MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dfaffe78b8ccb03626c2f55596f977da917e8e9a00ee7576ce9eca688d88447d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 5 File information Comments 1

SHA256 hash: dfaffe78b8ccb03626c2f55596f977da917e8e9a00ee7576ce9eca688d88447d
SHA3-384 hash: 83c769affddeab222755bb8afce00bfa4ccfb91c588e68ca5838a690a0b5c68d6df2f530439554216cac3d1be1f9e74c
SHA1 hash: a760daa7d545f7ffcf2ae85cfa8f37418bfaa9cf
MD5 hash: e996bbe2ebde333ee6c7ba78e4fb5e63
humanhash: alpha-massachusetts-black-solar
File name:e996bbe2ebde333ee6c7ba78e4fb5e63
Download: download sample
File size:26'444 bytes
First seen:2023-01-12 10:36:53 UTC
Last seen:2023-01-12 15:01:38 UTC
File type: elf
MIME type:application/x-executable
ssdeep 384:foWBUmvS/hMv91kMSVCtUi+HzffkfbdusfJliYgVbmejL9q1l21IrB0ju:JavhMv7kM45Rff8rJsdmeNqHeiB0j
TLSH T192C21892F907E4F5EC2740B580E7A7BF9F35A8B980208E6EEB19DB25D913542471334D
telfhash t1591140b57da515f4f7c0bd4d871f1243d6368af32711b8ed44b123113be2165e231520
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Reporter zbetcheckin
Tags:32 elf intel

Intelligence


File Origin
# of uploads :
2
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
anti-debug
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
1
Number of processes launched:
2
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Process Renaming
Botnet C2s
TCP botnet C2(s):
109.206.243.207:5555
UDP botnet C2(s):
not identified
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
64 / 100
Signature
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Behaviour
Behavior Graph:
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2023-01-12 10:37:07 UTC
File Type:
ELF32 Little (Exe)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
linux
Behaviour
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Trojan_Mirai_0cb1699c
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_268aac0b
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_88de437f
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_cc93863b
Author:Elastic Security
Rule name:meth_get_eip
Author:Willi Ballenthin

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

elf dfaffe78b8ccb03626c2f55596f977da917e8e9a00ee7576ce9eca688d88447d

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2023-01-12 10:37:08 UTC

url : hxxp://109.206.243.207/ssh/bot