MALICIOUS — Linux.Mirai.B.elf
MALICIOUS — Linux.Mirai.B.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Mirai family. 2 of 50 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
f60b29cfb7eab3aeb391f46e94d4d8efadde5498583a2f5c71bd8212d8ae92da - SHA-1:
9b8523cbf0f3af49dbb1680d53c8fc9b2782bcfc - MD5:
9a6e4b8a6ba5b4f5a408919d2c169d92 - ssdeep:
6144:XkYUAmEjloym0V80hkRocENCP0RnYtGSoBmb4d3PCBElKb/0FaiFsXWxATqtEvcM:XkYUAmEjloym0V80hkRo/NCP0RnYtGSj - TLSH:
T1A7455A3B1D646956F4B9CAC5D8E4C63C0FCF051E4C36DA8C8A8B467308195BBC9B12AD - Submitted as: Linux.Mirai.B.elf
- File type: elf · Size: 283000 bytes
- Verdict: malicious (99/100) · Family: Mirai
Detections (2 of 50 engines)
- ClamAV (daily): Unix.Trojan.Mirai-6987932-0
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Unix.Trojan.Mirai-6987932-0 (rule
Unix.Trojan.Mirai-6987932-0) - engine signal, weight 0.90, confidence 0.95 - 1 behavioral detection(s): Download-and-execute dropper (wget/curl + chmod) [high] (rule
tl-linux-download-exec) - dynamic signal, weight 0.60, confidence 0.90 - 1 behavioral detection(s): Download-and-execute dropper (wget/curl + chmod) [high] (rule
tl-linux-download-exec) - dynamic signal, weight 0.60, confidence 0.90 - YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://79.124.8.24/fetch.sh;/bin/busybox+chmod+777+fetch.sh;./fetch.sh, http://79.124.8.24/fetch.sh, http://79.124.8.24/fetch.sh+sh+fetch.sh+rm - static signal, weight 0.35, confidence 0.60
- Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (12 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Extracted generic config (12 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (linux)
881 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- entropy.ubuntu.com
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- _dosvc._tcp.local
- http
- http.local
- 250.255.255.239.in-addr.arpa
- HTTP
- ntp.ubuntu.com
- 185.125.189.53:443
- 127.243.199.68
- 203.26.79.13
- 74.178.240.61
- 10.240.0.1
Dropped files
- tmp_tmp.NDIOHCvrPc -
ada26fe94875baaa286bb1d570a641f379b62fa2a3f5091c022af52f22d987dd
Embedded URLs
- http://79.124.8.24/fetch.sh;/bin/busybox+chmod+777+fetch.sh;./fetch.sh
- http://79.124.8.24/fetch.sh
- http://79.124.8.24/fetch.sh+sh+fetch.sh+rm
- http://79.124.8.24/fetch.sh+chmod+777+fetch.sh+
- http://10.0.0.1/network_diagnostic_tools.php
- http://79.124.8.24/fetch.sh;chmod
- http://79.124.8.24/fetch.sh+chmod+777+fetch.sh+sh+fetch.sh
- http://79.124.8.24/fetch.sh+chmod+777
- http://tplinkwifi.net
- http://79.124.8.24/fetch.sh;sh
- http://79.124.8.24/fetch.sh&chmod&777&fetch.sh&sh&fetch.sh&tools_cmd=1&net_tools_set=1&wlan_idx_num=0
- http://79.124.8.24/fetch.sh;chmod+777
- http://79.124.8.24/fetch.sh+chmod+777+fetch.sh+sh+
- http://192.168.1.254/tr069
- http://79.124.8.24/fetch.sh;chmod+777+fetch.sh;sh
- http://127.0.0.1
- http://79.124.8.24/itooamgay/typpaostur.sh;chmod+777
- http://79.124.8.24/fetch.sh+chmod+777+fetch.sh+sh
- http://79.124.8.24/fetch.sh+chmod+777+fetch.sh+sh+fetch.sh%22
- http://79.124.8.24/fetch.arm7;chmod+777+fetch.arm7;/tmp/fetch.arm7+varcron
- http://schemas.xmlsoap.org/soap/envelope/
- http://schemas.xmlsoap.org/soap/encoding/
- http://79.124.8.24/fetch.mips;/tmp/fetch.mips
- http://79.124.8.24/fetch.sh;chmod+777+fetch.sh;sh+fetch.sh
- http://79.124.8.24/fetch.mips
Embedded domains
- fetch.sh
- www.comcast.net
- 20fetch.sh
- tplinkwifi.net
- 26fetch.sh
- run.sh
- 20shfetch.sh
- typpaostur.sh
- 777fetch.sh
- schemas.xmlsoap.org
- purenetworks.com
- www.w3.org
- iotsecurity.xyz
Embedded IP addresses
- 79.124.8.24
- 10.0.0.1
- 8.8.8.8
- 192.168.1.1
- 192.168.1.254
- 192.168.0.100
- 78.142.18.20
- 203.26.79.13
- 74.178.240.61
- 20.42.179.192
- 51.116.253.168
- 52.168.117.169
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report