🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eb81b7c6dd9db0df2ea8680726c4a38a8302840f98e7e69f11db009388ef29ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MooBot


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments 1

SHA256 hash: eb81b7c6dd9db0df2ea8680726c4a38a8302840f98e7e69f11db009388ef29ee
SHA3-384 hash: 0dcb6f8e9cccb16f6e4ea73bd0afe0cc6a5af1b125a855415e2368aa4b5eba4d55ca1ff3862889f03247b9954c35bdea
SHA1 hash: fc2d022cd1455d35999b14b6a3b409256dc05ad4
MD5 hash: a4de3e382a38572ac47bf5ddc48169c5
humanhash: don-carpet-aspen-wolfram
File name:a4de3e382a38572ac47bf5ddc48169c5
Download: download sample
Signature MooBot
File size:33'612 bytes
First seen:2024-03-17 08:36:43 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 384:bAflUMkNhj3U6+bhgAeWWjhrF/YwI2OMTylJCMDtLBFrXEr3KSNpog/sqB0zaCvY:bAfhkNhjA0LdYwPylJCe2poYsTuCyD
TLSH T113E28EB3C01AAD48D598C67866616FB42763F005C3671FFA5A6A82A6C007DFCF5093F5
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Reporter zbetcheckin
Tags:32 elf mirai Moobot renesas

Intelligence


File Origin
# of uploads :
1
# of downloads :
140
Origin country :
FR FR
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug mirai
Result
Threat name:
Mirai, Moobot
Detection:
malicious
Classification:
troj.evad
Score:
76 / 100
Signature
Detected Mirai
Multi AV Scanner detection for submitted file
Sample deletes itself
Snort IDS alert for network traffic
Yara detected Moobot
Behaviour
Behavior Graph:
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2024-03-17 08:37:08 UTC
File Type:
ELF32 Little (Exe)
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai linux
Malware Config
C2 Extraction:
hoon.cyberium.cc
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

MooBot

elf eb81b7c6dd9db0df2ea8680726c4a38a8302840f98e7e69f11db009388ef29ee

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2024-03-17 08:36:43 UTC

url : hxxp://205.185.126.140/sh4