MALICIOUS — 23c64cd813bcb30a7bfbc1de4fe45d33af171132632a08b7f3d884af627ee1a7
MALICIOUS — 23c64cd813bcb30a7bfbc1de4fe45d33af171132632a08b7f3d884af627ee1a7 is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Mirai family. 7 of 57 detection engines flagged it.
Identification
- SHA-256:
23c64cd813bcb30a7bfbc1de4fe45d33af171132632a08b7f3d884af627ee1a7 - SHA-1:
0e45d9c62c32ce218be5b33c306ef8577c23187f - MD5:
76c23a717c1e7c2a3b570febbfed9cb5 - ssdeep:
3072:phNlHuBafLeBtfCzpta8xlBIOdVo3/4sxLJ10xioYa5POdOQ33Q:p3lOYoaja8xzx/0wsxzSiAPqOJ - TLSH:
T1884602D2687BAC51CED8550041A20DFFECDB991F307ACC8D01460ABA656D7B3047EAE9 - Submitted as: 23c64cd813bcb30a7bfbc1de4fe45d33af171132632a08b7f3d884af627ee1a7
- File type: elf · Size: 299040 bytes
- Verdict: malicious (100/100) · Family: Mirai
Detections (7 of 57 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX 3.95
- ClamAV (daily): Unix.Trojan.Mirai-7100807-0
- YARA: Intezer community: INTEZER_ELF_UPX_Modified
- Detect It Easy (packer/type): DIE:UPX 3.95
- Microsoft Defender: Trojan:Linux/Dakkatoni.A!MTB
- Emsisoft (Emergency Kit): Linux.Mozi.P
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.r
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-7100807-0 (rule
Unix.Trojan.Mirai-7100807-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 7 finding(s) attributed to the sample across 1 technique(s), e.g. injected region in dropbear (pid 682) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Trojan:Linux/Dakkatoni.A!MTB (rule
Trojan:Linux/Dakkatoni.A!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Linux.Mozi.P (rule
Linux.Mozi.P) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Backdoor.Linux.Mirai.r (rule
HEUR:Backdoor.Linux.Mirai.r) - engine signal, weight 0.55, confidence 0.85 - YARA: Intezer community flagged INTEZER_ELF_UPX_Modified (rule
INTEZER_ELF_UPX_Modified) - engine signal, weight 0.40, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX 3.95 (rule
DIE:UPX 3.95) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX 3.95 (rule
UPX 3.95) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.sf.net, http://purenetworks.com/HNAP1/ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX 3.95 - static signal, weight 0.25, confidence 0.55
- Contacted 2106 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (2 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
2079 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- desktop-hsgcbep
- dht.transmissionbt.com
- router.bittorrent.com
- ntp.ubuntu.com
- router.utorrent.com
- bttracker.debian.org
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 131.192.59.96:49152
- 139.113.201.211:8080
- 157.99.131.224:8081
- 82.152.171.104:37215
- 19.167.159.37:80
- 209.129.108.206:52869
- 54.73.38.80:8080
- 219.241.142.24:8081
- 76.213.102.4:8080
- 60.38.85.9:80
Dropped files
- tmp_.config -
74c9b3a712c3e883f3d0181d64bb83d4aa02f1619615f4f584441e4ae4de0936 - tmp_.ips -
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
Embedded URLs
- http://upx.sf.net
- http://schemas.xmlsoap.org/soap/envelope/
- http://schemas.xmlsoap.org/soap/encoding/
- http://schemas.xmlsoap.org/soap/envelope//
- http://purenetworks.com/HNAP1/
- http://www.w3.org/2001/XMLSchema-instance
- http://www.w3.org/2001/XMLSchema
Embedded domains
- upx.sf.net
- bin.sh
- bix.sh
- schemas.xmlsoap.org
- purenetworks.com
- www.w3.org
- dht.transmissionbt.com
- router.bittorrent.com
- router.utorrent.com
Embedded IP addresses
- 239.255.255.250
- 192.168.0.100
- 192.168.1.1
- 192.168.3.1
- 18.157.220.20
- 92.135.11.235
- 110.227.249.22
- 102.132.18.9
- 191.189.109.19
- 192.241.199.75
- 96.168.141.62
- 102.216.86.139
- 85.164.9.235
- 19.39.234.222
- 112.168.9.81
- 162.39.56.228
- 57.118.38.174
- 1.92.185.187
- 206.57.15.83
- 162.32.113.116
- 163.200.140.59
- 16.6.232.47
- 52.103.71.126
- 178.11.199.117
- 128.73.0.174
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report