MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ff9570ad8d6ae41af2b4a7613c358ba4b034aebcb444114e2407c4cdfe7240c5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: ff9570ad8d6ae41af2b4a7613c358ba4b034aebcb444114e2407c4cdfe7240c5
SHA3-384 hash: 916cf69a2dca752e7cbfb6ced17d67ab426df4b32c3301f5143ad70c741faff239535505ade109c341137faacf337df7
SHA1 hash: 70af28991bb8cc774421b51629733ef3c86f703f
MD5 hash: 638733c4f791146ff372cb3fe883e7ba
humanhash: pennsylvania-oranges-echo-cat
File name:riscv32
Download: download sample
Signature Mirai
File size:82'800 bytes
First seen:2024-10-17 14:03:10 UTC
Last seen:2024-10-17 14:41:56 UTC
File type: elf
MIME type:application/x-executable
ssdeep 1536:tVRXJNQhO338/pnRlAemlDXQVOGn9az5R0OlutJFptG4m4+hwZtrXTP:tVRv1ELAXXQVOS9Alwd24+Kt/
TLSH T146836D04DC374B20D1E603F05FA98B43A9D03B6A26D76B44C74CB639FA5D4E5A1C1EAE
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
97
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
android anti-debug mirai
Result
Verdict:
MALICIOUS
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.evad
Score:
48 / 100
Signature
Opens /sys/class/net/* files useful for querying network interface information
Sample deletes itself
Behaviour
Behavior Graph:
behaviorgraph top1 process2 2 Behavior Graph ID: 1536120 Sample: riscv32.elf Startdate: 17/10/2024 Architecture: LINUX Score: 48 6 riscv32.elf 2->6         started        9 systemd snap-failure 2->9         started        signatures3 20 Sample deletes itself 6->20 11 riscv32.elf 6->11         started        14 snap-failure systemctl 9->14         started        16 snap-failure 9->16         started        process4 signatures5 22 Opens /sys/class/net/* files useful for querying network interface information 11->22 18 riscv32.elf 11->18         started        process6
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2024-10-09 08:04:11 UTC
File Type:
ELF32 Little (Exe)
AV detection:
4 of 38 (10.53%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf ff9570ad8d6ae41af2b4a7613c358ba4b034aebcb444114e2407c4cdfe7240c5

(this sample)

  
Delivery method
Distributed via web download

Comments