MALICIOUS — 086745aabc5602cdcf25bc78852cec41fd059c98fbc021ff8e80b73602e20f65.elf
MALICIOUS — 086745aabc5602cdcf25bc78852cec41fd059c98fbc021ff8e80b73602e20f65.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Mirai family. 4 of 56 detection engines flagged it.
Identification
- SHA-256:
086745aabc5602cdcf25bc78852cec41fd059c98fbc021ff8e80b73602e20f65 - SHA-1:
10baa3019c6a71143904b98feacdc50618e9fb79 - MD5:
e8a49303c543bb74c6ae2eb536b7be3c - ssdeep:
1536:cEBD698TW4NzZbDd+Jo6XURI/rQKydSwalVDGRMZdojA2keJ+uCD5cYVnQo3a6Fw:RR6y3dIo2QKyE7L7ojlA5cYVnQodc - TLSH:
T15142D857B3722844D9B9701622168DCD67D22689AFBC587B0312192E20E7D0F1F3EE97 - Submitted as: 086745aabc5602cdcf25bc78852cec41fd059c98fbc021ff8e80b73602e20f65.elf
- File type: elf · Size: 207520 bytes
- Verdict: malicious (95/100) · Family: Mirai
Source: MalwareBazaar · first seen 2026-08-03T00:00:00.000Z · SHA-256 verified
Detections (4 of 56 engines)
- ClamAV (daily): Unix.Trojan.Mirai-7759336-0
- Microsoft Defender: Backdoor:Linux/Gafgyt.BA!xp
- Emsisoft (Emergency Kit): Gen:Variant.Linux.DDoS.2
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.gen
Why this verdict
The malicious score of 95/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-7759336-0 (rule
Unix.Trojan.Mirai-7759336-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. injected region in -sh (pid 676) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Embedded network infrastructure: 192.0.0.64 - static signal, weight 0.35, confidence 0.60
- Contacted 990 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
941 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- 193.46.218.20:25991
- 127.243.203.180
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 193.46.218.20
- 67.173.94.9
- 201.156.160.113
- 69.20.224.27
- 103.59.92.81 ID · AS150492 ID-NIC ADMINISTRATORS
- 63.200.24.50
- 69.55.237.152
Dropped files
- tmp_.stc -
086745aabc5602cdcf25bc78852cec41fd059c98fbc021ff8e80b73602e20f65
Embedded domains
- netween.co.kr
- domain.name
- twget.sh
- tftp.sh
- ftp.sh
Embedded IP addresses
- 192.0.0.64
- 193.46.218.20
- 67.173.94.9
- 201.156.160.113
- 69.20.224.27
- 103.59.92.81
- 63.200.24.50
- 69.55.237.152
- 175.190.18.138
- 119.128.209.73
- 139.164.124.70
- 190.138.150.7
- 153.103.171.254
- 120.128.89.148
- 155.89.162.234
- 218.120.13.220
- 140.204.133.232
- 27.70.154.160
- 92.225.15.187
- 60.163.83.48
- 99.253.223.101
- 195.4.50.41
- 175.178.116.254
- 122.236.95.171
- 27.45.182.177
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report