MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ab262e88806b529d522fadf1aa3e2ba1cd273ae1f93d784503bf2174f1965ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 3ab262e88806b529d522fadf1aa3e2ba1cd273ae1f93d784503bf2174f1965ea
SHA3-384 hash: d995bcc6d404a9525bf50123e516767577aa66196976d58cf83ff990c1bd17ddd1a697b21c0e7351bb86f943401b2bc4
SHA1 hash: 00a4f9f667088ad2561277629a6c86b67fd65c23
MD5 hash: 24f72427e3b60dc2e7b7941de1c02916
humanhash: bacon-diet-social-grey
File name:cutem68k
Download: download sample
Signature Mirai
File size:45'292 bytes
First seen:2025-06-18 10:40:50 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:lLVEANGEw0dEAOEwfbS9iVHPUEWmdB0abaI8elM60FxUjWBpTks7XMp47CZ2It:zEANGEw0dEAOEwfbSqPUEVDT82MDxUaQ
TLSH T1491319E6B400EC7CF82DD77F8467050EB131B75544D20A3563A3B9A7A87A2951C2FF89
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=57c9aa81-1e00-0000-f027-6f5d97080000 pid=2199 /usr/bin/sudo guuid=56f1a883-1e00-0000-f027-6f5d9e080000 pid=2206 /tmp/sample.bin guuid=57c9aa81-1e00-0000-f027-6f5d97080000 pid=2199->guuid=56f1a883-1e00-0000-f027-6f5d9e080000 pid=2206 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1717346 Sample: cutem68k.elf Startdate: 18/06/2025 Architecture: LINUX Score: 48 14 103.149.252.178, 53496, 5683 DVS-AS-VNVIETDIGITALTECHNOLOGYLIABILITYCOMPANYVN unknown 2->14 16 Multi AV Scanner detection for submitted file 2->16 8 cutem68k.elf 2->8         started        signatures3 process4 process5 10 cutem68k.elf 8->10         started        process6 12 cutem68k.elf 10->12         started       
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-06-18 10:42:48 UTC
File Type:
ELF32 Big (Exe)
AV detection:
15 of 23 (65.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-6981989-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 3ab262e88806b529d522fadf1aa3e2ba1cd273ae1f93d784503bf2174f1965ea

(this sample)

  
Delivery method
Distributed via web download

Comments