MALICIOUS — 31cd898fd42a6b1dedbb16f3f0a5639d054222e826428c0eaea3125c1de7cf35.elf
MALICIOUS — 31cd898fd42a6b1dedbb16f3f0a5639d054222e826428c0eaea3125c1de7cf35.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Mirai family. 4 of 57 detection engines flagged it.
Identification
- SHA-256:
31cd898fd42a6b1dedbb16f3f0a5639d054222e826428c0eaea3125c1de7cf35 - SHA-1:
a951df36ab59b6d63cb6774418869793642731e7 - MD5:
43733eb1079a32b1b685d9e050ccbadb - ssdeep:
6144:UN8zKKxc/qZkQ4aGTJmtP2orE8/MCrZHtUdM/R5Oa+:UsKKeqZkQ4aaJmtP2orzUynUm/3Oa+ - TLSH:
T130425B6CAF5474D7E8B8C9C488D4C72C2F8F402C5D39DB8D5ADAA977045A5330A312AE - Submitted as: 31cd898fd42a6b1dedbb16f3f0a5639d054222e826428c0eaea3125c1de7cf35.elf
- File type: elf · Size: 214963 bytes
- Verdict: malicious (98/100) · Family: Mirai
Detections (4 of 57 engines)
- ClamAV (daily): Unix.Trojan.Mirai-9760303-0
- Microsoft Defender: Backdoor:Linux/Gafgyt.AX!xp
- Emsisoft (Emergency Kit): Trojan.Generic.40420762
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Gafgyt.hr
Why this verdict
The malicious score of 98/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-9760303-0 (rule
Unix.Trojan.Mirai-9760303-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:Linux/Gafgyt.AX!xp (rule
Backdoor:Linux/Gafgyt.AX!xp) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Generic.40420762 (rule
Trojan.Generic.40420762) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Backdoor.Linux.Gafgyt.hr (rule
HEUR:Backdoor.Linux.Gafgyt.hr) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: 1.1.1.1 - static signal, weight 0.35, confidence 0.60
- Contacted 12 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Memory forensics: 3 finding(s) elsewhere in the guest, not attributed to this sample, e.g. injected region in /bin/bash (pid 693) (rule
linux.malfind.Malfind) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (linux)
871 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- catddos.pirate
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- desktop-hsgcbep(4)._dosvc._tcp.local
- desktop-hsgcbep(5)._dosvc._tcp.local
- ntp.ubuntu.com
- desktop-hsgcbep(6)._dosvc._tcp.local
- 212.118.43.167:2222 NL · Lelystad · AS216071 SERVERS TECH FZCO
- 127.243.169.220
- 10.240.0.77
- 212.118.43.167 NL · Lelystad · AS216071 SERVERS TECH FZCO
- 195.10.195.195 DE · Frankfurt am Main · AS34549 meerfarbig GmbH & Co. KG
- 224.0.0.251
- ff02::fb
- 10.240.0.1
- 194.36.144.87 DE · Nürnberg · AS197540 netcup GmbH
- 51.254.162.59 FR · AS16276 OVH - OVH SAS, FR
- 74.178.232.29 NL · Amsterdam · AS8075 Microsoft Corporation
Embedded domains
- catddos.pirate
Embedded IP addresses
- 1.1.1.1
- 212.118.43.167
- 195.10.195.195
- 194.36.144.87
- 51.254.162.59
- 74.178.232.29
- 172.178.240.163
- 20.42.179.204
- 57.155.104.224
- 4.207.44.70
- 57.154.63.210
- 74.178.240.61
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report