MALICIOUS — 12ee92d529a704272662846f7752c077141070067246a4a9028309cee67583d0.elf
MALICIOUS — 12ee92d529a704272662846f7752c077141070067246a4a9028309cee67583d0.elf is a elf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Mirai family. 3 of 53 detection engines flagged it.
Identification
- SHA-256:
12ee92d529a704272662846f7752c077141070067246a4a9028309cee67583d0 - SHA-1:
7b5d6035d0927e3d0c1882621a8e7406f7a910d6 - MD5:
fcfdcbde7e0414492d82a7b084cdf7f1 - File type: elf · Size: 141180 bytes
- Verdict: malicious (97/100) · Family: Mirai
Source: MalwareBazaar · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (3 of 53 engines)
- ClamAV (daily): Unix.Trojan.Mirai-10012200-0
- Emsisoft (Emergency Kit): Trojan.Generic.40353885
- Kaspersky (KVRT): HEUR:Backdoor.Linux.Mirai.kl
Dynamic analysis (linux)
843 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- ntp.ubuntu.com
- desktop-hsgcbep
- 10.240.0.1
- ff02::1:3
- 224.0.0.252
- ff02::16
- 169.254.255.255
- 10.240.0.255
- 224.0.0.22
- ff02::1:2
- 185.125.190.57
- ff02::1
- 255.255.255.255
- 185.125.190.58
- ff02::2
- ff02::1:ff12:3456
- 157.240.8.35 AU · Sydney · AS32934 Facebook, Inc.
- ff02::1:ff4c:1d1d
Dropped files
- tmp_tmp.tcJBJPgCzw —
327ffa8729dddb1748ab2c1cc8fba95a6059c6634eae6f59bd1c347fc1662512
Embedded domains
- t.me
Embedded IP addresses
- 83.168.69.141
- 83.168.110.191
- 157.240.8.35
More Mirai samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report