MALICIOUS — a50bf46e0597f7aae092e4d87e6945a22ebd462bbb00d90bf37734bb27e32c73
MALICIOUS — a50bf46e0597f7aae092e4d87e6945a22ebd462bbb00d90bf37734bb27e32c73 is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (90/100), attributed to the Mirai family. 4 of 56 detection engines flagged it.
Identification
- SHA-256:
a50bf46e0597f7aae092e4d87e6945a22ebd462bbb00d90bf37734bb27e32c73 - SHA-1:
3c9f5fbb3ed0eceaf0956bd0cccc5f670fffba37 - MD5:
1920949a18314c0c985f3a431b87dd05 - ssdeep:
1536:VzjLfUzwQxOT/cJMhW65JKj9jdGfB1joJtZE6jWlmeJKbUt31sKOutiyTsr:VzfIxEcY5JKj9xezjo3ZEeWlmAqkw - TLSH:
T1FA3A3A694164A357F6D0E1B8E8695EDE804FD0C4A3B60FFCC243824C73D54839AB999B - Submitted as: a50bf46e0597f7aae092e4d87e6945a22ebd462bbb00d90bf37734bb27e32c73
- File type: elf · Size: 95036 bytes
- Verdict: malicious (90/100) · Family: Mirai
Detections (4 of 56 engines)
- ClamAV (daily): Unix.Trojan.Mirai-7135937-0
- Microsoft Defender: Backdoor:Linux/Mirai.AL!MTB
- Emsisoft (Emergency Kit): Trojan.Linux.Generic.222699
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.dx
Why this verdict
The malicious score of 90/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-7135937-0 (rule
Unix.Trojan.Mirai-7135937-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: 107.174.241.209 - static signal, weight 0.35, confidence 0.60
- Contacted 323 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (1 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
827 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- ntp.ubuntu.com
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- 107.174.241.209:60420 US · Seattle · AS36352 RackNerd LLC
- ff02::1:3
- 224.0.0.252
- 23.11.37.157
- 107.174.241.209 US · Seattle · AS36352 RackNerd LLC
- 112.148.100.90 KR · AS17858 IP Manager
- 136.109.101.90
- 161.6.29.83
- 113.74.126.115 CN · AS4134 Chinanet Hostmaster
- 91.240.220.93
- 94.162.184.124
- 129.5.197.205
- 84.171.202.141
Embedded IP addresses
- 107.174.241.209
- 112.148.100.90
- 136.109.101.90
- 161.6.29.83
- 113.74.126.115
- 91.240.220.93
- 94.162.184.124
- 129.5.197.205
- 84.171.202.141
- 114.6.227.74
- 92.123.52.11
- 85.252.4.28
- 171.55.92.233
- 47.81.200.237
- 133.51.140.111
- 69.29.198.47
- 195.243.21.217
- 83.189.114.180
- 64.53.51.118
- 72.235.128.104
- 122.71.59.126
- 102.224.74.160
- 37.246.135.253
- 122.109.239.228
- 203.248.7.57
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report