MALICIOUS — fde134790d4e436c56fe85dc3ef2532fa47f58cc151e4bd3b480e811d799ba63.bin
MALICIOUS — fde134790d4e436c56fe85dc3ef2532fa47f58cc151e4bd3b480e811d799ba63.bin is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Mirai family. 3 of 56 detection engines flagged it.
Identification
- SHA-256:
fde134790d4e436c56fe85dc3ef2532fa47f58cc151e4bd3b480e811d799ba63 - SHA-1:
ed0e6849b8fbaaafb5ab95d23ca7792c5fe898b2 - MD5:
0517aaccc22e828704d0707e786896be - ssdeep:
3072:pJNBiBPFv/itTw1AYnB3xCqaBfv51+DGEkhFyxRQVrZt9uQlssMab/BlGH+Iys6:pJNBIMtTw1AA19Ge+5LZlssM7khWo7 - TLSH:
T175439E5A034A765FD3E1CD49B8056CBC945330D6907178CD830AD90EA18DE37EEAA1FA - Submitted as: fde134790d4e436c56fe85dc3ef2532fa47f58cc151e4bd3b480e811d799ba63.bin
- File type: elf · Size: 224488 bytes
- Verdict: malicious (89/100) · Family: Mirai
Source: MalShare · first seen 2026-08-17T04:21:05.902Z · SHA-256 verified
Detections (3 of 56 engines)
- ClamAV (daily): Unix.Dropper.Mirai-7540662-0
- Emsisoft (Emergency Kit): Trojan.Generic.40417838
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.cw
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Unix.Dropper.Mirai-7540662-0 (rule
Unix.Dropper.Mirai-7540662-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://purenetworks.com/HNAP1/, 198.144.179.82 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (linux)
940 behavior events · 0 ATT&CK techniques · 2 dropped files.
Runtime network
- ntp.ubuntu.com
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 1.0.240.10.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- 255.255.254.169.in-addr.arpa
- 79.243.254.169.in-addr.arpa
- 198.144.179.82:55650 US · Elk Grove Village · AS36352 HostPapa
- 122.142.219.72
- 126.30.100.18
- 90.44.88.145
- 38.68.99.53
- 236.254.32.72
- 255.162.114.15
- 70.221.162.90
- 135.9.51.219
- 150.67.144.62
Dropped files
- var_tmp_.ba4dff -
fde134790d4e436c56fe85dc3ef2532fa47f58cc151e4bd3b480e811d799ba63 - var_tmp_.ba4dff.lck -
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
Embedded URLs
- http://purenetworks.com/HNAP1/
- http://www.w3.org/2001/XMLSchema-instance
- http://www.w3.org/2001/XMLSchema
- http://schemas.xmlsoap.org/soap/envelope/
- http://schemas.xmlsoap.org/soap/encoding/
Embedded domains
- purenetworks.com
- www.w3.org
- schemas.xmlsoap.org
- 1.sh
Embedded IP addresses
- 239.255.255.250
- 192.168.0.100
- 198.144.179.82
- 122.142.219.72
- 126.30.100.18
- 90.44.88.145
- 38.68.99.53
- 70.221.162.90
- 135.9.51.219
- 150.67.144.62
- 143.93.235.135
- 210.131.255.2
- 96.140.233.147
- 2.65.116.107
- 108.220.16.147
- 21.123.213.156
- 47.98.84.112
- 120.176.167.89
- 82.109.254.124
- 126.251.74.136
- 163.24.192.126
- 192.152.193.36
- 171.129.203.78
- 159.185.234.126
- 7.15.44.138
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report