MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 380b7de626148b8730fbf456c9b11930ce1f6b56065aa90666176d4b161ce95c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 380b7de626148b8730fbf456c9b11930ce1f6b56065aa90666176d4b161ce95c
SHA3-384 hash: f8b1c0c630ebfcbcac2a86a8240e920f9b15012a120918a73981d3fc104368ed6678c2bc594bbf6d36f553b2151d56f6
SHA1 hash: 4a7bd5a6c9bedb63f4a74011218401424f4eb7b8
MD5 hash: 164b959e65ea2132a07e0ed573375239
humanhash: music-east-carbon-uranus
File name:mips
Download: download sample
Signature Mirai
File size:222'396 bytes
First seen:2025-11-24 06:20:34 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:TYKSKkcRW8y4iEaR6mjHN/kjAf44Ay3YKRpHmOaWNnzR7:TYfcRW8y4iEa8EN/kjA6cYSp7aWNz9
TLSH T1D024A51E6E228F6DF768873047B79E21975C33D636E1CA45E1ACC6101E6039E641FFA8
telfhash t100418f580e7807f0a3256c9d199dff7ad6a330db3e126c378e51e46aab69e834d10c0c
Magika elf
Reporter abuse_ch
Tags:elf mirai upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 7981a49164b986125277c2148e5e7c595dada33adce84cfb4e89ea5b757cb5da
File size (compressed) :62'944 bytes
File size (de-compressed) :222'396 bytes
Format:linux/mips
Packed file: 7981a49164b986125277c2148e5e7c595dada33adce84cfb4e89ea5b757cb5da

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2025-11-24T04:32:00Z UTC
Last seen:
2025-11-26T00:53:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=cc2cb685-1600-0000-e198-2774270f0000 pid=3879 /usr/bin/sudo guuid=a5596387-1600-0000-e198-2774330f0000 pid=3891 /tmp/sample.bin guuid=cc2cb685-1600-0000-e198-2774270f0000 pid=3879->guuid=a5596387-1600-0000-e198-2774330f0000 pid=3891 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1819761 Sample: mips.elf Startdate: 24/11/2025 Architecture: LINUX Score: 48 12 109.202.202.202, 80 INIT7CH Switzerland 2->12 14 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->14 16 2 other IPs or domains 2->16 18 Multi AV Scanner detection for submitted file 2->18 6 dash rm 2->6         started        8 dash rm 2->8         started        10 mips.elf 2->10         started        signatures3 process4
Threat name:
Linux.Backdoor.Mirai
Status:
Malicious
First seen:
2025-11-24 07:10:40 UTC
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai discovery
Behaviour
System Network Configuration Discovery
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-8041698-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 380b7de626148b8730fbf456c9b11930ce1f6b56065aa90666176d4b161ce95c

(this sample)

Comments