MALICIOUS — 52e0c4974427db87b915d5b81785e6a9a014f5626e7adefee0c4a9710edd626d.elf
MALICIOUS — 52e0c4974427db87b915d5b81785e6a9a014f5626e7adefee0c4a9710edd626d.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (90/100), attributed to the Mirai family. 5 of 56 detection engines flagged it.
Identification
- SHA-256:
52e0c4974427db87b915d5b81785e6a9a014f5626e7adefee0c4a9710edd626d - SHA-1:
86953bc702ec75bd0c8d0ea32dd21911015155e9 - MD5:
bd87c85a06a65791729a8238a8f7a268 - ssdeep:
1536:rMmRqozBnO115B3k7myNqhwN+bYTMIqWBtlgALf5SZ+ZwLjh:wmDg3U7myNq+N+biL5tXD5+Ljh - TLSH:
T1FF3A5A2A426697CFF3C0F1B4E16C6E9C441AB4C961B68FDC8116424D77E5493F8AA0A3 - Submitted as: 52e0c4974427db87b915d5b81785e6a9a014f5626e7adefee0c4a9710edd626d.elf
- File type: elf · Size: 100564 bytes
- Verdict: malicious (90/100) · Family: Mirai
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (5 of 56 engines)
- ClamAV (daily): Unix.Trojan.Mirai-7100807-0
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
- Microsoft Defender: Backdoor:Linux/Mirai.AU!MTB
- Emsisoft (Emergency Kit): Trojan.Linux.Mirai.1
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.cw
Why this verdict
The malicious score of 90/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-7100807-0 (rule
Unix.Trojan.Mirai-7100807-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.35, confidence 0.70 - Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
877 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ntp.ubuntu.com
- wqok85qtq.net
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep
- 31.56.209.153:69
- 41.216.189.108:80
- ff02::1:3
- 224.0.0.252
- 31.56.209.153
- 41.216.189.108
- 10.240.0.1
- 8.8.8.8
- 224.0.0.251
- ff02::fb
- 10.240.0.255
- ff02::16
Embedded domains
- wqok85qtq.net
Embedded IP addresses
- 31.56.209.153
- 41.216.189.108
- 74.179.77.204
- 74.178.76.44
- 20.42.65.85
- 72.145.35.112
- 4.150.223.115
- 74.178.240.61
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report