MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc3e37db8c6f385ceee81cc24228c31cd7a2a61d850fb08cca3cb3b05a44311b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: cc3e37db8c6f385ceee81cc24228c31cd7a2a61d850fb08cca3cb3b05a44311b
SHA3-384 hash: 3931c184cd4c3524998bd6cf170bea0c6f0c9ae5181b98e743febd71e4267a009b64a88d5fcdbf31e59a5096bd492a22
SHA1 hash: e38a54c2421334958763535aa46d41fe6af9c36c
MD5 hash: bb995306925045f59e813566ea3671b8
humanhash: network-july-leopard-september
File name:Mozi.a
Download: download sample
File size:89'600 bytes
First seen:2021-06-02 20:01:08 UTC
Last seen:2021-06-02 20:48:49 UTC
File type: elf
MIME type:application/x-executable
ssdeep 1536:pxpJNlEYvXndUt/afLuZmVelu9eoCtcCCzNbC4RWC0CQFW3RLlNCzE:phNlHuBafLeBtfCzpta8xlB
TLSH 41930206BF35DD0ADF100C632ADE8F9E8C78BA5B8A9BB4B569D1948F17D00CA7857305
Reporter tolisec

Intelligence


File Origin
# of uploads :
2
# of downloads :
101
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
mips
Packer:
custom
Botnet:
115.88.206.32:59689
Number of open files:
0
Number of processes launched:
1
Processes remaning?
false
Result
Verdict:
MALICIOUS
Threat name:
Linux.Worm.Mozi
Status:
Malicious
First seen:
2021-06-02 20:02:10 UTC
AV detection:
5 of 47 (10.64%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf cc3e37db8c6f385ceee81cc24228c31cd7a2a61d850fb08cca3cb3b05a44311b

(this sample)

  
Delivery method
Distributed via web download

Comments