MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 05d2d4be8bc03591f6461dcbf68cf8445fbb403fa4b4ea4f5435dc1dab5c9ab3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 15


Intelligence 15 IOCs YARA 2 File information Comments

SHA256 hash: 05d2d4be8bc03591f6461dcbf68cf8445fbb403fa4b4ea4f5435dc1dab5c9ab3
SHA3-384 hash: fbe5d0b63ef97561106a1c1ea6a93e5c443962a03a2d65bae096ff1917170db360d264e57c5a819dde1b5ee16ecf9ff6
SHA1 hash: eb2e2647fbf991a6676caba37ed568aba08ed12c
MD5 hash: 7f890af1fb4c65b247b8e80ee3058b85
humanhash: gee-nuts-cup-low
File name:morte.i686
Download: download sample
Signature Mirai
File size:49'208 bytes
First seen:2025-11-07 17:09:58 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:38KlwmMVHwrjCz5T+CFn5t1cVrupnouy8Hyd:sKlbMhw3gEg5tG4outu
TLSH T13B23014A583C9708C2BF52F9D93E278F655CB2D315A9D43AABA059A1D4B6FF03600CD3
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai UPX
File size (compressed) :49'208 bytes
File size (de-compressed) :120'084 bytes
Format:linux/i386
Unpacked file: db5d47d8fd8645176f1a4dffe1ffb763aed90d3c2afcfcdbbaaa7456accded7d

Intelligence


File Origin
# of uploads :
1
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Runs as daemon
Opens a port
Sends data to a server
DNS request
Connection attempt
Performs a bruteforce attack in the network
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
gafgyt masquerade mirai obfuscated packed upx
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
UPX
Botnet:
unknown
Number of open files:
47
Number of processes launched:
5
Processes remaning?
false
Remote TCP ports scanned:
8888,22,52869,80,8080,81,37215,8081,23,9527,5000
Behaviour
Information Gathering
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2025-11-07T14:24:00Z UTC
Last seen:
2025-11-09T12:01:00Z UTC
Hits:
~10
Detections:
HEUR:Backdoor.Linux.Gafgyt.bl HEUR:Backdoor.Linux.Gafgyt.bj HEUR:Exploit.Linux.CVE-2018-10561.a HEUR:Backdoor.Linux.Mirai.r HEUR:Backdoor.Linux.Mirai.b
Status:
terminated
Behavior Graph:
%3 guuid=eec7499f-1b00-0000-1801-7584db0c0000 pid=3291 /usr/bin/sudo guuid=1af62fa3-1b00-0000-1801-7584e50c0000 pid=3301 /tmp/sample.bin net guuid=eec7499f-1b00-0000-1801-7584db0c0000 pid=3291->guuid=1af62fa3-1b00-0000-1801-7584e50c0000 pid=3301 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=1af62fa3-1b00-0000-1801-7584e50c0000 pid=3301->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=487edfa3-1b00-0000-1801-7584e80c0000 pid=3304 /tmp/sample.bin guuid=1af62fa3-1b00-0000-1801-7584e50c0000 pid=3301->guuid=487edfa3-1b00-0000-1801-7584e80c0000 pid=3304 clone guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960 /tmp/sample.bin net zombie guuid=1af62fa3-1b00-0000-1801-7584e50c0000 pid=3301->guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960 clone guuid=accf8bd0-1c00-0000-1801-7584790f0000 pid=3961 /tmp/sample.bin guuid=1af62fa3-1b00-0000-1801-7584e50c0000 pid=3301->guuid=accf8bd0-1c00-0000-1801-7584790f0000 pid=3961 clone guuid=31499ad0-1c00-0000-1801-75847a0f0000 pid=3962 /tmp/sample.bin net send-data zombie guuid=1af62fa3-1b00-0000-1801-7584e50c0000 pid=3301->guuid=31499ad0-1c00-0000-1801-75847a0f0000 pid=3962 clone guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305 /tmp/sample.bin net zombie guuid=487edfa3-1b00-0000-1801-7584e80c0000 pid=3304->guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305 clone guuid=877ff4a3-1b00-0000-1801-7584ea0c0000 pid=3306 /tmp/sample.bin guuid=487edfa3-1b00-0000-1801-7584e80c0000 pid=3304->guuid=877ff4a3-1b00-0000-1801-7584ea0c0000 pid=3306 clone guuid=b90fffa3-1b00-0000-1801-7584ec0c0000 pid=3308 /tmp/sample.bin dns net send-data zombie guuid=487edfa3-1b00-0000-1801-7584e80c0000 pid=3304->guuid=b90fffa3-1b00-0000-1801-7584ec0c0000 pid=3308 clone guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 68263c41-8602-545f-a958-9691869eb1e4 109.125.217.169:8888 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->68263c41-8602-545f-a958-9691869eb1e4 con d4dfab01-9a57-50a7-a9af-c4713bd7ee5d 14.32.193.169:80 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->d4dfab01-9a57-50a7-a9af-c4713bd7ee5d con 51bb7a7e-305e-554e-b4ed-d257d7b68c8d 120.10.5.122:22 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->51bb7a7e-305e-554e-b4ed-d257d7b68c8d con c9ee1b58-d963-5c25-9a8e-2624e61fca77 18.106.131.169:37215 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->c9ee1b58-d963-5c25-9a8e-2624e61fca77 con acde51c3-9dbf-5348-a47e-46630cfcc56e 174.249.60.84:80 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->acde51c3-9dbf-5348-a47e-46630cfcc56e con 6099e8d2-e375-5971-8e80-47ad9abfe61e 200.103.201.71:5000 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->6099e8d2-e375-5971-8e80-47ad9abfe61e con 54d2973f-81a8-5ceb-a2e5-2659d1a95d05 97.66.144.35:81 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->54d2973f-81a8-5ceb-a2e5-2659d1a95d05 con a2e4ce83-dd9d-5821-a84b-7b778a0bc241 141.202.232.39:80 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->a2e4ce83-dd9d-5821-a84b-7b778a0bc241 con f927dc8a-79c4-5574-87ac-465719ca61a9 91.167.222.85:8080 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->f927dc8a-79c4-5574-87ac-465719ca61a9 con 131a1c7f-37fa-5864-8c93-9605a7ad28a9 185.229.241.203:37215 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->131a1c7f-37fa-5864-8c93-9605a7ad28a9 con 240e2823-5df8-579c-8b86-11240ea47cb6 98.120.139.2:8080 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->240e2823-5df8-579c-8b86-11240ea47cb6 con 4873694f-b01a-5325-b281-a6bf0f2f6931 12.207.37.132:80 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->4873694f-b01a-5325-b281-a6bf0f2f6931 con cd0620db-b645-57e8-b8db-5444b24f7d3a 147.2.126.29:8888 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->cd0620db-b645-57e8-b8db-5444b24f7d3a con 1a41c48b-39df-56d2-b209-b1a9b5212d01 213.34.41.158:52869 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->1a41c48b-39df-56d2-b209-b1a9b5212d01 con f8105cf7-0f37-5be2-af72-7c77a017bb10 100.190.7.140:8080 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->f8105cf7-0f37-5be2-af72-7c77a017bb10 con 95aed0ba-587a-5b4a-8b36-79677a2ad2d3 188.234.31.164:37215 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->95aed0ba-587a-5b4a-8b36-79677a2ad2d3 con a7f6f896-b405-5ed3-b647-ea3a647490f4 200.226.212.64:8080 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->a7f6f896-b405-5ed3-b647-ea3a647490f4 con f43ad881-9a96-59d4-963d-267d16c24b77 44.66.213.218:8081 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->f43ad881-9a96-59d4-963d-267d16c24b77 con 2f01618e-0264-59fa-bb86-7c4d784e320e 14.120.11.11:37215 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->2f01618e-0264-59fa-bb86-7c4d784e320e con bd773499-391a-5eb3-bc28-62b9688a907a 166.164.6.123:8081 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->bd773499-391a-5eb3-bc28-62b9688a907a con a643f142-a679-5a63-9521-b6532a25d959 223.120.0.183:8081 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->a643f142-a679-5a63-9521-b6532a25d959 con 91dd401d-01d4-50c6-9cbd-67e7d739e1f0 166.195.88.96:81 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->91dd401d-01d4-50c6-9cbd-67e7d739e1f0 con 31544b0e-c296-52f4-ab6a-f48f7973d28c 119.215.178.238:8888 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->31544b0e-c296-52f4-ab6a-f48f7973d28c con 8c3c1d53-38f7-5d16-b49d-d97acbcdcbd5 54.47.107.205:8888 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->8c3c1d53-38f7-5d16-b49d-d97acbcdcbd5 con 87f32a4c-ba0d-50a2-8984-667a84a7df22 141.75.87.235:8080 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->87f32a4c-ba0d-50a2-8984-667a84a7df22 con 0002cce2-304e-5310-80e5-8068473698a0 210.239.214.80:37215 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->0002cce2-304e-5310-80e5-8068473698a0 con 733e3f8b-53d2-5797-a6ad-b1a76af8418e 117.189.247.163:80 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->733e3f8b-53d2-5797-a6ad-b1a76af8418e con 2b11a9ef-42fb-5105-b5ce-665c9d63bc37 35.23.120.3:80 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->2b11a9ef-42fb-5105-b5ce-665c9d63bc37 con e0454acd-3e70-5bed-9895-d4179cd47e84 13.92.152.217:9527 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->e0454acd-3e70-5bed-9895-d4179cd47e84 con 26e376ea-e028-501d-8362-17bb5cc19321 173.161.65.63:8080 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->26e376ea-e028-501d-8362-17bb5cc19321 con a3234ae8-d98b-5d2b-b5ed-4625aece3d4f 208.29.35.15:8080 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->a3234ae8-d98b-5d2b-b5ed-4625aece3d4f con c8dd2bc9-ecc6-5729-ab1d-cb23057fd54e 124.74.65.243:22 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->c8dd2bc9-ecc6-5729-ab1d-cb23057fd54e con f51cd999-f0de-5fe3-8a44-255d896be5b2 210.152.86.242:8080 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->f51cd999-f0de-5fe3-8a44-255d896be5b2 con 1ef3113f-f629-5c19-bf75-a9ef4470451e 198.143.124.241:5000 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->1ef3113f-f629-5c19-bf75-a9ef4470451e con 50e2d23d-1b1f-5a5c-904c-fd0b2ea8e62a 208.128.56.85:9527 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->50e2d23d-1b1f-5a5c-904c-fd0b2ea8e62a con 0db87fad-0518-5c77-a086-7c0507caf306 31.247.192.57:23 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->0db87fad-0518-5c77-a086-7c0507caf306 con e668ba47-cbf3-53a9-a6e0-45057e29604d 166.137.1.232:80 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->e668ba47-cbf3-53a9-a6e0-45057e29604d con bbfbd2b8-761e-53a2-bba7-dedb77288b30 110.23.173.127:37215 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->bbfbd2b8-761e-53a2-bba7-dedb77288b30 con 7ffeedde-20c0-53e6-b05f-2f937af6a199 174.50.140.218:23 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->7ffeedde-20c0-53e6-b05f-2f937af6a199 con aca057c4-b7ce-5551-b8f0-df958659d279 104.169.151.68:9527 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->aca057c4-b7ce-5551-b8f0-df958659d279 con 92bbaa39-b9f3-543f-b45c-67556466b0c4 158.190.10.231:8081 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->92bbaa39-b9f3-543f-b45c-67556466b0c4 con d632a2d1-7eed-557e-b885-92aa9dfa557a 178.205.8.224:52869 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->d632a2d1-7eed-557e-b885-92aa9dfa557a con 76f26fbf-b1a9-56b5-aa53-8f7505793ae3 211.45.145.31:8080 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->76f26fbf-b1a9-56b5-aa53-8f7505793ae3 con 96e8454b-6f5a-5894-be57-7895924c6b5e 124.30.220.36:37215 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->96e8454b-6f5a-5894-be57-7895924c6b5e con 30f2c76e-7d1e-5cec-9d21-aa5f3f2bdfeb 39.108.139.195:52869 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->30f2c76e-7d1e-5cec-9d21-aa5f3f2bdfeb con 0c59d9d2-d2bc-5b80-8006-4d67cfb6b403 185.173.178.124:8888 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->0c59d9d2-d2bc-5b80-8006-4d67cfb6b403 con ed066c3c-6fbe-50cc-84cd-a0ee10e222de 107.90.1.160:80 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->ed066c3c-6fbe-50cc-84cd-a0ee10e222de con 7c31d026-dbd1-571c-b667-37eb6e9de081 2.5.68.58:81 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->7c31d026-dbd1-571c-b667-37eb6e9de081 con fbf2e636-76c4-5da8-b43d-b60b04182ae9 188.133.233.113:8080 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->fbf2e636-76c4-5da8-b43d-b60b04182ae9 con 19f0529a-e102-5210-8b1d-4d0143e8d00a 168.229.27.183:23 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->19f0529a-e102-5210-8b1d-4d0143e8d00a con 7da9cdc8-4f9a-5807-9942-093e301dde79 111.99.243.174:9527 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->7da9cdc8-4f9a-5807-9942-093e301dde79 con aa69113b-37e3-51c7-8f85-95da0c7ddff0 208.106.245.109:80 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->aa69113b-37e3-51c7-8f85-95da0c7ddff0 con 01a34718-308e-564d-8bae-cc1b15885d27 164.12.112.3:9527 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->01a34718-308e-564d-8bae-cc1b15885d27 con 288ca45f-4132-5dbe-850c-3b581267b192 2.213.60.108:81 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->288ca45f-4132-5dbe-850c-3b581267b192 con 562a8d88-196d-591c-a0a7-544f06a63e8f 121.83.150.182:22 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->562a8d88-196d-591c-a0a7-544f06a63e8f con 1effa3c9-7c7f-5f63-91da-f580d016b305 18.13.252.90:22 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->1effa3c9-7c7f-5f63-91da-f580d016b305 con 5abb6b8a-e76e-56f9-a7ff-80f6a6c78443 143.27.161.104:8080 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->5abb6b8a-e76e-56f9-a7ff-80f6a6c78443 con 0844e208-90a2-5bc0-8d95-e89d9f83ae28 133.208.153.16:52869 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->0844e208-90a2-5bc0-8d95-e89d9f83ae28 con 080a6762-335d-531a-84ec-dc9614ec7edb 193.36.3.88:23 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->080a6762-335d-531a-84ec-dc9614ec7edb con 365fa3ab-3ad0-578e-971f-0f3b38dc10e7 84.58.1.146:8081 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->365fa3ab-3ad0-578e-971f-0f3b38dc10e7 con eee51222-0d36-5b54-84d4-a9d0f3851f64 89.186.118.64:8080 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->eee51222-0d36-5b54-84d4-a9d0f3851f64 con 007aa642-1cf9-57fb-b6ab-143ce27e2181 163.102.53.124:80 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->007aa642-1cf9-57fb-b6ab-143ce27e2181 con 5225ecf4-42a7-5b67-937d-49b65061891b 206.12.126.79:8081 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->5225ecf4-42a7-5b67-937d-49b65061891b con fc5b8540-fc40-577c-ba8e-ce47558970bf 32.166.103.180:80 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->fc5b8540-fc40-577c-ba8e-ce47558970bf con d8fe42e9-9926-5e1f-91df-681e39c375cb 111.85.70.207:23 guuid=8d3eeaa3-1b00-0000-1801-7584e90c0000 pid=3305->d8fe42e9-9926-5e1f-91df-681e39c375cb con guuid=b90fffa3-1b00-0000-1801-7584ec0c0000 pid=3308->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 108B 62d17e6a-4c11-5f38-bf9d-8aec77b84b23 mortex.duckdns.org:12121 guuid=b90fffa3-1b00-0000-1801-7584ec0c0000 pid=3308->62d17e6a-4c11-5f38-bf9d-8aec77b84b23 con guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e36ef7d2-a035-53fa-8fef-ed03c934a718 78.184.5.168:8081 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->e36ef7d2-a035-53fa-8fef-ed03c934a718 con 20816a61-6347-545e-99a6-7753c3b6a314 82.17.85.24:5000 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->20816a61-6347-545e-99a6-7753c3b6a314 con 41eb59db-dde1-5f61-a85e-c3e0c2e61cf4 146.111.155.72:37215 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->41eb59db-dde1-5f61-a85e-c3e0c2e61cf4 con b94fc941-b88d-5789-bedd-24c5acf76c4c 88.195.54.165:8888 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->b94fc941-b88d-5789-bedd-24c5acf76c4c con 9a109dc8-dcc5-5ecb-bf00-a5c11f675e42 161.87.45.111:23 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->9a109dc8-dcc5-5ecb-bf00-a5c11f675e42 con 3b013d26-6fec-5351-afd8-c61c0d59fa06 203.19.61.224:80 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->3b013d26-6fec-5351-afd8-c61c0d59fa06 con 14a05fb5-0cc8-59ed-b811-e233d520ce55 126.242.234.47:22 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->14a05fb5-0cc8-59ed-b811-e233d520ce55 con 22c341fd-1160-5133-9168-ae8d4bb5de1d 207.203.245.171:8080 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->22c341fd-1160-5133-9168-ae8d4bb5de1d con cd3667ff-3705-5eba-b7bf-63148d05ca9d 180.34.33.49:37215 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->cd3667ff-3705-5eba-b7bf-63148d05ca9d con 3fe6251b-3980-5f37-8bb1-a19aff08e70c 116.121.25.238:9527 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->3fe6251b-3980-5f37-8bb1-a19aff08e70c con 20155223-5514-5b24-bfd6-6aa358a217c3 151.214.185.160:80 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->20155223-5514-5b24-bfd6-6aa358a217c3 con bc9c7c49-81db-50be-b325-9c7c07062e92 200.15.74.213:9527 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->bc9c7c49-81db-50be-b325-9c7c07062e92 con 07df7d49-6ffb-5489-9b6c-603e562a2a59 46.137.50.136:5000 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->07df7d49-6ffb-5489-9b6c-603e562a2a59 con 343bfce5-e986-59b8-93cc-2328b5f9b2aa 95.21.245.21:52869 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->343bfce5-e986-59b8-93cc-2328b5f9b2aa con fc379595-65cd-576b-b033-3429cd12fc71 186.101.26.96:8081 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->fc379595-65cd-576b-b033-3429cd12fc71 con f46fce78-23dc-57bf-8ed5-1f60569e95b5 70.159.233.110:81 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->f46fce78-23dc-57bf-8ed5-1f60569e95b5 con f254710a-b635-5081-8da5-952d324dd225 38.205.196.78:37215 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->f254710a-b635-5081-8da5-952d324dd225 con 2d8fcd91-73d0-57a7-8a0c-0eba9c6682a1 130.72.200.230:80 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->2d8fcd91-73d0-57a7-8a0c-0eba9c6682a1 con f5e8577f-d799-5d22-b0e0-7d56f44214be 103.155.54.113:8888 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->f5e8577f-d799-5d22-b0e0-7d56f44214be con 53c8266b-db10-5ef1-ba8c-4c870ad531c0 119.156.139.222:81 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->53c8266b-db10-5ef1-ba8c-4c870ad531c0 con baac43b2-e629-584b-b8f5-d0aed5b58e6c 53.254.133.126:23 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->baac43b2-e629-584b-b8f5-d0aed5b58e6c con 72a914b5-1004-550e-9afe-6b6c9a03290f 212.52.5.249:80 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->72a914b5-1004-550e-9afe-6b6c9a03290f con 8ebba931-b746-5756-baf7-ed0d6e05ccae 153.243.161.41:8081 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->8ebba931-b746-5756-baf7-ed0d6e05ccae con d23ccc70-290f-56fe-ad1d-f450ae6e56b2 95.158.5.249:8080 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->d23ccc70-290f-56fe-ad1d-f450ae6e56b2 con b9a8c5dd-39b7-52af-9fe5-7972cf7eefd7 92.110.51.129:23 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->b9a8c5dd-39b7-52af-9fe5-7972cf7eefd7 con 22d48504-c16b-5c22-949b-e7d504362222 77.170.182.44:37215 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->22d48504-c16b-5c22-949b-e7d504362222 con 40570f8d-9f17-5193-baba-75124b3f003c 142.128.225.233:23 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->40570f8d-9f17-5193-baba-75124b3f003c con 38edeed8-bbf3-55c5-9f64-eeebaa63f29e 5.223.87.51:8080 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->38edeed8-bbf3-55c5-9f64-eeebaa63f29e con f4e2ed15-3381-5393-ad9b-edcd3b3c5452 80.63.151.240:22 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->f4e2ed15-3381-5393-ad9b-edcd3b3c5452 con 16958c17-98fc-586f-9668-d1df397fbd24 76.226.187.43:5000 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->16958c17-98fc-586f-9668-d1df397fbd24 con e769ab20-47d6-501b-b347-7764ab7f0600 14.99.65.97:80 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->e769ab20-47d6-501b-b347-7764ab7f0600 con be9fbff5-c43a-5e38-870a-f6eadcc6dc98 193.245.60.242:9527 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->be9fbff5-c43a-5e38-870a-f6eadcc6dc98 con 195a5e9f-d6a7-5ea5-a8b7-b48d4816dff1 144.175.176.144:37215 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->195a5e9f-d6a7-5ea5-a8b7-b48d4816dff1 con cc77ca2d-000a-55c9-8bc5-3cb911038063 169.241.123.242:22 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->cc77ca2d-000a-55c9-8bc5-3cb911038063 con 046a8a88-e3e5-5a63-9a17-13585b42d132 111.73.18.2:22 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->046a8a88-e3e5-5a63-9a17-13585b42d132 con c185114b-7f26-5c63-b1b1-61545d206979 186.59.37.44:8888 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->c185114b-7f26-5c63-b1b1-61545d206979 con 6567c6d2-b5cf-5fed-ae2b-0c542c545546 117.48.44.246:9527 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->6567c6d2-b5cf-5fed-ae2b-0c542c545546 con 51dd7b33-ccac-5b1b-ab71-af498841d65c 12.21.119.77:8080 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->51dd7b33-ccac-5b1b-ab71-af498841d65c con 00ff2988-c1cb-572a-8d28-d8d546cf844f 159.147.173.251:9527 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->00ff2988-c1cb-572a-8d28-d8d546cf844f con d6bc874e-2c00-5fe8-8167-a5bb5da6f25b 40.251.235.194:23 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->d6bc874e-2c00-5fe8-8167-a5bb5da6f25b con 80626922-1e53-5d1c-8d85-be993120d1a3 182.243.251.246:8080 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->80626922-1e53-5d1c-8d85-be993120d1a3 con e86bdfb0-78c0-521f-998f-c73060867dd2 59.30.21.86:23 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->e86bdfb0-78c0-521f-998f-c73060867dd2 con b6129fa8-43c4-527e-b596-b8656f0f76a9 213.177.160.243:37215 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->b6129fa8-43c4-527e-b596-b8656f0f76a9 con fa13cc12-f0ef-5aad-b971-501651f46584 123.42.105.18:9527 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->fa13cc12-f0ef-5aad-b971-501651f46584 con f75e3ebd-b7de-59d9-8f58-a322c19ccd94 107.250.131.66:9527 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->f75e3ebd-b7de-59d9-8f58-a322c19ccd94 con 789f1e8c-6dff-5c58-9364-b561657be70f 42.178.77.109:23 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->789f1e8c-6dff-5c58-9364-b561657be70f con a650e791-8bd1-599c-ac4d-0f94ae2665d2 41.116.168.90:5000 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->a650e791-8bd1-599c-ac4d-0f94ae2665d2 con a8455d40-5738-526d-a73e-37c331df28c1 120.195.238.15:8080 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->a8455d40-5738-526d-a73e-37c331df28c1 con f2e9c0ed-56ba-5e94-8e04-b28e17025087 40.64.64.61:37215 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->f2e9c0ed-56ba-5e94-8e04-b28e17025087 con 2ccb4807-6f1a-5c52-9369-c1c6ec88d572 64.57.132.220:23 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->2ccb4807-6f1a-5c52-9369-c1c6ec88d572 con e572d179-4be6-53d7-b774-e840aca0d3c6 119.204.4.90:9527 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->e572d179-4be6-53d7-b774-e840aca0d3c6 con d74c9e23-3b78-5f28-82c7-97cb09ebe3eb 142.39.197.151:8888 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->d74c9e23-3b78-5f28-82c7-97cb09ebe3eb con 9cc80ab4-6e67-5211-8a3c-31ab689b268d 64.144.12.241:37215 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->9cc80ab4-6e67-5211-8a3c-31ab689b268d con e3457d53-0f56-5ded-b0c7-78da62309891 185.128.38.177:9527 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->e3457d53-0f56-5ded-b0c7-78da62309891 con 4398cb7e-469c-5d32-8919-c0bf5c50e8cc 36.130.140.21:81 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->4398cb7e-469c-5d32-8919-c0bf5c50e8cc con 1afd223f-4703-5da5-965b-ee3733f551d6 213.187.49.150:81 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->1afd223f-4703-5da5-965b-ee3733f551d6 con 00c46d6a-cce4-5128-8779-508fa2fd9736 144.207.17.219:52869 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->00c46d6a-cce4-5128-8779-508fa2fd9736 con 5b0d3006-3df3-5771-b40c-6ebe8bbe2d86 154.54.223.40:5000 guuid=818e7cd0-1c00-0000-1801-7584780f0000 pid=3960->5b0d3006-3df3-5771-b40c-6ebe8bbe2d86 con guuid=31499ad0-1c00-0000-1801-75847a0f0000 pid=3962->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 540B b2255150-2060-5b7f-9786-12d5e647a020 84.201.5.31:12121 guuid=31499ad0-1c00-0000-1801-75847a0f0000 pid=3962->b2255150-2060-5b7f-9786-12d5e647a020 con
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
72 / 100
Signature
Connects to many ports of the same IP (likely port scanning)
Malicious sample detected (through community Yara rule)
Sample is packed with UPX
Uses dynamic DNS services
Uses known network protocols on non-standard ports
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1810089 Sample: morte.i686.elf Startdate: 07/11/2025 Architecture: LINUX Score: 72 30 mortex.duckdns.org 2->30 32 187.157.216.112, 37215 UninetSAdeCVMX Mexico 2->32 34 99 other IPs or domains 2->34 36 Malicious sample detected (through community Yara rule) 2->36 38 Yara detected Mirai 2->38 40 Connects to many ports of the same IP (likely port scanning) 2->40 44 2 other signatures 2->44 8 morte.i686.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        14 python3.8 dpkg 2->14         started        signatures3 42 Uses dynamic DNS services 30->42 process4 process5 16 morte.i686.elf 8->16         started        18 morte.i686.elf 8->18         started        20 morte.i686.elf 8->20         started        22 morte.i686.elf 8->22         started        process6 24 morte.i686.elf 16->24         started        26 morte.i686.elf 16->26         started        28 morte.i686.elf 16->28         started       
Threat name:
Linux.Backdoor.Mirai
Status:
Malicious
First seen:
2025-11-07 17:10:07 UTC
File Type:
ELF32 Little (Exe)
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
Enumerates running processes
Writes file to system bin folder
Modifies Watchdog functionality
Mirai
Mirai family
Verdict:
Malicious
Tags:
Unix.Dropper.Mirai-7135858-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 05d2d4be8bc03591f6461dcbf68cf8445fbb403fa4b4ea4f5435dc1dab5c9ab3

(this sample)

  
Delivery method
Distributed via web download

Comments