MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 03210b9a4a83e38cef972db97a33af5365ec109a13506d9af64b894d4f0c1974. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 14


Intelligence 14 IOCs YARA 3 File information Comments

SHA256 hash: 03210b9a4a83e38cef972db97a33af5365ec109a13506d9af64b894d4f0c1974
SHA3-384 hash: 5ca0e00bd81220d045aa989543b1892e0c2ea40ab9c274d5a042678ca6e8dbfdcd759bc4594b063bfaf47be029a866a5
SHA1 hash: add08d9f0c5ff446e80a5aa3d566a10de0394500
MD5 hash: 35e39c8ecb03fadc5715ccc0e102b9cf
humanhash: beryllium-happy-quiet-grey
File name:debug
Download: download sample
Signature Mirai
File size:49'344 bytes
First seen:2025-11-07 17:57:28 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:L2yeVYI0Rozi4fRBSIzDJsaq0kqRs1fnouy8Hyg:L2nV+mdftveaG2ooutT
TLSH T12823F11AD5584B05F002663808FFF54F2DA0461D9BEBC8E3858CB61F9752FE179297C2
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai UPX
File size (compressed) :49'344 bytes
File size (de-compressed) :115'988 bytes
Format:linux/i386
Unpacked file: f1cf642b53f15821b273f3a1f8d098c3906c8d12026cbc31e837abbd61b75779

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Opens a port
Connection attempt
DNS request
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
UPX
Botnet:
unknown
Number of open files:
47
Number of processes launched:
6
Processes remaning?
false
Remote TCP ports scanned:
8080,5000,80,22,37215,9527,81,8888,23,8081,52869
Behaviour
Information Gathering
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2025-11-07T15:05:00Z UTC
Last seen:
2025-11-09T12:29:00Z UTC
Hits:
~10
Detections:
HEUR:Exploit.Linux.CVE-2018-10561.a HEUR:Backdoor.Linux.Mirai.r HEUR:Backdoor.Linux.Mirai.b HEUR:Backdoor.Linux.Gafgyt.bl HEUR:Backdoor.Linux.Gafgyt.bj
Status:
terminated
Behavior Graph:
%3 guuid=3decf9e7-1900-0000-7a1a-c424bf0c0000 pid=3263 /usr/bin/sudo guuid=6c001eeb-1900-0000-7a1a-c424c90c0000 pid=3273 /tmp/sample.bin net send-data guuid=3decf9e7-1900-0000-7a1a-c424bf0c0000 pid=3263->guuid=6c001eeb-1900-0000-7a1a-c424c90c0000 pid=3273 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=6c001eeb-1900-0000-7a1a-c424c90c0000 pid=3273->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 540B b2255150-2060-5b7f-9786-12d5e647a020 84.201.5.31:12121 guuid=6c001eeb-1900-0000-7a1a-c424c90c0000 pid=3273->b2255150-2060-5b7f-9786-12d5e647a020 con guuid=9027e127-1a00-0000-7a1a-c424410d0000 pid=3393 /tmp/sample.bin dns net send-data guuid=6c001eeb-1900-0000-7a1a-c424c90c0000 pid=3273->guuid=9027e127-1a00-0000-7a1a-c424410d0000 pid=3393 clone guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962 /tmp/sample.bin net send-data guuid=6c001eeb-1900-0000-7a1a-c424c90c0000 pid=3273->guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962 clone guuid=29bca955-1b00-0000-7a1a-c4247b0f0000 pid=3963 /tmp/sample.bin guuid=6c001eeb-1900-0000-7a1a-c424c90c0000 pid=3273->guuid=29bca955-1b00-0000-7a1a-c4247b0f0000 pid=3963 clone guuid=9027e127-1a00-0000-7a1a-c424410d0000 pid=3393->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 108B 62d17e6a-4c11-5f38-bf9d-8aec77b84b23 mortex.duckdns.org:12121 guuid=9027e127-1a00-0000-7a1a-c424410d0000 pid=3393->62d17e6a-4c11-5f38-bf9d-8aec77b84b23 con guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394 /tmp/sample.bin net guuid=9027e127-1a00-0000-7a1a-c424410d0000 pid=3393->guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394 clone guuid=b7661228-1a00-0000-7a1a-c424430d0000 pid=3395 /tmp/sample.bin guuid=9027e127-1a00-0000-7a1a-c424410d0000 pid=3393->guuid=b7661228-1a00-0000-7a1a-c424430d0000 pid=3395 clone guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con a860c8bf-97a0-58de-afb0-3c37c845ddb4 35.180.124.191:80 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->a860c8bf-97a0-58de-afb0-3c37c845ddb4 con 6f2139d0-3544-5cc9-981f-feb859571591 100.11.100.191:52869 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->6f2139d0-3544-5cc9-981f-feb859571591 con 54d8ad79-2a57-5af7-8c7a-0a4914bb9f57 87.197.2.32:8080 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->54d8ad79-2a57-5af7-8c7a-0a4914bb9f57 con df802502-0dc4-5a2a-b5a0-a8507f6c51a1 201.230.113.24:8081 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->df802502-0dc4-5a2a-b5a0-a8507f6c51a1 con 10ff7695-d5bd-5d90-8f07-5bf61664f033 49.38.206.232:5000 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->10ff7695-d5bd-5d90-8f07-5bf61664f033 con 95f66822-a76d-50db-a379-34c3f9644e60 111.197.189.214:5000 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->95f66822-a76d-50db-a379-34c3f9644e60 con f5c4000d-7a77-5e81-8969-817ec9fd23c8 131.43.116.58:8080 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->f5c4000d-7a77-5e81-8969-817ec9fd23c8 con 11978932-ed4c-509e-abca-f10d4d7e66af 188.216.222.56:80 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->11978932-ed4c-509e-abca-f10d4d7e66af con 8a5e2e4d-87c5-5e57-a959-d14e210f8fc6 64.188.147.224:37215 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->8a5e2e4d-87c5-5e57-a959-d14e210f8fc6 con 4881fd07-ec9b-5e1f-be83-25e098345640 84.223.130.45:9527 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->4881fd07-ec9b-5e1f-be83-25e098345640 con 73982446-454a-5214-946d-6519116c02e4 24.37.82.194:80 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->73982446-454a-5214-946d-6519116c02e4 con 052d6eb8-1075-52b8-af10-04c9792dd672 148.196.7.217:37215 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->052d6eb8-1075-52b8-af10-04c9792dd672 con 03b5a5f9-e1dc-540b-af4d-cd1cee96cfff 185.51.124.163:81 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->03b5a5f9-e1dc-540b-af4d-cd1cee96cfff con 2e8b0f52-813d-58fe-83b0-448eb5f17d85 212.74.10.52:9527 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->2e8b0f52-813d-58fe-83b0-448eb5f17d85 con 9dba01da-6741-588b-b71d-4054e54228ea 169.94.51.43:37215 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->9dba01da-6741-588b-b71d-4054e54228ea con e7430752-f024-5a00-bffb-df12ac341176 79.119.222.238:8888 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->e7430752-f024-5a00-bffb-df12ac341176 con b4f91537-788b-5d09-ac0a-bdcdb2f3d282 206.229.156.180:23 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->b4f91537-788b-5d09-ac0a-bdcdb2f3d282 con 2a0a6e97-0e8e-5e68-b51e-aa582572a32e 130.68.44.7:37215 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->2a0a6e97-0e8e-5e68-b51e-aa582572a32e con 4e1a940b-8f4d-5bf8-80a1-36fd4b5465e9 195.120.212.8:5000 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->4e1a940b-8f4d-5bf8-80a1-36fd4b5465e9 con 7b5a5ba0-0b2e-5df3-a7b6-d6460b2660c2 129.111.59.222:9527 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->7b5a5ba0-0b2e-5df3-a7b6-d6460b2660c2 con c06705a1-d026-5c9d-b8f8-83d874144843 84.53.225.132:8080 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->c06705a1-d026-5c9d-b8f8-83d874144843 con 81d4b828-36dc-59ee-a326-434efcbb1b62 12.175.222.139:80 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->81d4b828-36dc-59ee-a326-434efcbb1b62 con 95ea6935-0502-5dce-9571-60566573563b 199.134.189.235:9527 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->95ea6935-0502-5dce-9571-60566573563b con 94a68cc2-8c02-5d40-8250-ee1e3530fb4b 43.217.98.255:8080 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->94a68cc2-8c02-5d40-8250-ee1e3530fb4b con 9c5772cf-9c8f-54d6-b67d-3e76334a0180 187.254.37.249:22 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->9c5772cf-9c8f-54d6-b67d-3e76334a0180 con 442e3123-9498-5e01-afaf-239c73f39a48 59.100.39.159:80 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->442e3123-9498-5e01-afaf-239c73f39a48 con 26894817-028c-5965-9a66-08202047ef97 90.126.216.103:52869 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->26894817-028c-5965-9a66-08202047ef97 con 27f9874d-9b0f-5e77-81dc-3546011e2558 78.101.223.75:8888 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->27f9874d-9b0f-5e77-81dc-3546011e2558 con b7838062-e4bb-5b49-84c5-eb9603c668bd 149.190.61.170:81 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->b7838062-e4bb-5b49-84c5-eb9603c668bd con ffb12dc3-b081-5352-98ed-be65ad397d70 97.46.236.140:8080 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->ffb12dc3-b081-5352-98ed-be65ad397d70 con 0b0c1abd-eba6-5e29-8142-255676710c79 105.116.17.84:22 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->0b0c1abd-eba6-5e29-8142-255676710c79 con 03c60111-4a9f-5697-93b0-a8995d3a0621 200.177.47.4:22 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->03c60111-4a9f-5697-93b0-a8995d3a0621 con e9c75459-a39e-5c17-9759-c2b501e3adf0 123.221.187.124:37215 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->e9c75459-a39e-5c17-9759-c2b501e3adf0 con d1c968ff-75ab-5f89-b09c-24cd3f70bed2 52.159.98.149:81 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->d1c968ff-75ab-5f89-b09c-24cd3f70bed2 con 5fe27919-6d33-5bed-906d-054b06fa72c2 199.165.244.199:80 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->5fe27919-6d33-5bed-906d-054b06fa72c2 con f27ec950-2cd8-58e3-b70d-26bb59f5d01d 160.112.118.143:8888 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->f27ec950-2cd8-58e3-b70d-26bb59f5d01d con 18b49824-a327-52e4-bbdf-28e458f3ac28 162.241.96.20:23 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->18b49824-a327-52e4-bbdf-28e458f3ac28 con eaabf3c0-5d61-5a20-949c-fa2391a04729 95.96.20.173:37215 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->eaabf3c0-5d61-5a20-949c-fa2391a04729 con a38d244b-2872-5cf9-9577-e290dbe6de6c 81.232.89.254:23 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->a38d244b-2872-5cf9-9577-e290dbe6de6c con 11738aad-96c0-5b63-a861-39cf4df78e15 98.201.139.29:8081 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->11738aad-96c0-5b63-a861-39cf4df78e15 con 7a1558cc-9b04-5718-b934-11de89eeea86 142.94.160.194:8080 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->7a1558cc-9b04-5718-b934-11de89eeea86 con 2768982a-f6a2-51f1-ac9f-00df8528591f 151.66.83.122:8080 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->2768982a-f6a2-51f1-ac9f-00df8528591f con 48c76836-84eb-526b-b205-9f47cc82924d 163.232.216.177:8080 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->48c76836-84eb-526b-b205-9f47cc82924d con ec4f5c29-b9ee-5d8d-8e8e-db29c6ba279c 71.177.73.84:9527 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->ec4f5c29-b9ee-5d8d-8e8e-db29c6ba279c con 616c8a93-33f2-5478-a790-d7c778fe254f 67.61.216.147:23 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->616c8a93-33f2-5478-a790-d7c778fe254f con f6984b64-2b89-5c0b-a1da-5a917f3edf0d 116.108.88.219:5000 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->f6984b64-2b89-5c0b-a1da-5a917f3edf0d con 505af52e-337d-54ec-a4cf-fbe8b63afac9 130.42.51.245:8888 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->505af52e-337d-54ec-a4cf-fbe8b63afac9 con fe0d2c0c-01ec-5649-90b1-8359e50ca7dd 47.54.164.116:8080 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->fe0d2c0c-01ec-5649-90b1-8359e50ca7dd con 591be8b2-1ae5-56de-bbed-5f196da3c5d8 4.46.138.38:22 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->591be8b2-1ae5-56de-bbed-5f196da3c5d8 con 249d176a-b797-5d22-a407-a92f54ef561b 192.108.127.33:9527 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->249d176a-b797-5d22-a407-a92f54ef561b con 1494aea4-16d8-538e-93d4-ca75bf777ad5 205.33.158.154:8080 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->1494aea4-16d8-538e-93d4-ca75bf777ad5 con a6839a5e-6b65-56a4-8f1e-91dc188c05f4 204.235.52.97:8081 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->a6839a5e-6b65-56a4-8f1e-91dc188c05f4 con eb966971-3a2a-5b39-a6f1-8cea33ff36da 93.28.243.51:9527 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->eb966971-3a2a-5b39-a6f1-8cea33ff36da con 3fc0fc9e-cbf1-5b50-b81d-165537bf4734 166.91.145.95:22 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->3fc0fc9e-cbf1-5b50-b81d-165537bf4734 con 3b713f9b-d7bb-5da7-baa1-bfdfbbab170b 207.194.232.131:8080 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->3b713f9b-d7bb-5da7-baa1-bfdfbbab170b con 2c7621ef-8045-5034-b80d-96a20e8b3963 12.44.28.200:5000 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->2c7621ef-8045-5034-b80d-96a20e8b3963 con 21677c6b-3ff8-5413-b520-1d14708db7a2 32.231.97.238:8080 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->21677c6b-3ff8-5413-b520-1d14708db7a2 con d767994c-e2ec-595f-8a95-b07dc1e19ed7 68.147.38.12:22 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->d767994c-e2ec-595f-8a95-b07dc1e19ed7 con b939c204-efbd-570f-8001-247258851bcc 57.14.10.19:23 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->b939c204-efbd-570f-8001-247258851bcc con 8950b95b-6ec7-52dc-9a01-a68a77c3416e 141.175.120.147:23 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->8950b95b-6ec7-52dc-9a01-a68a77c3416e con 03682c92-1fb7-5bcf-b24e-4842a3776444 193.62.225.191:80 guuid=fc600028-1a00-0000-7a1a-c424420d0000 pid=3394->03682c92-1fb7-5bcf-b24e-4842a3776444 con guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 485ea2a5-af39-5579-985f-0750ab21c83c 113.70.111.244:81 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->485ea2a5-af39-5579-985f-0750ab21c83c con 6e08dfcc-fb6f-5956-aa8d-87e598573cd8 171.22.183.24:80 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->6e08dfcc-fb6f-5956-aa8d-87e598573cd8 send: 949B b98598a4-e1ea-55c8-be84-84055a27f4c0 101.27.203.243:23 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->b98598a4-e1ea-55c8-be84-84055a27f4c0 con 22dc271e-421b-53d7-afc0-3b673040d1ec 114.159.56.233:8080 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->22dc271e-421b-53d7-afc0-3b673040d1ec con 1ce6e373-b649-5268-b6ad-e493067da8f9 207.12.28.91:8080 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->1ce6e373-b649-5268-b6ad-e493067da8f9 con 97fa967d-56b9-54df-b8e9-6f2b9e3c977e 152.211.236.148:8081 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->97fa967d-56b9-54df-b8e9-6f2b9e3c977e con 9f1047ce-094c-52fb-a07a-92135f14464c 203.182.207.230:8081 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->9f1047ce-094c-52fb-a07a-92135f14464c con e611a9d2-0ea3-53f7-8ff6-2cb19f0ac70d 152.164.160.189:37215 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->e611a9d2-0ea3-53f7-8ff6-2cb19f0ac70d con d34057f2-f92b-5cbc-ad32-2406867aaf5b 64.157.250.14:9527 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->d34057f2-f92b-5cbc-ad32-2406867aaf5b con a871dee3-4aff-524b-b79c-f302337f9980 158.36.139.96:23 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->a871dee3-4aff-524b-b79c-f302337f9980 con ebf7b5a2-151e-5481-8b30-7fa9dbedef02 59.174.184.63:37215 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->ebf7b5a2-151e-5481-8b30-7fa9dbedef02 con 9a38a2c1-0329-55dc-99f5-e2f40c03d475 124.148.40.177:80 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->9a38a2c1-0329-55dc-99f5-e2f40c03d475 con 2d59d6b8-ce35-50bf-8a86-1d79baf132e8 68.140.139.242:23 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->2d59d6b8-ce35-50bf-8a86-1d79baf132e8 con c3713a28-fd9c-5b93-85ed-77309340f489 125.197.197.120:80 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->c3713a28-fd9c-5b93-85ed-77309340f489 con 32951840-0d6a-544a-8fe8-d93fef2e22bb 117.115.99.31:81 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->32951840-0d6a-544a-8fe8-d93fef2e22bb con 6ffe1449-7d4f-55ce-a8cd-138a76fbd22c 74.100.106.29:22 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->6ffe1449-7d4f-55ce-a8cd-138a76fbd22c con e829162d-94f7-5e09-a453-9a53101e24b6 163.156.39.137:9527 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->e829162d-94f7-5e09-a453-9a53101e24b6 con e811c45e-12c0-5b3a-afb7-1e5695839e23 220.244.94.25:52869 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->e811c45e-12c0-5b3a-afb7-1e5695839e23 con 196913b1-eb4f-5d31-9496-5f93e13e6c9b 76.8.215.252:23 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->196913b1-eb4f-5d31-9496-5f93e13e6c9b con c0a8034c-06f5-5adf-ae4c-731122c05c5e 124.118.24.129:9527 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->c0a8034c-06f5-5adf-ae4c-731122c05c5e con f18dcb3d-e0ce-5b73-afee-46d3575be206 194.167.24.142:23 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->f18dcb3d-e0ce-5b73-afee-46d3575be206 con 35deebba-0572-5986-9f77-114dde871659 216.103.10.87:80 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->35deebba-0572-5986-9f77-114dde871659 con 1e83c523-9d70-5db0-bd6c-db79774435fa 206.198.23.48:8080 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->1e83c523-9d70-5db0-bd6c-db79774435fa con 8987f0a1-e5ad-5a05-8da5-34b15f14cdb6 209.52.207.19:22 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->8987f0a1-e5ad-5a05-8da5-34b15f14cdb6 con 03ab0b66-917e-5d75-9200-0a84939801ce 13.190.198.190:80 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->03ab0b66-917e-5d75-9200-0a84939801ce con f3aca9df-8d98-5abf-a581-0ef544de2a87 91.142.250.62:23 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->f3aca9df-8d98-5abf-a581-0ef544de2a87 con f335db77-41ed-51ef-bf2a-bf16586c10f3 58.156.44.204:80 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->f335db77-41ed-51ef-bf2a-bf16586c10f3 con 5e5baeac-6bfa-5a8a-8439-f70f889bdfc5 90.60.164.184:8080 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->5e5baeac-6bfa-5a8a-8439-f70f889bdfc5 con b3418ac2-edf3-5f34-81cf-b54e17d1ffb4 76.121.60.220:8081 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->b3418ac2-edf3-5f34-81cf-b54e17d1ffb4 con bca85c6b-d6cc-5cef-9db9-7381b8c10495 217.201.0.32:8888 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->bca85c6b-d6cc-5cef-9db9-7381b8c10495 con dad23dff-e51c-56cc-8960-81c6e2ed07b5 41.163.158.164:8888 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->dad23dff-e51c-56cc-8960-81c6e2ed07b5 con 459799d7-0bf2-5c80-8b3f-930af6f6f83a 54.77.201.192:22 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->459799d7-0bf2-5c80-8b3f-930af6f6f83a con 0d781267-e206-5dbc-846f-e753fdf5cb60 60.101.145.176:80 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->0d781267-e206-5dbc-846f-e753fdf5cb60 con 8d671007-190b-56f4-adff-d83a53e1c8b2 212.187.5.212:5000 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->8d671007-190b-56f4-adff-d83a53e1c8b2 con db7f4309-2266-54ed-a4d8-3f75d76cce85 9.171.214.23:81 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->db7f4309-2266-54ed-a4d8-3f75d76cce85 con b54a13b0-392b-594c-aa9e-8fce662de411 184.218.181.204:5000 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->b54a13b0-392b-594c-aa9e-8fce662de411 con 78f86297-4c01-5b78-9a9c-05f6e30a0e0c 162.151.105.35:81 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->78f86297-4c01-5b78-9a9c-05f6e30a0e0c con d849ebb1-3f6b-57a4-a552-b5ddf49c843b 18.113.146.90:81 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->d849ebb1-3f6b-57a4-a552-b5ddf49c843b con 4603f911-7862-5635-a595-9f5b16b32fd8 20.87.101.150:9527 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->4603f911-7862-5635-a595-9f5b16b32fd8 con f16056f3-88fc-5654-a153-2cafca357ddf 80.82.251.231:80 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->f16056f3-88fc-5654-a153-2cafca357ddf con 66af9b86-0c17-556b-af59-d2e32f9344fa 211.52.149.82:23 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->66af9b86-0c17-556b-af59-d2e32f9344fa con b3410816-b754-5ef9-8dda-697f748f6991 207.85.225.4:5000 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->b3410816-b754-5ef9-8dda-697f748f6991 con fd4eeafe-953c-5544-9ea7-21fcd0adad82 130.130.228.39:80 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->fd4eeafe-953c-5544-9ea7-21fcd0adad82 con 518777fb-5c47-5f4b-9977-bdbba437f2dd 219.118.227.69:22 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->518777fb-5c47-5f4b-9977-bdbba437f2dd con 911ce1bb-2888-5515-a639-6dfbacc3df64 209.206.144.149:5000 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->911ce1bb-2888-5515-a639-6dfbacc3df64 con 82e98c36-658d-5acc-baf7-a0daee9cc4b0 148.236.4.70:37215 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->82e98c36-658d-5acc-baf7-a0daee9cc4b0 con 9ad2fd8f-ab60-56f2-803f-f3eb7b8c42ed 187.83.179.84:8080 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->9ad2fd8f-ab60-56f2-803f-f3eb7b8c42ed con 06c58c75-dbda-53f3-b6a5-ede8f85eddf5 220.248.186.234:23 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->06c58c75-dbda-53f3-b6a5-ede8f85eddf5 con 1de504c9-a9cc-53a3-b33f-369ac1ac1b6b 92.197.158.88:22 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->1de504c9-a9cc-53a3-b33f-369ac1ac1b6b con 7a6bc294-d198-5f0a-bdce-629dace34237 103.117.100.195:80 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->7a6bc294-d198-5f0a-bdce-629dace34237 con 0344f6da-9c6d-53c1-b72e-f4db4ee12d54 102.105.240.8:22 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->0344f6da-9c6d-53c1-b72e-f4db4ee12d54 con 492b240b-2cb7-5874-bcd2-c260946cae96 205.145.95.62:52869 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->492b240b-2cb7-5874-bcd2-c260946cae96 con b935952b-77d4-530c-85cc-a71f2f869366 8.100.125.26:81 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->b935952b-77d4-530c-85cc-a71f2f869366 con b4a9e80f-e188-5b66-86fe-c8caf2985cc2 96.97.165.0:37215 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->b4a9e80f-e188-5b66-86fe-c8caf2985cc2 con 59df1e34-3b8a-5aea-a4de-b2936f59003f 47.250.32.37:8080 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->59df1e34-3b8a-5aea-a4de-b2936f59003f con f0dd17cf-6603-541c-a4f1-56d70fbcbf92 221.226.26.164:9527 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->f0dd17cf-6603-541c-a4f1-56d70fbcbf92 con 142bf43d-97b7-526e-bf7d-1d0d9c43f569 89.242.49.64:5000 guuid=ec3a9e55-1b00-0000-7a1a-c4247a0f0000 pid=3962->142bf43d-97b7-526e-bf7d-1d0d9c43f569 con
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
52 / 100
Signature
Connects to many ports of the same IP (likely port scanning)
Sample is packed with UPX
Uses dynamic DNS services
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1810115 Sample: debug.elf Startdate: 07/11/2025 Architecture: LINUX Score: 52 22 mortex.duckdns.org 2->22 24 67.89.90.225, 37215 XO-AS15US United States 2->24 26 100 other IPs or domains 2->26 28 Connects to many ports of the same IP (likely port scanning) 2->28 30 Sample is packed with UPX 2->30 8 debug.elf 2->8         started        10 python3.8 dpkg 2->10         started        signatures3 32 Uses dynamic DNS services 22->32 process4 process5 12 debug.elf 8->12         started        14 debug.elf 8->14         started        16 debug.elf 8->16         started        process6 18 debug.elf 12->18         started        20 debug.elf 12->20         started       
Threat name:
Linux.Backdoor.Mirai
Status:
Malicious
First seen:
2025-11-07 17:58:15 UTC
File Type:
ELF32 Little (Exe)
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
Enumerates running processes
Writes file to system bin folder
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
mortex.duckdns.org
Verdict:
Malicious
Tags:
Unix.Dropper.Mirai-7135858-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 03210b9a4a83e38cef972db97a33af5365ec109a13506d9af64b894d4f0c1974

(this sample)

  
Delivery method
Distributed via web download

Comments