MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a8af19872a460ed85df7e9d13dc5c4344b03cd67fb8c507a18654f4202b3d78. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 4a8af19872a460ed85df7e9d13dc5c4344b03cd67fb8c507a18654f4202b3d78
SHA3-384 hash: ba18092726a8442ae0dde29e66277d2455a42ff2db1bc1b87076cac495febf48994bbb0a12b936f39d90c26b0da2ce08
SHA1 hash: 787b2fd1e6ef77da6fd78552852c861c635703ff
MD5 hash: 55f6ac7d0e65b78273d70443186bb623
humanhash: west-jersey-bulldog-sixteen
File name:dlr.mipsel
Download: download sample
Signature Mirai
File size:2'844 bytes
First seen:2025-12-06 07:28:31 UTC
Last seen:2025-12-06 09:24:08 UTC
File type: elf
MIME type:application/x-executable
ssdeep 48:/ETnBEx02WsDqWcmmzpsoiASJbdNXawZ/0X1rz9syyn8s:/InBE0s+W+zps4SJxNXai8XxRsyyn8
TLSH T1D55103A91FA0393FDE2ADD370519DB5923DC901F92AA6F466324E9007D0B7486BC389C
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
3
# of downloads :
75
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2025-12-06T06:38:00Z UTC
Last seen:
2025-12-07T01:41:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1827872 Sample: dlr.mipsel.elf Startdate: 06/12/2025 Architecture: LINUX Score: 48 23 169.254.169.254, 80 USDOSUS Reserved 2->23 25 45.8.93.146, 2113, 46472 TING-WIRELESSUS Germany 2->25 27 5 other IPs or domains 2->27 29 Multi AV Scanner detection for submitted file 2->29 8 dlr.mipsel.elf Hari 2->8         started        signatures3 process4 file5 21 /tmp/Hari, ELF 8->21 dropped 11 Hari 8->11         started        process6 process7 13 Hari 11->13         started        15 Hari 11->15         started        17 Hari 11->17         started        19 1018 other processes 11->19
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-06 07:14:48 UTC
File Type:
ELF32 Little (Exe)
AV detection:
16 of 37 (43.24%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 4a8af19872a460ed85df7e9d13dc5c4344b03cd67fb8c507a18654f4202b3d78

(this sample)

  
Delivery method
Distributed via web download

Comments