MALICIOUS — d45d025d4fc1bb11f1e88011b1da13cb894688967cb3bf9b1843dd5e18378f84
MALICIOUS — d45d025d4fc1bb11f1e88011b1da13cb894688967cb3bf9b1843dd5e18378f84 is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mirai family. 5 of 57 detection engines flagged it.
Identification
- SHA-256:
d45d025d4fc1bb11f1e88011b1da13cb894688967cb3bf9b1843dd5e18378f84 - SHA-1:
6aad0461e4ed6ce92fc6ab883b31ae095fc441bd - MD5:
dfd7772a081ffa5c17edf1cf5d6e8e1e - ssdeep:
6144:T2s/gAWuboqsJ9xcJxspJBqQgTuaJZRhVabE5wKSDP99zBa77oNsKqqfPqOJ:T2s/bW+UmJqBxAuaPRhVabEDSDP99zB - TLSH:
T17D465D15AF6E589BF83846D58CE0497C03CE11AC8E28DEDC4B8E5EB308596A31E741F5 - Submitted as: d45d025d4fc1bb11f1e88011b1da13cb894688967cb3bf9b1843dd5e18378f84
- File type: elf · Size: 291088 bytes
- Verdict: malicious (99/100) · Family: Mirai
Detections (5 of 57 engines)
- ClamAV (daily): Unix.Trojan.Mirai-7100807-0
- YARA: Stratosphere IPS: STRATO_Mirai_Botnet
- Microsoft Defender: Backdoor:Linux/Mirai.I!xp
- Emsisoft (Emergency Kit): Trojan.Linux.Mozi.21
- Kaspersky (KVRT): HEUR:Trojan.Linux.Agent.nx
Why this verdict
The malicious score of 99/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-7100807-0 (rule
Unix.Trojan.Mirai-7100807-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Stratosphere IPS flagged STRATO_Mirai_Botnet (rule
STRATO_Mirai_Botnet) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged Backdoor:Linux/Mirai.I!xp (rule
Backdoor:Linux/Mirai.I!xp) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Linux.Mozi.21 (rule
Trojan.Linux.Mozi.21) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Linux.Agent.nx (rule
HEUR:Trojan.Linux.Agent.nx) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: http://ipinfo.io/ip, http://127.0.0.1, http://purenetworks.com/HNAP1/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
872 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- desktop-hsgcbep
- ntp.ubuntu.com
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- _dosvc._tcp.local
- ff02::1:3
- 224.0.0.252
- 10.240.0.255
- 10.240.0.1
- 224.0.0.251
- ff02::fb
- 52.123.252.203 AU · Sydney · AS8075 Microsoft Corporation
- 185.125.190.57
- 4.150.223.102 US · Des Moines · AS8075 Microsoft Corporation
- ff02::1
- ff02::1:2
- 4.247.188.233 IN · Pune · AS8075 Microsoft Corporation
- 255.255.255.255
Embedded URLs
- http://ipinfo.io/ip
- http://127.0.0.1
- http://schemas.xmlsoap.org/soap/envelope/
- http://schemas.xmlsoap.org/soap/encoding/
- http://schemas.xmlsoap.org/soap/envelope//
- http://purenetworks.com/HNAP1/
- http://www.w3.org/2001/XMLSchema-instance
- http://www.w3.org/2001/XMLSchema
Embedded domains
- baidu.com
- ipinfo.io
- wifi.sh
- dht.transmissionbt.com
- router.bittorrent.com
- router.utorrent.com
- bttracker.debian.org
- bin.sh
- bix.sh
- schemas.xmlsoap.org
- purenetworks.com
- www.w3.org
Embedded IP addresses
- 8.8.8.8
- 114.114.114.114
- 212.129.33.59
- 82.221.103.244
- 130.239.18.159
- 87.98.162.88
- 239.255.255.250
- 192.168.0.100
- 52.123.252.203
- 4.150.223.102
- 4.247.188.233
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report