🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0dc7eeccc8ff047fb593c42e46fa9ca706f0ada25b779c1819a5dba946c7fb55. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 17 File information Comments

SHA256 hash: 0dc7eeccc8ff047fb593c42e46fa9ca706f0ada25b779c1819a5dba946c7fb55
SHA3-384 hash: c9feb1b4a58b45990f49b285a2d9d46d82244fce5612b8bb0f3830fc782f67ae166827305c517532e7baf2df99fa1498
SHA1 hash: 64ab0734849346a0ee167d08b295e8a4fa269bba
MD5 hash: 6d16e9a95800dce8ba2c474f1fd35068
humanhash: one-football-fruit-triple
File name:x86_64
Download: download sample
Signature Mirai
File size:615'624 bytes
First seen:2026-10-06 11:55:11 UTC
Last seen:2026-10-06 14:08:49 UTC
File type: elf
MIME type:application/x-executable
ssdeep 12288:VoKlsqf2bgeHSYUHveuPOBfOSD19h42s4WuEiLSMkvg/aYu:h88eHSYsPOnfKj4rLLSMkoiYu
TLSH T123D47E03FAF10475CC66CD74870F5723D7BAF44A6226A75B27C96B113E2AAA1AF1C710
telfhash t118d1ef0463e83f9a7ad0520363f1191b1c5b29e195dd0ece63a85fdb1daff422619836
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Manages services
Receives data from a server
Connection attempt
Changes access rights for a written file
Changes access rights for a file
Sets a written file as executable
Collects information on the RAM
Sends data to a server
Kills processes
Runs as daemon
Locks files
Creates directories in a system directory
Launching a process
Substitutes an application name
Writes files to system subdirectory
Creates or modifies files in /cron to set up autorun
Deletes a system binary file
Performs a bruteforce attack in the network
Creates or modifies files in /init.d to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Creates or modifies files to set up autorun
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
base64 expand lolbin
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
3
Number of processes launched:
3
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=061f5f46-1a00-0000-ecbd-8e7bec0b0000 pid=3052 /usr/bin/sudo guuid=a5c2864a-1a00-0000-ecbd-8e7bf20b0000 pid=3058 /tmp/sample.bin guuid=061f5f46-1a00-0000-ecbd-8e7bec0b0000 pid=3052->guuid=a5c2864a-1a00-0000-ecbd-8e7bf20b0000 pid=3058 execve guuid=5c4ed94a-1a00-0000-ecbd-8e7bf30b0000 pid=3059 /tmp/sample.bin zombie guuid=a5c2864a-1a00-0000-ecbd-8e7bf20b0000 pid=3058->guuid=5c4ed94a-1a00-0000-ecbd-8e7bf30b0000 pid=3059 clone guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3060 /tmp/sample.bin net send-data write-file zombie guuid=5c4ed94a-1a00-0000-ecbd-8e7bf30b0000 pid=3059->guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3060 clone 501abe1d-66af-5ba2-8ec4-a7a0e878512c 45.144.52.239:9111 guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3060->501abe1d-66af-5ba2-8ec4-a7a0e878512c send: 715B guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3061 /tmp/sample.bin guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3060->guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3061 clone guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3062 /tmp/sample.bin guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3060->guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3062 clone guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063 /tmp/sample.bin send-data write-config write-file zombie guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3060->guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063 clone guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3710 /tmp/sample.bin guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3060->guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3710 clone b82cac6a-c7b5-5e3f-9205-e71cca0c8a43 1.1.1.1:80 guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063->b82cac6a-c7b5-5e3f-9205-e71cca0c8a43 send: 1148000B c6d405c3-1fcc-5424-8b02-6750d921b602 1.0.0.1:80 guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063->c6d405c3-1fcc-5424-8b02-6750d921b602 send: 1148000B 51475a40-5531-5652-88be-7dda12342b64 8.8.8.8:80 guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063->51475a40-5531-5652-88be-7dda12342b64 send: 1146600B 5698d2eb-c4cd-5579-9cfa-b0fa477ec808 8.8.4.4:80 guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063->5698d2eb-c4cd-5579-9cfa-b0fa477ec808 send: 1146600B 4ef87a6a-c78e-5d03-9a21-74e118b8935c 9.9.9.9:80 guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063->4ef87a6a-c78e-5d03-9a21-74e118b8935c send: 1146600B guuid=5ee04b4a-1b00-0000-ecbd-8e7b3d0d0000 pid=3389 /tmp/sample.bin net net-scan send-data guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063->guuid=5ee04b4a-1b00-0000-ecbd-8e7b3d0d0000 pid=3389 clone guuid=7116514a-1b00-0000-ecbd-8e7b3e0d0000 pid=3390 /tmp/sample.bin net send-data guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063->guuid=7116514a-1b00-0000-ecbd-8e7b3e0d0000 pid=3390 clone guuid=9c8afb4b-1b00-0000-ecbd-8e7b3f0d0000 pid=3391 /usr/bin/dash guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063->guuid=9c8afb4b-1b00-0000-ecbd-8e7b3f0d0000 pid=3391 execve guuid=e07beaa0-1b00-0000-ecbd-8e7bd00d0000 pid=3536 /usr/bin/dash guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063->guuid=e07beaa0-1b00-0000-ecbd-8e7bd00d0000 pid=3536 execve guuid=b3660da5-1b00-0000-ecbd-8e7bde0d0000 pid=3550 /usr/bin/dash guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063->guuid=b3660da5-1b00-0000-ecbd-8e7bde0d0000 pid=3550 execve guuid=b4cb29fd-1b00-0000-ecbd-8e7b780e0000 pid=3704 /usr/bin/dash guuid=df4d2c4b-1a00-0000-ecbd-8e7bf40b0000 pid=3063->guuid=b4cb29fd-1b00-0000-ecbd-8e7b780e0000 pid=3704 execve guuid=5ee04b4a-1b00-0000-ecbd-8e7b3d0d0000 pid=3389|network network activity to 383 IP addresses review logs to see them all guuid=5ee04b4a-1b00-0000-ecbd-8e7b3d0d0000 pid=3389->guuid=5ee04b4a-1b00-0000-ecbd-8e7b3d0d0000 pid=3389|network network guuid=51c7425a-1b00-0000-ecbd-8e7b530d0000 pid=3411 /tmp/sample.bin net send-data guuid=5ee04b4a-1b00-0000-ecbd-8e7b3d0d0000 pid=3389->guuid=51c7425a-1b00-0000-ecbd-8e7b530d0000 pid=3411 clone 4a91f619-dc1d-5f0e-a860-23a595541440 45.144.52.239:80 guuid=7116514a-1b00-0000-ecbd-8e7b3e0d0000 pid=3390->4a91f619-dc1d-5f0e-a860-23a595541440 send: 72B 7eb0e2b2-488d-5444-b6cf-712c13c2fcbf 81.102.128.230:22 guuid=7116514a-1b00-0000-ecbd-8e7b3e0d0000 pid=3390->7eb0e2b2-488d-5444-b6cf-712c13c2fcbf con 4389c018-6ded-582a-9bb9-9d9e18e1888f 78.102.70.160:22 guuid=7116514a-1b00-0000-ecbd-8e7b3e0d0000 pid=3390->4389c018-6ded-582a-9bb9-9d9e18e1888f con 49861bdf-0edc-5a39-af23-1dc6d60a7053 110.102.119.47:2222 guuid=7116514a-1b00-0000-ecbd-8e7b3e0d0000 pid=3390->49861bdf-0edc-5a39-af23-1dc6d60a7053 con 2676b95d-66b1-507f-a8c6-029a8648850e 106.102.13.4:2222 guuid=7116514a-1b00-0000-ecbd-8e7b3e0d0000 pid=3390->2676b95d-66b1-507f-a8c6-029a8648850e con guuid=ddb2b74e-1b00-0000-ecbd-8e7b420d0000 pid=3394 /tmp/sample.bin net send-data guuid=7116514a-1b00-0000-ecbd-8e7b3e0d0000 pid=3390->guuid=ddb2b74e-1b00-0000-ecbd-8e7b420d0000 pid=3394 clone guuid=9c98e34c-1b00-0000-ecbd-8e7b400d0000 pid=3392 /usr/bin/systemctl guuid=9c8afb4b-1b00-0000-ecbd-8e7b3f0d0000 pid=3391->guuid=9c98e34c-1b00-0000-ecbd-8e7b400d0000 pid=3392 execve a8d024af-0a0f-50bf-9c26-bd70e8a29a75 45.144.52.239:48101 guuid=ddb2b74e-1b00-0000-ecbd-8e7b420d0000 pid=3394->a8d024af-0a0f-50bf-9c26-bd70e8a29a75 send: 90B guuid=51c7425a-1b00-0000-ecbd-8e7b530d0000 pid=3411->a8d024af-0a0f-50bf-9c26-bd70e8a29a75 send: 90B guuid=57612da1-1b00-0000-ecbd-8e7bd10d0000 pid=3537 /usr/bin/systemctl guuid=e07beaa0-1b00-0000-ecbd-8e7bd00d0000 pid=3536->guuid=57612da1-1b00-0000-ecbd-8e7bd10d0000 pid=3537 execve guuid=2fdaba13-0000-0000-ecbd-8e7b01000000 pid=1 /usr/lib/systemd/systemd guuid=b57fc2a2-1b00-0000-ecbd-8e7bd60d0000 pid=3542 /usr/lib/.cache/.svc-mon write-file guuid=2fdaba13-0000-0000-ecbd-8e7b01000000 pid=1->guuid=b57fc2a2-1b00-0000-ecbd-8e7bd60d0000 pid=3542 execve guuid=b10cce01-1e00-0000-ecbd-8e7b4a130000 pid=4938 /usr/lib/.cache/.svc-mon write-file guuid=2fdaba13-0000-0000-ecbd-8e7b01000000 pid=1->guuid=b10cce01-1e00-0000-ecbd-8e7b4a130000 pid=4938 execve guuid=9f6b876a-2000-0000-ecbd-8e7b52130000 pid=4946 /usr/lib/.cache/.svc-mon write-file guuid=2fdaba13-0000-0000-ecbd-8e7b01000000 pid=1->guuid=9f6b876a-2000-0000-ecbd-8e7b52130000 pid=4946 execve guuid=b96070d5-2200-0000-ecbd-8e7b73130000 pid=4979 /usr/lib/.cache/.svc-mon write-file guuid=2fdaba13-0000-0000-ecbd-8e7b01000000 pid=1->guuid=b96070d5-2200-0000-ecbd-8e7b73130000 pid=4979 execve guuid=978a6238-2500-0000-ecbd-8e7b75130000 pid=4981 /usr/lib/.cache/.svc-mon write-file guuid=2fdaba13-0000-0000-ecbd-8e7b01000000 pid=1->guuid=978a6238-2500-0000-ecbd-8e7b75130000 pid=4981 execve guuid=0c2fe69b-2700-0000-ecbd-8e7b77130000 pid=4983 /usr/lib/.cache/.svc-mon write-file guuid=2fdaba13-0000-0000-ecbd-8e7b01000000 pid=1->guuid=0c2fe69b-2700-0000-ecbd-8e7b77130000 pid=4983 execve guuid=626740a5-1b00-0000-ecbd-8e7bdf0d0000 pid=3551 /usr/sbin/update-rc.d guuid=b3660da5-1b00-0000-ecbd-8e7bde0d0000 pid=3550->guuid=626740a5-1b00-0000-ecbd-8e7bdf0d0000 pid=3551 execve guuid=9590f2a6-1b00-0000-ecbd-8e7be70d0000 pid=3559 /usr/bin/systemctl guuid=626740a5-1b00-0000-ecbd-8e7bdf0d0000 pid=3551->guuid=9590f2a6-1b00-0000-ecbd-8e7be70d0000 pid=3559 execve
Threat name:
Linux.Network.Generic
Status:
Suspicious
First seen:
2026-10-06 11:55:39 UTC
File Type:
ELF64 Little (Exe)
AV detection:
6 of 36 (16.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
command_and_control credential_access defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Changes its process name
Reads system network configuration
Modifies Bash startup script
Reads process memory
Creates/modifies Cron job
Creates/modifies environment variables
Enumerates running processes
Modifies init.d
Modifies rc script
Modifies systemd
Reads MAC address of network interface
Reads system routing table
Outbound SSH connection to public host
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:ELF_Packer_Dropper_Fileless_Armhf
Author:Serhii Kocherhan
Description:Detects obfuscated Linux ELF packers/droppers featuring ChaCha20/RC4 decryption, memfd_create/execveat fileless execution capabilities, and unique binary artifacts.
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:golang
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:LIN_Malware_Unknown_ForgeAuto_43efb4f0
Author:Marjoriefort
Description:Detects Unknown (elf, etat binaire)
Rule name:LIN_Malware_Unknown_ForgeAuto_7213850f
Author:Marjoriefort
Description:Detects Unknown (elf, etat binaire)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NSVPS_Hydra_SSH_Bruteforce
Author:sanad (NSVPS-SOC)
Description:Hydra SSH brute-force campaign credentials pattern from NSVPS honeypot
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 0dc7eeccc8ff047fb593c42e46fa9ca706f0ada25b779c1819a5dba946c7fb55

(this sample)

  
Delivery method
Distributed via web download

Comments