MALICIOUS — 992132cce0a25055e5d6edc69fa4ef834e6b867a9eb156dfd76757fdaa528b08.elf
MALICIOUS — 992132cce0a25055e5d6edc69fa4ef834e6b867a9eb156dfd76757fdaa528b08.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Mirai family. 4 of 56 detection engines flagged it.
Identification
- SHA-256:
992132cce0a25055e5d6edc69fa4ef834e6b867a9eb156dfd76757fdaa528b08 - SHA-1:
bf60d9f7385ea861679288b4010d45cd0ab7c36a - MD5:
d53fa689a88061e8a274c95a7494d757 - ssdeep:
3072:oe8lFShubUaW9Ew4Thsy6zWRO5EZ7Jd6hh1Pf:oe8GsYjGw49sy6yA5EZNAf - TLSH:
T102403B11BA7A2465F8358AD88C84483D01CE065C4E2CDFF98FCAAEE3481EB575DB14E5 - Submitted as: 992132cce0a25055e5d6edc69fa4ef834e6b867a9eb156dfd76757fdaa528b08.elf
- File type: elf · Size: 167512 bytes
- Verdict: malicious (89/100) · Family: Mirai
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (4 of 56 engines)
- ClamAV (daily): Unix.Dropper.Mirai-7136013-0
- Microsoft Defender: Backdoor:Linux/Mirai.AW!xp
- Emsisoft (Emergency Kit): Trojan.Generic.40357159
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.cw
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Unix.Dropper.Mirai-7136013-0 (rule
Unix.Dropper.Mirai-7136013-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://www.bing.com, https://www.yahoo.com, https://www.facebook.com - static signal, weight 0.35, confidence 0.60
Dynamic analysis
This sample is built for ARM, which no sandbox guest in our fleet executes, so it was not detonated. The absence of runtime behaviour here is a coverage gap on our side, not a finding about the sample.
Embedded URLs
- https://www.google.com
- https://www.bing.com
- https://www.yahoo.com
- https://www.facebook.com
- https://www.twitter.com
- https://www.linkedin.com
- https://www.reddit.com
- https://www.youtube.com
- https://www.amazon.com
- https://www.netflix.com
- https://www.google.com/
- https://www.bing.com/
- https://www.yahoo.com/
- https://www.facebook.com/
- https://www.twitter.com/
- https://www.linkedin.com/
- https://www.reddit.com/
- https://www.youtube.com/
- https://www.amazon.com/
- https://www.netflix.com/
Embedded domains
- www.google.com
- www.bing.com
- www.yahoo.com
- www.facebook.com
- www.twitter.com
- www.linkedin.com
- www.reddit.com
- www.youtube.com
- www.amazon.com
- www.netflix.com
Embedded IP addresses
- 192.168.1.1
- 10.0.0.1
- 172.16.0.1
- 203.0.113.1
- 31.77.227.111
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report