MALICIOUS — 3e9feb9723dedeec05d2aeef59c49d2a97c3eb4018c1d008ea8ae8644d045a56
MALICIOUS — 3e9feb9723dedeec05d2aeef59c49d2a97c3eb4018c1d008ea8ae8644d045a56 is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Mirai family. 3 of 57 detection engines flagged it.
Identification
- SHA-256:
3e9feb9723dedeec05d2aeef59c49d2a97c3eb4018c1d008ea8ae8644d045a56 - SHA-1:
9d165133c072a2ed586968be277717e74d7df246 - MD5:
db06f25570801c47a03b81b58ad60f18 - ssdeep:
768:j1diP8oCXjI0ATLg+D8/RnuE2zLN1mRdvJ3Ik0CO29A2I+Cqq8E:RQIMdv9D8pHKLaTK2B - TLSH:
T10F354AD54157B402E7F0FE026416ACFD64B7B53A203A949C821E951EF2ED2738D702AE - Submitted as: 3e9feb9723dedeec05d2aeef59c49d2a97c3eb4018c1d008ea8ae8644d045a56
- File type: elf · Size: 59168 bytes
- Verdict: malicious (97/100) · Family: Mirai
Detections (3 of 57 engines)
- ClamAV (daily): Unix.Trojan.Mirai-7640640-0
- Microsoft Defender: Backdoor:Linux/Gafgyt.AW!xp
- Emsisoft (Emergency Kit): Gen:Variant.Linux.DDoS.2
Why this verdict
The malicious score of 97/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-7640640-0 (rule
Unix.Trojan.Mirai-7640640-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:Linux/Gafgyt.AW!xp (rule
Backdoor:Linux/Gafgyt.AW!xp) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Linux.DDoS.2 (rule
Gen:Variant.Linux.DDoS.2) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://www.youtube.ru/watch?v=OGp9P6QvMjY, 199.195.248.54 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
845 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- ntp.ubuntu.com
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ff02::1:3
- 10.240.0.1
- 224.0.0.252
- 10.240.0.255
- ff02::fb
- 224.0.0.251
- 142.250.4.84
- 172.178.240.163 US · San Jose · AS8075 Microsoft Limited
- 57.154.63.210 US · Phoenix · AS8075 Microsoft Limited UK
- 185.125.190.57
- ff02::16
- ff02::1:ff4c:1d1d
- ff02::1:ff12:3456
- ff02::1
Embedded URLs
- https://www.youtube.ru/watch?v=OGp9P6QvMjY
Embedded domains
- www.youtube.ru
Embedded IP addresses
- 239.255.255.250
- 199.195.248.54
- 172.178.240.163
- 57.154.63.210
- 20.42.73.25
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report