MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1110798a017996cb750eb4195ad9943b3fd053a680a5a2d4d6151166f1b35531. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 1110798a017996cb750eb4195ad9943b3fd053a680a5a2d4d6151166f1b35531
SHA3-384 hash: fc06b59321c1dc3066fae518388bcdd767955de9dd6a7bbf4b2210d12e76b2ac036b4580e2586af0bea2a2828c3a2e58
SHA1 hash: de6a3099b268411eaf5654942d2c70d3afc0f886
MD5 hash: 40a6b90657e2440afa563464c8167be4
humanhash: sweet-wyoming-floor-montana
File name:3atoNational.sh4
Download: download sample
Signature Mirai
File size:50'668 bytes
First seen:2025-12-02 03:30:57 UTC
Last seen:2025-12-02 06:23:56 UTC
File type: elf
MIME type:application/x-executable
ssdeep 768:Ca5oGwtR8WT5tRuRej8FriIkFsvKv5MJumtnnGCFodAEVC9:CaCGwtWx3T4v20mtnGpZVC9
TLSH T188337DB6C4E9BDB8D2049F74BD158A348B13A40086672EFEDA45C699C087DEDF2097F1
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
71
Origin country :
DE DE
Vendor Threat Intelligence
Malware configuration found for:
Mirai
Details
Mirai
a c2 socket address and a scan socket address
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
masquerade
Result
Gathering data
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-02 03:31:38 UTC
File Type:
ELF32 Little (Exe)
AV detection:
23 of 36 (63.89%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai linux
Verdict:
Malicious
Tags:
Unix.Dropper.Mirai-7135890-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 1110798a017996cb750eb4195ad9943b3fd053a680a5a2d4d6151166f1b35531

(this sample)

  
Delivery method
Distributed via web download

Comments