MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 057a09a1fa3aa8bbde2e8c2637f12135cee1f0fa9c92e86e49c526c04b52bd97. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 12 File information Comments

SHA256 hash: 057a09a1fa3aa8bbde2e8c2637f12135cee1f0fa9c92e86e49c526c04b52bd97
SHA3-384 hash: f3b4b48dbcd761262203658938590200dee837f6317401c70473fa58aa0c3331eb9a3857727af7a535f989ad37396124
SHA1 hash: 50f1f5e3a3316f415bf059fbf89dc30073138c83
MD5 hash: 18296ed64327f31cb9874f849261e9be
humanhash: alpha-mexico-pasta-happy
File name:debug.dbg
Download: download sample
Signature Mirai
File size:166'540 bytes
First seen:2026-08-27 02:59:21 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:YZyMidXmhlERn29y/FS4Y2Vn2ePlAUQuT67r6u1EssMZc/T03ImIys61X1h5o7:6i5mLERn2ASoBO7rnEssMOgh5o7
TLSH T1E6F37CC16EA3D0F1E553497A42BF931A5A36E433011ACA11F73E69387F42150E7BB69C
telfhash t17e6109f82f7b0cecb7909815a25eab117e0d6b7b286036b604b3547532bfd4145bac39
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Opens a port
Launching a process
Sets a written file as executable
Sends data to a server
Creates directories in a temporary directory
Runs as daemon
Kills processes
Creating a file in the %temp% subdirectories
Connection attempt
Creating a file in the %temp% directory
Creating a process from a recently created file
Deleting a recently created file
Creates directories in a subdirectory of a temporary directory
Receives data from a server
Removes directories from a subdirectory of a temporary directory
Collects information on the OS
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Deleting of the original file
Creates or modifies files in /init.d to set up autorun
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
bashlite masquerade mirai
Status:
terminated
Behavior Graph:
%3 guuid=ed7becc9-1900-0000-6b23-73cc560a0000 pid=2646 /usr/bin/sudo guuid=a76cf3cc-1900-0000-6b23-73cc570a0000 pid=2647 /tmp/sample.bin delete-file net guuid=ed7becc9-1900-0000-6b23-73cc560a0000 pid=2646->guuid=a76cf3cc-1900-0000-6b23-73cc570a0000 pid=2647 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=a76cf3cc-1900-0000-6b23-73cc570a0000 pid=2647->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8a4772cd-1900-0000-6b23-73cc580a0000 pid=2648 /tmp/sample.bin delete-file write-config write-file zombie guuid=a76cf3cc-1900-0000-6b23-73cc570a0000 pid=2647->guuid=8a4772cd-1900-0000-6b23-73cc580a0000 pid=2648 clone guuid=6fd15709-1a00-0000-6b23-73ccab0a0000 pid=2731 /tmp/sample.bin write-file guuid=8a4772cd-1900-0000-6b23-73cc580a0000 pid=2648->guuid=6fd15709-1a00-0000-6b23-73ccab0a0000 pid=2731 clone guuid=dcc46109-1a00-0000-6b23-73ccac0a0000 pid=2732 /usr/bin/dash guuid=8a4772cd-1900-0000-6b23-73cc580a0000 pid=2648->guuid=dcc46109-1a00-0000-6b23-73ccac0a0000 pid=2732 execve guuid=fe8dae17-1a00-0000-6b23-73ccd60a0000 pid=2774 /tmp/sample.bin guuid=8a4772cd-1900-0000-6b23-73cc580a0000 pid=2648->guuid=fe8dae17-1a00-0000-6b23-73ccd60a0000 pid=2774 clone guuid=5a7fb417-1a00-0000-6b23-73ccd70a0000 pid=2775 /tmp/sample.bin guuid=8a4772cd-1900-0000-6b23-73cc580a0000 pid=2648->guuid=5a7fb417-1a00-0000-6b23-73ccd70a0000 pid=2775 clone guuid=d289b917-1a00-0000-6b23-73ccd80a0000 pid=2776 /tmp/x delete-file net guuid=8a4772cd-1900-0000-6b23-73cc580a0000 pid=2648->guuid=d289b917-1a00-0000-6b23-73ccd80a0000 pid=2776 execve guuid=21e8bc17-1a00-0000-6b23-73ccda0a0000 pid=2778 /tmp/sample.bin net send-data write-file guuid=8a4772cd-1900-0000-6b23-73cc580a0000 pid=2648->guuid=21e8bc17-1a00-0000-6b23-73ccda0a0000 pid=2778 clone guuid=61efa909-1a00-0000-6b23-73ccae0a0000 pid=2734 /usr/sbin/xtables-nft-multi guuid=dcc46109-1a00-0000-6b23-73ccac0a0000 pid=2732->guuid=61efa909-1a00-0000-6b23-73ccae0a0000 pid=2734 execve guuid=34f32b17-1a00-0000-6b23-73ccd40a0000 pid=2772 /usr/sbin/xtables-nft-multi guuid=dcc46109-1a00-0000-6b23-73ccac0a0000 pid=2732->guuid=34f32b17-1a00-0000-6b23-73ccd40a0000 pid=2772 execve guuid=a9f0ba17-1a00-0000-6b23-73ccd90a0000 pid=2777 /usr/bin/dash guuid=fe8dae17-1a00-0000-6b23-73ccd60a0000 pid=2774->guuid=a9f0ba17-1a00-0000-6b23-73ccd90a0000 pid=2777 execve guuid=048a5c18-1a00-0000-6b23-73ccdf0a0000 pid=2783 /usr/bin/dash guuid=fe8dae17-1a00-0000-6b23-73ccd60a0000 pid=2774->guuid=048a5c18-1a00-0000-6b23-73ccdf0a0000 pid=2783 execve guuid=d289b917-1a00-0000-6b23-73ccd80a0000 pid=2776->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=264c3e19-1a00-0000-6b23-73cce30a0000 pid=2787 /usr/bin/dash guuid=d289b917-1a00-0000-6b23-73ccd80a0000 pid=2776->guuid=264c3e19-1a00-0000-6b23-73cce30a0000 pid=2787 execve guuid=e5907b1c-1a00-0000-6b23-73ccee0a0000 pid=2798 /tmp/x delete-file write-config write-file zombie guuid=d289b917-1a00-0000-6b23-73ccd80a0000 pid=2776->guuid=e5907b1c-1a00-0000-6b23-73ccee0a0000 pid=2798 clone guuid=799bea17-1a00-0000-6b23-73ccdd0a0000 pid=2781 /usr/bin/kmod guuid=a9f0ba17-1a00-0000-6b23-73ccd90a0000 pid=2777->guuid=799bea17-1a00-0000-6b23-73ccdd0a0000 pid=2781 execve guuid=21e8bc17-1a00-0000-6b23-73ccda0a0000 pid=2778->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 753e308f-647b-5f4b-8a28-fe89dd00047a 198.144.179.82:55650 guuid=21e8bc17-1a00-0000-6b23-73ccda0a0000 pid=2778->753e308f-647b-5f4b-8a28-fe89dd00047a send: 60B guuid=f2f0cf17-1a00-0000-6b23-73ccdc0a0000 pid=2780 /tmp/sample.bin net net-scan send-data write-file guuid=21e8bc17-1a00-0000-6b23-73ccda0a0000 pid=2778->guuid=f2f0cf17-1a00-0000-6b23-73ccdc0a0000 pid=2780 clone guuid=f2f0cf17-1a00-0000-6b23-73ccdc0a0000 pid=2780|network network activity to 66 IP addresses review logs to see them all guuid=f2f0cf17-1a00-0000-6b23-73ccdc0a0000 pid=2780->guuid=f2f0cf17-1a00-0000-6b23-73ccdc0a0000 pid=2780|network network guuid=cfa3c819-1a00-0000-6b23-73cce60a0000 pid=2790 /usr/bin/cp guuid=264c3e19-1a00-0000-6b23-73cce30a0000 pid=2787->guuid=cfa3c819-1a00-0000-6b23-73cce60a0000 pid=2790 execve guuid=e73ff31a-1a00-0000-6b23-73ccea0a0000 pid=2794 /usr/bin/chmod guuid=264c3e19-1a00-0000-6b23-73cce30a0000 pid=2787->guuid=e73ff31a-1a00-0000-6b23-73ccea0a0000 pid=2794 execve guuid=1363774a-1a00-0000-6b23-73cc2e0b0000 pid=2862 /tmp/x write-file guuid=e5907b1c-1a00-0000-6b23-73ccee0a0000 pid=2798->guuid=1363774a-1a00-0000-6b23-73cc2e0b0000 pid=2862 clone guuid=68b37d4a-1a00-0000-6b23-73cc2f0b0000 pid=2863 /usr/bin/dash guuid=e5907b1c-1a00-0000-6b23-73ccee0a0000 pid=2798->guuid=68b37d4a-1a00-0000-6b23-73cc2f0b0000 pid=2863 execve guuid=35818c4b-1a00-0000-6b23-73cc330b0000 pid=2867 /tmp/x write-file guuid=e5907b1c-1a00-0000-6b23-73ccee0a0000 pid=2798->guuid=35818c4b-1a00-0000-6b23-73cc330b0000 pid=2867 clone guuid=d8c3924b-1a00-0000-6b23-73cc340b0000 pid=2868 /tmp/x guuid=e5907b1c-1a00-0000-6b23-73ccee0a0000 pid=2798->guuid=d8c3924b-1a00-0000-6b23-73cc340b0000 pid=2868 clone guuid=fa7d994b-1a00-0000-6b23-73cc350b0000 pid=2869 /tmp/x guuid=e5907b1c-1a00-0000-6b23-73ccee0a0000 pid=2798->guuid=fa7d994b-1a00-0000-6b23-73cc350b0000 pid=2869 clone guuid=32bd9e4b-1a00-0000-6b23-73cc370b0000 pid=2871 /tmp/x net send-data write-file guuid=e5907b1c-1a00-0000-6b23-73ccee0a0000 pid=2798->guuid=32bd9e4b-1a00-0000-6b23-73cc370b0000 pid=2871 clone guuid=2dd1a74a-1a00-0000-6b23-73cc310b0000 pid=2865 /usr/sbin/xtables-nft-multi guuid=68b37d4a-1a00-0000-6b23-73cc2f0b0000 pid=2863->guuid=2dd1a74a-1a00-0000-6b23-73cc310b0000 pid=2865 execve guuid=df5b084b-1a00-0000-6b23-73cc320b0000 pid=2866 /usr/sbin/xtables-nft-multi guuid=68b37d4a-1a00-0000-6b23-73cc2f0b0000 pid=2863->guuid=df5b084b-1a00-0000-6b23-73cc320b0000 pid=2866 execve guuid=00179a4b-1a00-0000-6b23-73cc360b0000 pid=2870 /usr/bin/dash guuid=35818c4b-1a00-0000-6b23-73cc330b0000 pid=2867->guuid=00179a4b-1a00-0000-6b23-73cc360b0000 pid=2870 execve guuid=42dcbe4d-1a00-0000-6b23-73cc3f0b0000 pid=2879 /usr/bin/dash guuid=35818c4b-1a00-0000-6b23-73cc330b0000 pid=2867->guuid=42dcbe4d-1a00-0000-6b23-73cc3f0b0000 pid=2879 execve guuid=9069af89-1a00-0000-6b23-73ccc30b0000 pid=3011 /usr/bin/dash guuid=35818c4b-1a00-0000-6b23-73cc330b0000 pid=2867->guuid=9069af89-1a00-0000-6b23-73ccc30b0000 pid=3011 execve guuid=6d5d5cc6-1a00-0000-6b23-73cc150c0000 pid=3093 /usr/bin/dash guuid=35818c4b-1a00-0000-6b23-73cc330b0000 pid=2867->guuid=6d5d5cc6-1a00-0000-6b23-73cc150c0000 pid=3093 execve guuid=e4b50418-1b00-0000-6b23-73cc420c0000 pid=3138 /usr/bin/dash guuid=35818c4b-1a00-0000-6b23-73cc330b0000 pid=2867->guuid=e4b50418-1b00-0000-6b23-73cc420c0000 pid=3138 execve guuid=bf72cf4b-1a00-0000-6b23-73cc390b0000 pid=2873 /usr/bin/kmod guuid=00179a4b-1a00-0000-6b23-73cc360b0000 pid=2870->guuid=bf72cf4b-1a00-0000-6b23-73cc390b0000 pid=2873 execve guuid=32bd9e4b-1a00-0000-6b23-73cc370b0000 pid=2871->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=32bd9e4b-1a00-0000-6b23-73cc370b0000 pid=2871->753e308f-647b-5f4b-8a28-fe89dd00047a send: 62B guuid=f858b44b-1a00-0000-6b23-73cc380b0000 pid=2872 /tmp/x delete-file net net-scan send-data write-file guuid=32bd9e4b-1a00-0000-6b23-73cc370b0000 pid=2871->guuid=f858b44b-1a00-0000-6b23-73cc380b0000 pid=2872 clone guuid=f858b44b-1a00-0000-6b23-73cc380b0000 pid=2872|network network activity to 56 IP addresses review logs to see them all guuid=f858b44b-1a00-0000-6b23-73cc380b0000 pid=2872->guuid=f858b44b-1a00-0000-6b23-73cc380b0000 pid=2872|network network guuid=79427a18-1b00-0000-6b23-73cc450c0000 pid=3141 /usr/bin/rm guuid=e4b50418-1b00-0000-6b23-73cc420c0000 pid=3138->guuid=79427a18-1b00-0000-6b23-73cc450c0000 pid=3141 execve guuid=8e032819-1b00-0000-6b23-73cc470c0000 pid=3143 /usr/bin/rm guuid=e4b50418-1b00-0000-6b23-73cc420c0000 pid=3138->guuid=8e032819-1b00-0000-6b23-73cc470c0000 pid=3143 execve
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Connects to many ports of the same IP (likely port scanning)
Drops files in suspicious directories
Drops invisible ELF files
Executes the "iptables" command to insert, remove and/or manipulate rules
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to persist itself using cron
Writes identical ELF files to multiple locations
Yara detected Moobot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1964479 Sample: debug.dbg.elf Startdate: 27/08/2026 Architecture: LINUX Score: 100 101 131.0.57.126, 23, 80, 8081 SRdaSilvaTelecomunicacoesBR Brazil 2->101 103 121.190.31.108, 23, 80, 8081 KIXS-AS-KRKoreaTelecomKR South Korea 2->103 105 61 other IPs or domains 2->105 115 Malicious sample detected (through community Yara rule) 2->115 117 Antivirus detection for dropped file 2->117 119 Antivirus / Scanner detection for submitted sample 2->119 121 3 other signatures 2->121 12 debug.dbg.elf 2->12         started        signatures3 process4 signatures5 129 Sample deletes itself 12->129 15 debug.dbg.elf 12->15         started        process6 file7 99 /etc/crontab, ASCII 15->99 dropped 107 Writes identical ELF files to multiple locations 15->107 109 Drops invisible ELF files 15->109 111 Drops files in suspicious directories 15->111 113 2 other signatures 15->113 19 debug.dbg.elf x 15->19         started        22 debug.dbg.elf sh 15->22         started        24 debug.dbg.elf 15->24         started        26 3 other processes 15->26 signatures8 process9 signatures10 123 Sample deletes itself 19->123 28 x 19->28         started        32 debug.dbg.elf sh 19->32         started        34 sh iptables 22->34         started        36 sh iptables 22->36         started        38 debug.dbg.elf sh 24->38         started        40 debug.dbg.elf sh 24->40         started        42 debug.dbg.elf sh 24->42         started        46 2 other processes 24->46 44 debug.dbg.elf 26->44         started        process11 file12 91 /var/tmp/.r.sh, POSIX 28->91 dropped 93 /var/tmp/.e180fe, ELF 28->93 dropped 95 /var/tmp/.ba4dff, ELF 28->95 dropped 97 2 other malicious files 28->97 dropped 131 Drops invisible ELF files 28->131 133 Drops files in suspicious directories 28->133 135 Sample reads /proc/mounts (often used for finding a writable filesystem) 28->135 137 Sample tries to persist itself using cron 28->137 48 x sh 28->48         started        50 x 28->50         started        52 x 28->52         started        66 3 other processes 28->66 54 sh cp 32->54         started        58 sh chmod 32->58         started        139 Executes the "iptables" command to insert, remove and/or manipulate rules 34->139 60 sh rm 38->60         started        62 sh rm 38->62         started        64 sh insmod 40->64         started        signatures13 process14 file15 68 sh iptables 48->68         started        71 sh iptables 48->71         started        73 x sh 50->73         started        75 x sh 50->75         started        77 x sh 50->77         started        81 2 other processes 50->81 79 x 52->79         started        89 /tmp/x, ELF 54->89 dropped 127 Writes identical ELF files to multiple locations 54->127 signatures16 process17 signatures18 125 Executes the "iptables" command to insert, remove and/or manipulate rules 68->125 83 sh rm 73->83         started        85 sh rm 73->85         started        87 sh insmod 75->87         started        process19
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-08-27 03:00:33 UTC
File Type:
ELF32 Little (Exe)
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation rootkit
Behaviour
Command and Scripting Interpreter: Unix Shell
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Creates/modifies Cron job
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Reads list of loaded kernel modules
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Loads a kernel module
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Rootkit_Generic_61229bdf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_5bf62ce4
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_5f7b67b8
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_cc93863b
Author:Elastic Security
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 057a09a1fa3aa8bbde2e8c2637f12135cee1f0fa9c92e86e49c526c04b52bd97

(this sample)

  
Delivery method
Distributed via web download

Comments