MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ff83788996f4b60c59075e202827a6bf2345cb0dea1d95a3634899ea7f883f45. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments 1

SHA256 hash: ff83788996f4b60c59075e202827a6bf2345cb0dea1d95a3634899ea7f883f45
SHA3-384 hash: ca0509fb2a5e71f874d3c4b7af436b5a3a4b41944b4190c414841bae769ffedef9592527fbeb2f1a5230bbc4130edaf2
SHA1 hash: 740baffb01a7d03f53b4bdc3c539511527ef50d8
MD5 hash: c1c90fa5655ed387def19a639f39fdcc
humanhash: golf-early-idaho-stream
File name:c1c90fa5655ed387def19a639f39fdcc
Download: download sample
Signature Mirai
File size:129'980 bytes
First seen:2023-12-24 07:37:19 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:9pNnHA9Tl86XXxZ9IzidQMQuE+FjCJKF/y4Qs2eTBnbi:Sd3Xh8WfTE0jty4J2eJbi
TLSH T144C35CC6F802AEAEF84B93B6445F090DB97053C06B63162AE7DB7EA7EC360D46C15D44
Reporter zbetcheckin
Tags:32 elf mirai motorola

Intelligence


File Origin
# of uploads :
1
# of downloads :
111
Origin country :
FR FR
Vendor Threat Intelligence
Detection(s):
Sanesecurity.Malware.29325.LC.Pl.UNOFFICIAL
SecuriteInfo.com.Linux.Mirai-81.UNOFFICIAL
Sanesecurity.Malware.28886.LC.UNOFFICIAL
Sanesecurity.Malware.29524.LC.UNOFFICIAL
Sanesecurity.Malware.28878.LC.UNOFFICIAL
Sanesecurity.Malware.28877.LC.UNOFFICIAL
Unix.Trojan.Mirai-6981989-0
Unix.Trojan.Mirai-7100807-0
Unix.Dropper.Mirai-7135868-0
Unix.Dropper.Mirai-7135891-0
Unix.Dropper.Mirai-7135892-0
Unix.Dropper.Mirai-7136013-0
Unix.Dropper.Mirai-7136034-0
Unix.Dropper.Mirai-7136057-0
Unix.Dropper.Mirai-7540663-0
Unix.Trojan.Gafgyt-7782058-0
Unix.Trojan.Mirai-8025795-0
Unix.Trojan.Mirai-9441505-0
Unix.Trojan.Mirai-9858729-0
Unix.Trojan.Mirai-9940650-0
Unix.Trojan.Mirai-9945193-0
Unix.Trojan.Mirai-9946826-0
Unix.Dropper.Mirai-9977145-0
Unix.Dropper.Mirai-10008433-0
Unix.Trojan.Mirai-10011027-0
Unix.Trojan.Mirai-10011918-0
Unix.Packed.Botnet-6566031-0
Unix.Dropper.Botnet-6566040-0
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug botnet lolbin mirai obfuscated remote
Result
Verdict:
MALICIOUS
Result
Threat name:
Mirai, Moobot
Detection:
malicious
Classification:
troj
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Yara detected Mirai
Yara detected Moobot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1366626 Sample: KmvhN8br0q.elf Startdate: 24/12/2023 Architecture: LINUX Score: 100 37 197.190.198.152, 37215 zain-asGH Ghana 2->37 39 197.152.252.88 airtel-tz-asTZ Tanzania United Republic of 2->39 41 98 other IPs or domains 2->41 43 Snort IDS alert for network traffic 2->43 45 Malicious sample detected (through community Yara rule) 2->45 47 Antivirus / Scanner detection for submitted sample 2->47 49 4 other signatures 2->49 9 KmvhN8br0q.elf 2->9         started        signatures3 process4 process5 11 KmvhN8br0q.elf 9->11         started        13 KmvhN8br0q.elf sh 9->13         started        process6 15 KmvhN8br0q.elf 11->15         started        17 KmvhN8br0q.elf 11->17         started        19 KmvhN8br0q.elf 11->19         started        21 sh rm 13->21         started        23 sh mkdir 13->23         started        25 sh mv 13->25         started        27 sh chmod 13->27         started        process7 29 KmvhN8br0q.elf 15->29         started        31 KmvhN8br0q.elf 15->31         started        33 KmvhN8br0q.elf 15->33         started        35 1181 other processes 15->35
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2023-12-24 03:26:35 UTC
File Type:
ELF32 Big (Exe)
AV detection:
19 of 37 (51.35%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:mirai linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf ff83788996f4b60c59075e202827a6bf2345cb0dea1d95a3634899ea7f883f45

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2023-12-24 07:37:20 UTC

url : hxxp://37.44.238.75/mont/.nekoisdaddy.m68k