MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0851b040a2284df51949fa24ffc1bddea5a5b0ad4385e472585dcaed3322ad88. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 0851b040a2284df51949fa24ffc1bddea5a5b0ad4385e472585dcaed3322ad88
SHA3-384 hash: 9ba2e192b992d204dcb7a6a4daa13ed655f59805ef55e4c955372e0dd3741877ab1693b348243949405b43afec94888e
SHA1 hash: 60ec66fd39b6fbcd2a18dbe67628b5c353453637
MD5 hash: cbda2a87b60a889ee5f15c96637924ee
humanhash: nine-stairway-fourteen-black
File name:sh4
Download: download sample
Signature Mirai
File size:30'784 bytes
First seen:2025-07-09 20:13:56 UTC
Last seen:2025-07-10 21:41:36 UTC
File type: elf
MIME type:application/x-executable
ssdeep 768:bIKymb+IavkoVgqYTwCIyX7FoJWadCh31:bP+IavkombwCIyX7KwmCh3
TLSH T16CD26CA2CD2E1E58E15D93B97150CE7C6353D428A6975FFA161BCA344083ECCFA1A3B4
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
21
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=4d4fc610-1900-0000-6434-db3699110000 pid=4505 /usr/bin/sudo guuid=fce9e012-1900-0000-6434-db36a3110000 pid=4515 /tmp/sample.bin guuid=4d4fc610-1900-0000-6434-db3699110000 pid=4505->guuid=fce9e012-1900-0000-6434-db36a3110000 pid=4515 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-07-09 20:14:27 UTC
File Type:
ELF32 Little (Exe)
AV detection:
14 of 38 (36.84%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-7138377-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 0851b040a2284df51949fa24ffc1bddea5a5b0ad4385e472585dcaed3322ad88

(this sample)

  
Delivery method
Distributed via web download

Comments