MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ef7006421ee8db847999dbadff35e804e9706b241a7c0b2364503c6eaee0326. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 12


Intelligence 12 IOCs YARA 10 File information Comments

SHA256 hash: 2ef7006421ee8db847999dbadff35e804e9706b241a7c0b2364503c6eaee0326
SHA3-384 hash: 67ad01097c10ba49dbbd4e86521ae55d8d03ac7d97c9bb49974bb54225f7235b0603553381967c9bffbbce097dcd02ba
SHA1 hash: 430cac25534a33ba3859c6b5892dc283c10f5f58
MD5 hash: fa58ec961098aa1e7da905aebdf75225
humanhash: five-asparagus-wolfram-nebraska
File name:Akhenaton3ATOx64
Download: download sample
Signature Mirai
File size:41'984 bytes
First seen:2025-07-29 06:42:34 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:lVu2eCac5mcXmviroq2gNcTVXtzPz9T57aJI7yIk:62Fac5mcXproqPuTJt7hT57t2I
TLSH T1E2131A17B94184FCC089C234577AB53ED92B71BE0239B3EA37D4FB266AC9E611E1D804
telfhash t19601a2f27d2a0c55b1e7f016b79ae1514c380d1120d036f6e6b179ea9b19f415771c3b
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
26
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
android mirai
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
4
Number of processes launched:
12
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Process Renaming
Botnet C2s
TCP botnet C2(s):
type:Mirai 45.135.194.13:34711
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=45eeadd9-1a00-0000-012a-7d49e6090000 pid=2534 /usr/bin/sudo guuid=797134dd-1a00-0000-012a-7d49ee090000 pid=2542 /tmp/sample.bin net guuid=45eeadd9-1a00-0000-012a-7d49e6090000 pid=2534->guuid=797134dd-1a00-0000-012a-7d49ee090000 pid=2542 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=797134dd-1a00-0000-012a-7d49ee090000 pid=2542->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=548860dd-1a00-0000-012a-7d49ef090000 pid=2543 /tmp/sample.bin zombie guuid=797134dd-1a00-0000-012a-7d49ee090000 pid=2542->guuid=548860dd-1a00-0000-012a-7d49ef090000 pid=2543 clone guuid=c50664dd-1a00-0000-012a-7d49f0090000 pid=2544 /tmp/sample.bin zombie guuid=797134dd-1a00-0000-012a-7d49ee090000 pid=2542->guuid=c50664dd-1a00-0000-012a-7d49f0090000 pid=2544 clone guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545 /tmp/sample.bin net send-data zombie guuid=797134dd-1a00-0000-012a-7d49ee090000 pid=2542->guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545 clone guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8065ac23-a9b1-5cd7-b7c5-35b0acf50b7b 45.135.194.13:34711 guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545->8065ac23-a9b1-5cd7-b7c5-35b0acf50b7b send: 9B guuid=c24278dd-1a00-0000-012a-7d49f2090000 pid=2546 /tmp/sample.bin guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545->guuid=c24278dd-1a00-0000-012a-7d49f2090000 pid=2546 clone guuid=52617add-1a00-0000-012a-7d49f3090000 pid=2547 /tmp/sample.bin guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545->guuid=52617add-1a00-0000-012a-7d49f3090000 pid=2547 clone guuid=8eaf653f-1f00-0000-012a-7d4971140000 pid=5233 /tmp/sample.bin net send-data guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545->guuid=8eaf653f-1f00-0000-012a-7d4971140000 pid=5233 clone guuid=a745e045-1f00-0000-012a-7d4973140000 pid=5235 /tmp/sample.bin net send-data guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545->guuid=a745e045-1f00-0000-012a-7d4973140000 pid=5235 clone guuid=a6c8014e-1f00-0000-012a-7d4975140000 pid=5237 /tmp/sample.bin net send-data guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545->guuid=a6c8014e-1f00-0000-012a-7d4975140000 pid=5237 clone guuid=ec2bdc00-2100-0000-012a-7d497e140000 pid=5246 /tmp/sample.bin net send-data guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545->guuid=ec2bdc00-2100-0000-012a-7d497e140000 pid=5246 clone guuid=5c3c1402-2100-0000-012a-7d497f140000 pid=5247 /tmp/sample.bin net send-data guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545->guuid=5c3c1402-2100-0000-012a-7d497f140000 pid=5247 clone guuid=d8610903-2100-0000-012a-7d4981140000 pid=5249 /tmp/sample.bin net send-data guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545->guuid=d8610903-2100-0000-012a-7d4981140000 pid=5249 clone guuid=2e726905-2100-0000-012a-7d4984140000 pid=5252 /tmp/sample.bin net send-data guuid=4be866dd-1a00-0000-012a-7d49f1090000 pid=2545->guuid=2e726905-2100-0000-012a-7d4984140000 pid=5252 clone 86c2ad65-94b0-5354-8aa4-9e5580305e11 61.134.65.211:80 guuid=8eaf653f-1f00-0000-012a-7d4971140000 pid=5233->86c2ad65-94b0-5354-8aa4-9e5580305e11 send: 2097664B guuid=9a62713f-1f00-0000-012a-7d4972140000 pid=5234 /tmp/sample.bin guuid=8eaf653f-1f00-0000-012a-7d4971140000 pid=5233->guuid=9a62713f-1f00-0000-012a-7d4972140000 pid=5234 clone guuid=a745e045-1f00-0000-012a-7d4973140000 pid=5235->86c2ad65-94b0-5354-8aa4-9e5580305e11 send: 2097664B guuid=622de845-1f00-0000-012a-7d4974140000 pid=5236 /tmp/sample.bin guuid=a745e045-1f00-0000-012a-7d4973140000 pid=5235->guuid=622de845-1f00-0000-012a-7d4974140000 pid=5236 clone guuid=a6c8014e-1f00-0000-012a-7d4975140000 pid=5237->86c2ad65-94b0-5354-8aa4-9e5580305e11 send: 2097664B guuid=d46b794e-1f00-0000-012a-7d4976140000 pid=5238 /tmp/sample.bin guuid=a6c8014e-1f00-0000-012a-7d4975140000 pid=5237->guuid=d46b794e-1f00-0000-012a-7d4976140000 pid=5238 clone d261297f-8f57-53d5-b49a-a1d84721088a 173.2.180.183:6672 guuid=ec2bdc00-2100-0000-012a-7d497e140000 pid=5246->d261297f-8f57-53d5-b49a-a1d84721088a send: 2097664B guuid=6b2cfe03-2100-0000-012a-7d4983140000 pid=5251 /tmp/sample.bin guuid=ec2bdc00-2100-0000-012a-7d497e140000 pid=5246->guuid=6b2cfe03-2100-0000-012a-7d4983140000 pid=5251 clone guuid=5c3c1402-2100-0000-012a-7d497f140000 pid=5247->d261297f-8f57-53d5-b49a-a1d84721088a send: 2097664B guuid=28500903-2100-0000-012a-7d4980140000 pid=5248 /tmp/sample.bin guuid=5c3c1402-2100-0000-012a-7d497f140000 pid=5247->guuid=28500903-2100-0000-012a-7d4980140000 pid=5248 clone guuid=d8610903-2100-0000-012a-7d4981140000 pid=5249->d261297f-8f57-53d5-b49a-a1d84721088a send: 2097664B guuid=d9828403-2100-0000-012a-7d4982140000 pid=5250 /tmp/sample.bin guuid=d8610903-2100-0000-012a-7d4981140000 pid=5249->guuid=d9828403-2100-0000-012a-7d4982140000 pid=5250 clone guuid=2e726905-2100-0000-012a-7d4984140000 pid=5252->d261297f-8f57-53d5-b49a-a1d84721088a send: 2097664B guuid=cc733a06-2100-0000-012a-7d4985140000 pid=5253 /tmp/sample.bin guuid=2e726905-2100-0000-012a-7d4984140000 pid=5252->guuid=cc733a06-2100-0000-012a-7d4985140000 pid=5253 clone
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-07-29 01:15:50 UTC
File Type:
ELF64 Little (Exe)
AV detection:
26 of 38 (68.42%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari linux
Malware Config
C2 Extraction:
newageofkifirempire.camdvr.org
Verdict:
Malicious
Tags:
trojan gafgyt mirai Unix.Dropper.Mirai-7135890-0
YARA:
Linux_Trojan_Gafgyt_9e9530a7 Linux_Trojan_Gafgyt_807911a2 Linux_Trojan_Gafgyt_d4227dbf Linux_Trojan_Gafgyt_620087b9 Linux_Trojan_Gafgyt_33b4111a Linux_Trojan_Mirai_520deeb8 Linux_Trojan_Mirai_6a77af0f Linux_Trojan_Mirai_01e4a728 Linux_Trojan_Mirai_e0cf29e2
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_01e4a728
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_520deeb8
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_6a77af0f
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_e0cf29e2
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 2ef7006421ee8db847999dbadff35e804e9706b241a7c0b2364503c6eaee0326

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh

Comments