MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 27b1bcad149875ad7993ccf5c36a9f73d1587971ed28b09e1852e578de3eb49b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 27b1bcad149875ad7993ccf5c36a9f73d1587971ed28b09e1852e578de3eb49b
SHA3-384 hash: ade2e31c14429076f4c909c152c48ed945db67ebeead9236ed645edb38c643d88ef792c325649007f828ee330e3c0539
SHA1 hash: ba510f41055e7b0cf24496a02e651d1b4cd003ff
MD5 hash: 24c629f42fc92fb23ae9ffb70ba16a5d
humanhash: stairway-music-jig-blue
File name:katrina
Download: download sample
Signature Mirai
File size:106'144 bytes
First seen:2025-07-18 05:24:57 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:1JDveimCMtOJ80GmQmqsqWRs1gywN3oforr4Rc/XOJ:1JDvtmGJ84uYHyw9ofo/4cOJ
TLSH T163A34CC7F900DEBDF809D77644574906B130A3A20E921A737257396BFE3A0981977F8A
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
21
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated
Status:
terminated
Behavior Graph:
%3 guuid=ff7398db-1900-0000-4da9-b7620d0a0000 pid=2573 /usr/bin/sudo guuid=bde8b2df-1900-0000-4da9-b762190a0000 pid=2585 /tmp/sample.bin guuid=ff7398db-1900-0000-4da9-b7620d0a0000 pid=2573->guuid=bde8b2df-1900-0000-4da9-b762190a0000 pid=2585 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
56 / 100
Signature
Connects to many ports of the same IP (likely port scanning)
Multi AV Scanner detection for submitted file
Terminates several processes with shell command 'killall'
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1739344 Sample: katrina.elf Startdate: 18/07/2025 Architecture: LINUX Score: 56 47 45.173.189.216 WILLYNETPROVEDORBR Brazil 2->47 49 209.203.43.192 Vox-TelecomZA South Africa 2->49 51 98 other IPs or domains 2->51 55 Multi AV Scanner detection for submitted file 2->55 57 Connects to many ports of the same IP (likely port scanning) 2->57 10 dash rm katrina.elf 2->10         started        12 dash rm 2->12         started        14 dash cat 2->14         started        16 7 other processes 2->16 signatures3 process4 process5 18 katrina.elf 10->18         started        process6 20 katrina.elf 18->20         started        22 katrina.elf 18->22         started        process7 24 katrina.elf sh 20->24         started        26 katrina.elf sh 20->26         started        28 katrina.elf sh 20->28         started        30 78 other processes 20->30 process8 32 sh killall 24->32         started        35 sh killall 26->35         started        37 sh killall 28->37         started        39 sh killall 30->39         started        41 sh killall 30->41         started        43 sh killall 30->43         started        45 75 other processes 30->45 signatures9 53 Terminates several processes with shell command 'killall' 32->53
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-07-18 05:25:15 UTC
File Type:
ELF32 Big (Exe)
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:kyton linux
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-6981989-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 27b1bcad149875ad7993ccf5c36a9f73d1587971ed28b09e1852e578de3eb49b

(this sample)

  
Delivery method
Distributed via web download

Comments