MALICIOUS — e7bafa13cd6341c27abd8e34f0825503fb36a5ba40d402382b6a40f160cf01cb.elf
MALICIOUS — e7bafa13cd6341c27abd8e34f0825503fb36a5ba40d402382b6a40f160cf01cb.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Mirai family. 4 of 56 detection engines flagged it.
Identification
- SHA-256:
e7bafa13cd6341c27abd8e34f0825503fb36a5ba40d402382b6a40f160cf01cb - SHA-1:
f49b2d4361a4e6166ed4d35625cbe28bc1b54a33 - MD5:
55ee253f78a89c28060c1f910f39907e - ssdeep:
1536:nJxSUCuRy82KFEFfkLaxQ+tBPznN95YYsP08tu8/1e:JIwaFcL2DDNPVSe - TLSH:
T1E738395E487E87B4E7C4425E61085F7CE6BAA81906FBEC7F829086FAD0956F71431203 - Submitted as: e7bafa13cd6341c27abd8e34f0825503fb36a5ba40d402382b6a40f160cf01cb.elf
- File type: elf · Size: 78952 bytes
- Verdict: malicious (93/100) · Family: Mirai
Detections (4 of 56 engines)
- ClamAV (daily): Unix.Trojan.Mirai-9858729-0
- Microsoft Defender: Backdoor:Linux/Mirai.FS!MTB
- Emsisoft (Emergency Kit): Trojan.Linux.Mirai.39487111
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.b
Why this verdict
The malicious score of 93/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-9858729-0 (rule
Unix.Trojan.Mirai-9858729-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 2 finding(s), e.g. injected region in 44pu4w73aht7cqd (pid 681) (rule
linux.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Contacted 13 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
867 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- 250.255.255.239.in-addr.arpa
- desktop-hsgcbep._dosvc._tcp.local
- _dosvc._tcp.local
- ntp.ubuntu.com
- desktop-hsgcbep
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 94.154.43.115:18129 GB · London · AS208485 SUNUCUN BILGI ILETSIM TEKNOLOJILERI VE TICARET LIMITED SIRKETI
- 94.154.43.115 GB · London · AS208485 SUNUCUN BILGI ILETSIM TEKNOLOJILERI VE TICARET LIMITED SIRKETI
- ff02::1:3
- 224.0.0.252
- 224.0.0.251
- ff02::fb
- 203.26.79.13 NZ · Auckland · AS24305 EdgeIX Pty Ltd
- 74.179.77.204 US · Moses Lake · AS8075 Microsoft Corporation
- 10.240.0.1
- 10.240.0.255
- ff02::16
Embedded IP addresses
- 94.154.43.115
- 203.26.79.13
- 74.179.77.204
- 40.79.167.9
- 52.168.117.171
- 72.153.5.134
- 135.232.92.34
- 172.172.255.217
- 172.172.255.216
- 20.184.175.21
- 48.211.4.16
- 4.150.223.112
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report