MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 21f294719163d195e423dc5b81d440238e7d41ad0ef0ce634fe83d450414afca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 21f294719163d195e423dc5b81d440238e7d41ad0ef0ce634fe83d450414afca
SHA3-384 hash: 651579b6c51f170cab8397f642a2afdbc980e8a4f1b0023699e54c6690c2c7135a64d4ddbbc582ddfb157ccb9d2d4985
SHA1 hash: 7c1244fbc56ef2c81ad18a9c2fb4036b8b3661f6
MD5 hash: b44752474dbdd570cdf338dc057c65df
humanhash: magnesium-lamp-four-oxygen
File name:agetty
Download: download sample
Signature Mirai
File size:108'048 bytes
First seen:2025-07-17 23:54:00 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:fFGtuAdRAtedI47oOqVjadDSOltp/SYM5BJtvQ3GT/s6:fFtC0edI4sOqV+dD1D/SY862T7
TLSH T1A9B35C22FA66092BC4D4657A61F34330F1F3539A14788A1B7EA30E8DBF246443567BF6
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
22
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated
Status:
terminated
Behavior Graph:
%3 guuid=d612f362-1600-0000-6f27-63e83d0d0000 pid=3389 /usr/bin/sudo guuid=204ff864-1600-0000-6f27-63e8440d0000 pid=3396 /tmp/sample.bin guuid=d612f362-1600-0000-6f27-63e83d0d0000 pid=3389->guuid=204ff864-1600-0000-6f27-63e8440d0000 pid=3396 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
56 / 100
Signature
Connects to many ports of the same IP (likely port scanning)
Multi AV Scanner detection for submitted file
Terminates several processes with shell command 'killall'
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1739272 Sample: agetty.elf Startdate: 18/07/2025 Architecture: LINUX Score: 56 46 64.55.3.119 XO-AS15US United States 2->46 48 65.47.21.93 XO-AS15US United States 2->48 50 99 other IPs or domains 2->50 52 Multi AV Scanner detection for submitted file 2->52 54 Connects to many ports of the same IP (likely port scanning) 2->54 9 agetty.elf 2->9         started        11 xfce4-session xfwm4 2->11         started        13 xfce4-session xfwm4 2->13         started        15 5 other processes 2->15 signatures3 process4 process5 17 agetty.elf 9->17         started        19 agetty.elf 9->19         started        21 agetty.elf 9->21         started        process6 23 agetty.elf sh 17->23         started        25 agetty.elf sh 17->25         started        27 agetty.elf sh 17->27         started        29 509 other processes 17->29 process7 31 sh killall 23->31         started        34 sh killall 25->34         started        36 sh killall 27->36         started        38 sh killall 29->38         started        40 sh killall 29->40         started        42 sh killall 29->42         started        44 143 other processes 29->44 signatures8 56 Terminates several processes with shell command 'killall' 31->56
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-07-17 23:54:18 UTC
File Type:
ELF32 Big (Exe)
AV detection:
20 of 38 (52.63%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 21f294719163d195e423dc5b81d440238e7d41ad0ef0ce634fe83d450414afca

(this sample)

  
Delivery method
Distributed via web download

Comments