MALICIOUS — 04fc92d37968f2d09f65c6cfd74a39052d504d239c357e5f6612e207b80cfd21.elf
MALICIOUS — 04fc92d37968f2d09f65c6cfd74a39052d504d239c357e5f6612e207b80cfd21.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Mirai family. 4 of 56 detection engines flagged it.
Identification
- SHA-256:
04fc92d37968f2d09f65c6cfd74a39052d504d239c357e5f6612e207b80cfd21 - SHA-1:
687cbee14180c428503085e1cf3f55ec64e4e194 - MD5:
6fcfd32e4707781648b15a07568c1197 - ssdeep:
1536:GyY5PRqZv1F6Wu6UvWaRvVnFvNLjCuorywgnY8V2FvwRP/mr+zlSTU0:Gy6W0WaR/1L8rlgnN2FAuC8Tv - TLSH:
T1993928256A6C2499F03486D98C94093C12CE065D8D5CDFE88F9F6EE3491EFA35EB00E5 - Submitted as: 04fc92d37968f2d09f65c6cfd74a39052d504d239c357e5f6612e207b80cfd21.elf
- File type: elf · Size: 91732 bytes
- Verdict: malicious (95/100) · Family: Mirai
Detections (4 of 56 engines)
- ClamAV (daily): Unix.Dropper.Mirai-7135890-0
- Microsoft Defender: Backdoor:Linux/Mirai.FO!MTB
- Emsisoft (Emergency Kit): Trojan.Generic.40362670
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.cw
Why this verdict
The malicious score of 95/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Unix.Dropper.Mirai-7135890-0 (rule
Unix.Dropper.Mirai-7135890-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 1 finding(s), e.g. injected region in LqDAxwYStMnlSCk (pid 738) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Embedded network infrastructure: 204.10.194.60 - static signal, weight 0.35, confidence 0.60
- Contacted 4 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
951 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- desktop-hsgcbep._dosvc._tcp.local
- ntp.ubuntu.com
- desktop-hsgcbep
- 204.10.194.60:1999 CA · AS206216 Advin Services LLC
- 127.243.200.116
- 0.2.155.92
- 224.0.0.251
- ff02::fb
- 204.10.194.60 CA · AS206216 Advin Services LLC
- 10.240.0.1
- 23.221.133.123
- 23.221.133.182
- ff02::1:3
- 224.0.0.252
- ff02::16
- 10.240.0.255
- 20.190.142.163
- 10.240.0.77
- ff02::1
- ff02::1:ff4c:1d1d
Embedded IP addresses
- 204.10.194.60
- 20.42.73.24
- 203.26.79.13
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report