MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ab8fc8c4cebfdcb983f03dc1716b4ea8fb213691ad6b6527692953cc4377e74. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 2ab8fc8c4cebfdcb983f03dc1716b4ea8fb213691ad6b6527692953cc4377e74
SHA3-384 hash: bc145c84b12b7185fb142e58e2b6568ae33b1621d4e7cdf8293850e065adbf180831fe5a215ef480bf415c491217196c
SHA1 hash: 0099fd6d15b9b9e55d32b007258d970908108714
MD5 hash: ff2f05cde3244481fdbdde5ca88adddd
humanhash: kitten-coffee-kansas-purple
File name:dlr.x86_64
Download: download sample
Signature Mirai
File size:1'688 bytes
First seen:2025-12-06 07:28:35 UTC
Last seen:2025-12-06 09:24:13 UTC
File type: elf
MIME type:application/x-executable
ssdeep 24:GHOpHZAXmJSu2gdW20Amljh0aVxJwD6nujoxcozffTTqf:GH4ZYMk20AmJG8wD6usxLzXy
TLSH T13F313306EF1BB47CF81691FD896703F69E21B8EC23397642AE0959020C0A9E0189C491
telfhash t15aa00254b19938cc9fe7a4157b5efb2b60003a9d05123652c842c8f76d653bd7cd8514
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
3
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2025-12-06T06:30:00Z UTC
Last seen:
2025-12-06T15:51:00Z UTC
Hits:
~10
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Malicious sample detected (through community Yara rule)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1827869 Sample: dlr.x86_64.elf Startdate: 06/12/2025 Architecture: LINUX Score: 48 23 169.254.169.254, 80 USDOSUS Reserved 2->23 25 179.43.172.109, 2113, 35220, 58930 PLI-ASCH Panama 2->25 27 3 other IPs or domains 2->27 29 Malicious sample detected (through community Yara rule) 2->29 8 dlr.x86_64.elf Hari 2->8         started        signatures3 process4 file5 21 /tmp/Hari, ELF 8->21 dropped 11 Hari 8->11         started        process6 process7 13 Hari 11->13         started        15 Hari 11->15         started        17 Hari 11->17         started        19 1018 other processes 11->19
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-12-06 07:14:54 UTC
File Type:
ELF64 Little (Exe)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
linux
Behaviour
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 2ab8fc8c4cebfdcb983f03dc1716b4ea8fb213691ad6b6527692953cc4377e74

(this sample)

  
Delivery method
Distributed via web download

Comments