MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ddd0d2b210d35927b2eb7e858d302622a533131df5c3e004c5a0dfd4ba435f91. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments 1

SHA256 hash: ddd0d2b210d35927b2eb7e858d302622a533131df5c3e004c5a0dfd4ba435f91
SHA3-384 hash: a36b23f17b25279df8d354593ffdd522e3419e5920abd4e54520d505be1d6abcd2a0149a8f77a6ca645bf67df746b602
SHA1 hash: 1d89ebcb6037d3b901afaee97941a8d71fd07118
MD5 hash: b00dca7456327227beed7a3c22facdbd
humanhash: spaghetti-bulldog-florida-happy
File name:b00dca7456327227beed7a3c22facdbd
Download: download sample
Signature Mirai
File size:92'168 bytes
First seen:2021-10-16 02:14:34 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:xQutcVXS4EgUa6M97KiZHvXJlvgrUw8tez5+dhr7J2rXfEFb1l1Wqtpw/v:6bk2UYmiZHvXJlvgrUNhdhr7UfEFb1lk
TLSH T19293406B7E209F29F75C573106FBAC28834A13A726E5E64AD18FD6005E3132D1C1FAB5
Reporter zbetcheckin
Tags:32 elf mips mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
128
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
mips
Packer:
not packed
Botnet:
unknown
Number of open files:
0
Number of processes launched:
4
Processes remaning?
true
Remote TCP ports scanned:
23
Behaviour
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Uses known network protocols on non-standard ports
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 503868 Sample: vdQzjfJR0u Startdate: 16/10/2021 Architecture: LINUX Score: 68 16 185.156.114.138 XFIBER-ASNO Norway 2->16 18 46.6.213.188 XFERAES Spain 2->18 20 98 other IPs or domains 2->20 22 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Yara detected Mirai 2->26 28 Uses known network protocols on non-standard ports 2->28 8 vdQzjfJR0u 2->8         started        signatures3 process4 process5 10 vdQzjfJR0u 8->10         started        process6 12 vdQzjfJR0u 10->12         started        14 vdQzjfJR0u 10->14         started       
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2021-10-16 02:15:10 UTC
AV detection:
12 of 45 (26.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf ddd0d2b210d35927b2eb7e858d302622a533131df5c3e004c5a0dfd4ba435f91

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-10-16 02:14:35 UTC

url : hxxp://23.94.37.59/ivano.mips