MALICIOUS — 9c5d705f07e17a4bf809d384c67630ec197ac11335747e068424067fde56a9d0.elf
MALICIOUS — 9c5d705f07e17a4bf809d384c67630ec197ac11335747e068424067fde56a9d0.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (90/100), attributed to the Mirai family. 5 of 56 detection engines flagged it.
Identification
- SHA-256:
9c5d705f07e17a4bf809d384c67630ec197ac11335747e068424067fde56a9d0 - SHA-1:
d40e19637020b972b09a7fec9acc4beff2e8e364 - MD5:
7d936fab5bf40ac4d251814d723c8fa9 - ssdeep:
3072:7EqQwKemz+S5OCXUBta7ecz2mRsfJCmBD:4qQwKepSM5n3fJCmBD - TLSH:
T1593B385A92246B8FF3C0E6B4E06D5EAC50A634CDA2768EECC101429D73E8447F8E7457 - Submitted as: 9c5d705f07e17a4bf809d384c67630ec197ac11335747e068424067fde56a9d0.elf
- File type: elf · Size: 107796 bytes
- Verdict: malicious (90/100) · Family: Mirai
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (5 of 56 engines)
- ClamAV (daily): Unix.Trojan.Mirai-7100807-0
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
- Microsoft Defender: Backdoor:Linux/Mirai.AU!MTB
- Emsisoft (Emergency Kit): Trojan.Linux.Mirai.1
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.cw
Why this verdict
The malicious score of 90/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-7100807-0 (rule
Unix.Trojan.Mirai-7100807-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.35, confidence 0.70 - Contacted 11 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
927 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- wqok85qtq.net
- desktop-hsgcbep._dosvc._tcp.local
- 255.255.254.169.in-addr.arpa
- 251.0.0.224.in-addr.arpa
- 41.216.189.108:80 DE · Frankfurt am Main · AS211138 Private-Hosting di Cipriano Oscar
- 31.56.209.153:69 GB · London · AS25369 AE-GOLDIP
- 72.154.7.96 US · Moses Lake · AS8075 Microsoft Corporation
- ff02::1:3
- 224.0.0.252
- 150.171.109.66
- 199.232.138.172
- 10.240.0.255
- 31.56.209.153 GB · London · AS25369 AE-GOLDIP
Embedded domains
- wqok85qtq.net
Embedded IP addresses
- 72.154.7.96
- 31.56.209.153
- 41.216.189.108
- 172.172.255.216
- 20.184.175.11
- 4.247.188.224
- 40.84.85.40
- 20.184.175.2
- 135.233.95.80
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report