MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 48ed7fab3ca6d26f4b0eec19e53ebb3f63a45cdc99ec0257b8c9824e1078dce3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 48ed7fab3ca6d26f4b0eec19e53ebb3f63a45cdc99ec0257b8c9824e1078dce3
SHA3-384 hash: 001219a85733458ae3d9a7a30abb63dcacba247d1792cc57b4f97e5d7220b98a125913e729bddfc3587dabb0ae0252be
SHA1 hash: 047587c7b5482c5d99da74ce11346864d0bd66e2
MD5 hash: a927ac6b743832242ce7d175ae0646d1
humanhash: green-violet-island-vegan
File name:fentppc
Download: download sample
Signature Mirai
File size:46'784 bytes
First seen:2026-01-10 13:27:57 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:rpdMOjLbb0mPBrjyRIHEJo9ZHtjROjAeOgoKxm1L:4PcysD9voOgP6
TLSH T1DD232901323C0E5BC5A256742A3F06E483FFFA9521E4BB84654FAB4B8635E760586FCD
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Runs as daemon
Receives data from a server
Opens a port
Sends data to a server
Connection attempt
Substitutes an application name
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2026-01-10T15:33:00Z UTC
Last seen:
2026-01-10T16:41:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=7307c42f-1b00-0000-1558-50061e0b0000 pid=2846 /usr/bin/sudo guuid=ef475932-1b00-0000-1558-5006220b0000 pid=2850 /tmp/sample.bin guuid=7307c42f-1b00-0000-1558-50061e0b0000 pid=2846->guuid=ef475932-1b00-0000-1558-5006220b0000 pid=2850 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1847928 Sample: fentppc.elf Startdate: 10/01/2026 Architecture: LINUX Score: 48 18 87.121.112.123, 53410, 666 NETERRA-ASBG Bulgaria 2->18 20 109.202.202.202, 80 INIT7CH Switzerland 2->20 22 2 other IPs or domains 2->22 24 Multi AV Scanner detection for submitted file 2->24 8 fentppc.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 fentppc.elf 8->14         started        process6 16 fentppc.elf 14->16         started       
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-01-10 13:28:33 UTC
File Type:
ELF32 Big (Exe)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Verdict:
Malicious
Tags:
Unix.Dropper.Mirai-7135957-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 48ed7fab3ca6d26f4b0eec19e53ebb3f63a45cdc99ec0257b8c9824e1078dce3

(this sample)

  
Delivery method
Distributed via web download

Comments