MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ff68b33622215372ab6e21df9f3fe9d91ef66ae7bb9d2e5c17e18cbe84121c7d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 8
| SHA256 hash: | ff68b33622215372ab6e21df9f3fe9d91ef66ae7bb9d2e5c17e18cbe84121c7d |
|---|---|
| SHA3-384 hash: | 1bb13c62b4b65a7d6934cd01b3d92bfc74de3f549abb97b8fba808e7d375c3e31f103658b1d8984e0a9ae0cd798507bd |
| SHA1 hash: | e0824059cdad49c8f46113c185845100131c6997 |
| MD5 hash: | 629d53f97f2110b1c976a99e191e733c |
| humanhash: | december-papa-delaware-diet |
| File name: | mips |
| Download: | download sample |
| File size: | 592'688 bytes |
| First seen: | 2025-07-05 17:15:01 UTC |
| Last seen: | Never |
| File type: | elf |
| MIME type: | application/x-executable |
| ssdeep | 12288:M57U0INmdtgOcyJXDOMzf03gdvZ/yCnEI7zi:W7v+mrY2xzf03yvZ/YIC |
| TLSH | T1AEC4F1A377204F91C35195B209F389335AF6199706F39982537DEE107F20A68386BFE9 |
| telfhash | t10ab0011070740bb84308e12d5cdcae5679f20cc3fe470c27db6047a159b54434d00d18 |
| Magika | elf |
| Reporter | |
| Tags: | elf |
Intelligence
File Origin
DEVendor Threat Intelligence
Result
Behaviour
Behaviour
Botnet C2s
type: 130.239.18.158:6881
type: 67.215.246.10:6881
type: 5.79.98.134:6881
type: 37.2.166.222:6881
type: 216.128.97.44:6881
type: 172.118.8.49:6881
type: 112.186.10.138:6881
type: 24.193.65.157:6881
type: 73.63.201.84:6881
type: 223.122.130.123:6881
type: 50.46.5.78:6881
type: 94.113.97.103:6881
type: 184.65.184.4:6881
type: 112.119.103.176:6881
type: 18.221.7.72:6881
type: 190.18.29.123:6881
type: 85.254.34.110:6881
type: 35.167.186.212:6881
type: 35.155.156.153:6881
type: 176.193.178.107:6881
type: 213.154.15.64:6881
type: 18.191.2.28:6881
type: 54.214.62.55:6881
type: 153.34.34.25:6881
type: 18.218.241.3:6881
type: 59.188.59.46:6881
type: 13.58.27.33:6881
type: 18.223.137.220:6881
type: 171.6.107.139:6881
type: 194.233.81.181:6881
type: 82.44.124.225:6881
type: 220.246.210.25:6881
type: 124.62.154.2:6881
type: 45.152.210.37:6881
type: 174.17.163.132:6881
type: 54.70.174.84:6881
type: 18.188.31.0:6881
type: 94.140.240.18:6881
type: 27.114.153.102:6881
type: 89.85.27.38:6881
type: 90.116.213.16:6881
type: 93.81.253.179:6881
type: 95.154.160.92:6881
type: 135.181.238.57:50000
type: 37.27.117.113:50000
type: 135.181.227.244:50000
type: 37.27.103.253:50000
type: 88.99.145.203:50000
type: 135.181.227.243:50000
type: 65.21.129.47:50000
type: 37.27.119.180:50000
type: 37.27.117.251:50000
type: 37.27.120.54:50000
type: 65.21.125.160:50000
type: 65.21.128.209:50000
type: 65.21.128.235:50000
type: 37.27.117.180:50000
type: 37.27.103.248:50000
type: 37.27.107.116:50000
type: 65.21.128.214:50000
type: 65.21.128.240:50000
type: 65.21.125.186:50000
type: 65.21.129.49:50000
type: 37.27.119.253:50000
type: 65.21.125.166:50000
type: 167.235.10.94:50000
type: 65.21.129.56:50000
type: 65.21.125.174:50000
type: 37.27.119.183:50000
type: 148.251.41.51:50000
type: 37.27.120.62:50000
type: 37.27.117.119:50000
type: 135.181.223.86:50000
type: 37.27.104.50:50000
type: 95.216.3.146:50000
type: 37.27.119.119:50000
type: 37.27.104.49:50000
type: 65.21.128.232:50000
type: 37.27.119.244:50000
type: 37.27.119.190:50000
type: 37.27.104.57:50000
type: 135.181.238.121:50000
type: 65.21.125.172:50000
type: 65.21.125.161:50000
type: 65.108.194.186:50000
type: 213.239.217.110:50000
type: 37.27.107.117:50000
type: 88.99.91.85:50000
type: 135.181.223.105:50000
type: 37.27.107.123:50000
type: 37.27.119.175:50000
type: 135.181.238.61:50000
type: 37.27.117.190:50000
type: 65.109.84.42:50000
type: 65.21.128.216:50000
type: 65.21.128.237:50000
type: 135.181.238.53:50000
type: 37.27.103.244:50000
type: 37.27.117.125:50000
type: 37.27.103.183:50000
type: 65.21.128.249:50000
type: 37.27.117.186:50000
type: 37.27.117.239:50000
type: 37.27.117.178:50000
type: 65.21.128.228:50000
type: 130.239.18.158:8515
type: 178.162.174.222:28014
type: 178.162.174.82:28014
type: 178.162.174.43:28004
type: 178.162.174.227:28004
type: 178.162.174.237:28004
type: 178.162.174.121:28004
type: 178.162.173.2:28004
type: 130.239.18.158:8524
type: 178.162.174.149:28001
type: 178.162.174.178:28001
type: 5.79.73.138:28001
type: 37.187.20.193:51413
type: 95.211.81.107:51413
type: 93.89.141.246:51413
type: 77.37.168.146:51413
type: 94.190.112.28:51413
type: 89.168.69.159:51413
type: 45.132.114.236:51413
type: 5.135.158.154:51413
type: 5.39.95.146:51413
type: 138.199.27.226:51413
type: 37.59.61.117:51413
type: 37.187.116.102:51413
type: 178.66.50.3:51413
type: 97.119.101.177:51413
type: 5.135.162.33:51413
type: 31.20.226.127:51413
type: 5.196.69.84:51413
type: 78.99.136.225:51413
type: 86.86.174.235:51413
type: 62.171.181.95:51413
type: 5.80.32.47:51413
type: 118.209.30.128:51413
type: 60.140.146.30:51413
type: 139.99.104.39:51413
type: 176.31.182.29:51413
type: 121.224.141.72:51413
type: 195.218.227.142:51413
type: 31.187.156.172:51413
type: 195.154.233.74:6880
type: 3.141.159.213:6880
type: 3.12.65.135:6880
type: 148.153.170.2:6880
type: 44.210.22.159:6880
type: 50.17.19.6:6880
type: 3.218.205.217:6880
type: 178.162.173.91:28003
type: 178.162.173.105:28003
type: 130.239.18.158:8597
type: 130.239.18.158:8513
type: 142.202.48.88:10099
type: 130.239.18.158:8580
type: 130.239.18.158:8516
type: 45.136.230.224:50171
type: 89.149.200.92:28027
type: 178.162.173.12:28007
type: 178.162.173.89:28007
type: 37.48.71.178:28007
type: 54.211.14.111:20871
type: 123.202.50.214:20578
type: 93.165.252.80:11887
type: 69.50.95.40:10000
type: 178.162.173.111:28008
type: 183.97.84.214:65339
type: 185.183.35.248:6882
type: 46.32.67.137:6882
type: 185.149.91.171:51010
type: 178.162.174.102:28009
type: 178.162.173.172:28009
type: 46.232.211.211:58145
type: 46.232.211.211:64183
type: 178.162.174.173:28016
type: 95.168.168.234:52277
type: 45.137.83.14:20401
type: 51.38.81.212:8658
type: 57.129.45.81:8658
type: 195.201.179.130:16309
type: 108.163.159.4:22265
type: 81.171.20.66:64010
type: 46.232.211.148:11209
type: 195.154.171.138:30519
type: 178.162.174.106:28002
type: 95.211.247.101:28013
type: 213.227.151.25:28013
type: 212.7.200.93:23999
type: 5.135.165.33:6331
type: 88.198.230.221:49668
type: 221.229.53.143:6892
type: 18.196.86.103:6892
type: 185.21.216.185:60731
type: 72.21.17.87:31328
type: 163.172.10.195:32912
type: 185.203.56.37:64462
type: 212.7.200.12:65423
type: 89.149.221.10:61481
type: 178.162.173.166:28006
type: 178.162.173.136:28006
type: 176.56.239.28:6774
type: 163.172.219.66:62882
type: 62.112.10.81:6887
type: 103.140.3.2:63885
type: 213.227.153.16:28005
type: 185.186.132.182:57687
type: 169.197.143.248:62256
type: 178.198.39.89:49001
type: 176.213.7.92:49001
type: 151.252.109.130:49001
type: 84.244.31.169:49001
type: 178.65.229.6:49001
type: 193.151.240.56:49001
type: 86.11.185.10:49001
type: 85.94.12.210:49001
type: 51.15.228.13:51542
type: 5.2.130.18:17970
type: 125.200.31.232:14652
type: 185.149.91.39:51024
type: 37.59.60.43:59452
type: 113.158.164.249:6889
type: 46.171.77.230:6889
type: 82.206.68.88:6889
type: 91.183.35.68:6889
type: 85.236.5.74:6889
type: 24.132.161.14:6889
type: 37.18.105.171:6889
type: 85.220.189.46:50361
type: 146.120.165.83:21665
type: 50.42.103.147:57936
type: 94.31.75.106:37179
type: 220.119.154.196:40732
type: 213.47.44.228:42819
type: 80.213.29.77:9008
type: 185.149.91.148:51530
type: 46.98.118.191:36293
type: 45.142.232.203:49352
type: 14.45.189.129:32967
type: 109.161.200.73:34856
type: 118.102.68.201:45960
type: 213.138.246.242:24330
type: 142.122.120.105:29394
type: 188.27.234.80:41181
type: 89.134.8.242:6309
type: 50.111.64.168:44904
type: 187.245.66.247:29646
type: 90.11.2.63:45454
type: 149.88.121.174:29578
type: 176.63.19.241:4821
type: 24.135.37.83:6893
type: 88.244.91.172:53115
type: 218.41.96.245:40638
type: 60.79.230.34:45658
type: 31.10.154.105:9869
type: 88.115.110.26:60087
type: 119.201.91.42:33180
type: 187.46.245.164:35288
type: 201.4.28.99:47475
type: 211.112.84.62:39065
type: 188.165.231.168:54715
type: 61.58.97.67:34068
type: 77.137.68.108:3235
type: 183.103.246.250:40643
type: 152.53.45.107:7186
type: 24.215.82.99:34436
type: 89.23.103.21:38231
type: 93.183.167.21:54733
type: 223.187.27.9:48337
type: 176.79.19.241:44144
type: 37.133.233.159:16555
type: 211.206.7.29:7908
type: 92.114.251.164:39951
type: 173.225.242.206:45629
type: 160.176.53.46:10874
type: 88.240.181.46:51629
type: 144.76.175.153:43246
type: 122.37.186.54:40858
type: 194.29.101.83:10240
type: 95.214.53.172:1688
type: 78.142.231.133:6767
type: 208.87.240.21:11162
type: 54.39.52.64:64804
type: 152.53.45.107:7238
type: 38.134.41.130:32681
type: 47.89.251.173:7777
type: 1.21.49.182:3713
type: 72.21.17.85:62734
type: 178.162.173.220:28015
type: 89.212.208.90:23779
type: 98.184.218.186:10993
type: 46.232.211.200:24259
type: 104.36.20.99:26659
type: 46.232.211.180:15509
type: 185.203.56.20:21575
type: 178.162.173.224:28011
type: 185.203.56.55:23389
type: 185.21.217.5:53575
type: 185.203.56.38:31324
type: 112.187.6.119:33223
type: 78.58.131.70:29922
type: 111.99.103.41:18679
type: 142.181.146.35:42129
type: 185.149.91.29:51001
type: 76.231.26.196:46933
type: 102.132.222.85:51940
type: 195.154.225.2:51414
type: 190.137.185.1:56332
type: 81.22.132.133:43995
type: 14.52.68.234:42066
type: 181.9.206.3:33253
type: 72.21.17.39:24254
type: 138.64.209.18:7740
type: 195.154.172.179:27752
type: 83.4.151.65:54860
type: 213.152.176.135:52532
type: 82.112.160.7:40393
type: 105.113.112.45:20747
type: 213.134.166.117:29816
type: 69.232.241.144:50505
type: 174.126.32.180:20357
type: 185.203.56.12:18410
type: 87.191.42.29:21849
type: 72.27.100.167:44355
type: 58.176.4.44:21042
type: 37.5.251.53:11618
type: 38.194.150.212:62951
type: 116.255.23.55:40762
type: 31.223.52.196:44851
type: 181.94.228.75:55673
type: 5.29.23.177:19278
type: 188.165.250.70:58759
type: 5.68.62.236:37803
type: 37.27.113.233:30532
Result
Signature
Behaviour
Result
Behaviour
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | enterpriseapps2 |
|---|---|
| Author: | Tim Brown @timb_machine |
| Description: | Enterprise apps |
| Rule name: | linux_generic_ipv6_catcher |
|---|---|
| Author: | @_lubiedo |
| Description: | ELF samples using IPv6 addresses |
| Rule name: | unixredflags3 |
|---|---|
| Author: | Tim Brown @timb_machine |
| Description: | Hunts for UNIX red flags |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
elf ff68b33622215372ab6e21df9f3fe9d91ef66ae7bb9d2e5c17e18cbe84121c7d
(this sample)
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_PIE | Missing Position-Independent Executable (PIE) Protection | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.