MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0686b544552fe48cee8b3dca8cd397fd43f066b548c6fb5fb7942a8f3ae487ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 8 File information Comments

SHA256 hash: 0686b544552fe48cee8b3dca8cd397fd43f066b548c6fb5fb7942a8f3ae487ed
SHA3-384 hash: fa5a8c8c2e0eba146afda0ed0c90e26979841010c45212e67f13188e1a47cd73c5d8b1eefc06b9fe272a86792743c317
SHA1 hash: bb43f0f9c5c23982bd954399cb4c7479bcc0547a
MD5 hash: ce4679f696cc9425d1910c2c01b147bd
humanhash: india-oregon-florida-delta
File name:mips
Download: download sample
Signature Mirai
File size:197'348 bytes
First seen:2026-08-10 19:56:31 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:EsynaW6hmKOBhgB6WfQxsKjFZQkdv/QM/mskXwmw2oIPYn3wHjM2:Es6aW6hmKEC6+QfFGU3sXnfzPY3c1
TLSH T19E14961A6E228F7EF278C73447B74A34975D23D627E1D684D2ACC1141F6029E681FFA8
telfhash t12541a71c0d7817b0a6355c5d05ddfb66d6a331da7e266c338f61e86aab68b839e10c0c
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Kills processes
Deletes a file
Launching a process
Manages services
Runs as daemon
Creating a file
Substitutes an application name
Writes files to system directory
Writes files to system subdirectory
Writes symbolic links to system subdirectory
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
mirai
Status:
terminated
Behavior Graph:
%3 guuid=6e5400cf-1700-0000-4d9e-dc22400a0000 pid=2624 /usr/bin/sudo guuid=beb2fdd0-1700-0000-4d9e-dc22440a0000 pid=2628 /tmp/sample.bin guuid=6e5400cf-1700-0000-4d9e-dc22400a0000 pid=2624->guuid=beb2fdd0-1700-0000-4d9e-dc22440a0000 pid=2628 execve guuid=02cfc8d2-1700-0000-4d9e-dc224a0a0000 pid=2634 /usr/bin/dash guuid=beb2fdd0-1700-0000-4d9e-dc22440a0000 pid=2628->guuid=02cfc8d2-1700-0000-4d9e-dc224a0a0000 pid=2634 clone guuid=3e8deed2-1700-0000-4d9e-dc224b0a0000 pid=2635 /usr/bin/dash guuid=beb2fdd0-1700-0000-4d9e-dc22440a0000 pid=2628->guuid=3e8deed2-1700-0000-4d9e-dc224b0a0000 pid=2635 clone guuid=39e003d3-1700-0000-4d9e-dc224d0a0000 pid=2637 /usr/bin/dash guuid=beb2fdd0-1700-0000-4d9e-dc22440a0000 pid=2628->guuid=39e003d3-1700-0000-4d9e-dc224d0a0000 pid=2637 clone
Threat name:
Linux.Backdoor.Mirai
Status:
Malicious
First seen:
2026-08-10 19:57:36 UTC
File Type:
ELF32 Big (Exe)
AV detection:
10 of 36 (27.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_Mirai
Author:NDA0E
Description:Detects multiple Mirai variants
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:has_telegram_urls
Author:Aaron DeVera<aaron@backchannel.re>
Description:Detects Telegram URLs
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:test_rule_vldslv
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
Rule name:virustotal
Author:Tracel

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 0686b544552fe48cee8b3dca8cd397fd43f066b548c6fb5fb7942a8f3ae487ed

(this sample)

  
Delivery method
Distributed via web download

Comments