4c70ac032d658b0ca5fac9353e23cd245cc418
SHA3-384 hash: e5b670d34626aeb09e931499a742caa671501f62c7d8f9a5dd5a8bde7c25102cb18201e48ea65d5c1483fd979d752e9b
SHA1 hash: 74155a3f4178860b90feb572af1d55071a104bf9
MD5 hash: aad17cba61b4d49007e1234581e304f8
humanhash: april-jupiter-harry-failed
File name:x86
Download: download sample
Signature Mirai
File size:46'288 bytes
First seen:2021-10-18 21:00:04 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:r0U9qSFRmm/dI0prbhaRiejEG2AZHtQaMGO7HEOI3thmDJnnbcuyD7UWyqdvXQGt:IU0cRmipr1aRSYp27Hp8vmlnnouy8Nqz
TLSH T12123F143681B52CDD399BA728CCFF51D0C59465EC7962BB2B38C5533CFE27622298362
Reporter tolisec
Tags:gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
124
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
custom
Botnet:
45.95.169.115:80/StableBins
Number of open files:
4
Number of processes launched:
5
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Verdict:
MALICIOUS
Result
Threat name:
Detection:
malicious
Classification:
spre.troj
Score:
60 / 100
Signature
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 505110 Sample: x86 Startdate: 18/10/2021 Architecture: LINUX Score: 60 20 14.226.70.205, 23, 39230 VNPT-AS-VNVNPTCorpVN Viet Nam 2->20 22 37.10.181.13, 23, 35106 TELEFONICA_DE_ESPANAES Spain 2->22 24 5 other IPs or domains 2->24 26 Multi AV Scanner detection for submitted file 2->26 28 Yara detected Mirai 2->28 9 x86 2->9         started        signatures3 process4 signatures5 30 Opens /proc/net/* files useful for finding connected devices and routers 9->30 12 x86 9->12         started        process6 process7 14 x86 12->14         started        process8 16 x86 14->16         started        18 x86 14->18         started       
Threat name:
Linux.Trojan.Gafgyt
Status:
Malicious
First seen:
2021-10-18 21:00:18 UTC
AV detection:
13 of 45 (28.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf badc89fd1e3b4d7d2e05ff94be4c70ac032d658b0ca5fac9353e23cd245cc418

(this sample)

  
Delivery method
Distributed via web download

Comments