MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f61085bfb975ac092e8d727ce28dffc4d8f8974a2be437a1871aa99774863e7a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments 1

SHA256 hash: f61085bfb975ac092e8d727ce28dffc4d8f8974a2be437a1871aa99774863e7a
SHA3-384 hash: e6d9c96186213e9fd864010d2fd9e1fd4d1731478430c4c811e27ead63ac4fe1032763dfd901f993323db9fcb0bb632e
SHA1 hash: e5ecb2a8504d22ecb7ca887793303629b6332cc3
MD5 hash: 0e1b35532b87759f87301355e9fa1d70
humanhash: quebec-wolfram-one-beryllium
File name:0e1b35532b87759f87301355e9fa1d70
Download: download sample
Signature Mirai
File size:128'047 bytes
First seen:2021-07-14 13:06:39 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:IZMu4C+u2dLhLRE90bYK5h9T96NOI+5/YtM/9gM/:eMu4C+u+RfbYK5hb6R+5/AM/9gM/
TLSH T116C32A46EA408B13C5D61777FAAF414A3322DB54D3DB330689285BF43F87A9E0E57A06
telfhash t1c121e4b1471a56246665cfec8ddd73aa022c83155386df33df21c4ec640909de535c8f
Reporter zbetcheckin
Tags:32 arm elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
102
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
arm
Packer:
not packed
Botnet:
46.166.185.38:80/AB4g5
Number of open files:
0
Number of processes launched:
0
Processes remaning?
false
Remote TCP ports scanned:
23
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
46.166.185.38:420
UDP botnet C2(s):
not identified
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2021-07-14 13:07:09 UTC
AV detection:
29 of 46 (63.04%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf f61085bfb975ac092e8d727ce28dffc4d8f8974a2be437a1871aa99774863e7a

(this sample)

Comments



Avatar
zbet commented on 2021-07-14 13:06:40 UTC

url : hxxp://46.166.185.38/AB4g5/Josho.arm7