MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b7c709aba3af9f79945f21998b06e73ec951ec5a523bc038fd21d0bdecfe326. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA 3 File information Comments

SHA256 hash: 4b7c709aba3af9f79945f21998b06e73ec951ec5a523bc038fd21d0bdecfe326
SHA3-384 hash: 9a59a172b2b74857269849e58c67fb063abc074d501d758f7f754d9eda37c2f42bda0908064930e55a9937fb8804323c
SHA1 hash: c0216d9bc7cd0e7f7da8a75de3baf3817676b338
MD5 hash: ef9e282b9917c11798dc99b9298beca7
humanhash: georgia-alanine-nine-november
File name:x86_64
Download: download sample
Signature Mirai
File size:59'628 bytes
First seen:2026-08-07 01:39:26 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:oJOy7sp/RfJScbFon8/huyCxykcOQUvxDvnnhmuwxlfnSfshmjL0VUm3aLEDKJ8k:kOy74pfrm8/Xz1wDvnErfGYm0VUmGZ
TLSH T17D43026B9359D1FBCA35E8B6B443638DF4B17C037602470FB53922752B5AC227F60682
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai UPX
File size (compressed) :59'628 bytes
File size (de-compressed) :149'992 bytes
Format:linux/amd64
Unpacked file: 1ae01ac29110a83c78af2f046599bffd4212b5653d949074374a4f27a6d6aaef

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Kills processes
Deletes a file
Launching a process
Manages services
Runs as daemon
Creating a file
Substitutes an application name
Writes files to system directory
Deletes a system binary file
Writes symbolic links to system directory
Deleting of the original file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
bashlite mirai packed upx
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-08-06T23:43:00Z UTC
Last seen:
2026-08-07T00:16:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=0d33ae0b-1700-0000-fc56-0e808f0c0000 pid=3215 /usr/bin/sudo guuid=01569f0f-1700-0000-fc56-0e80990c0000 pid=3225 /tmp/sample.bin mprotect-exec guuid=0d33ae0b-1700-0000-fc56-0e808f0c0000 pid=3215->guuid=01569f0f-1700-0000-fc56-0e80990c0000 pid=3225 execve guuid=72716311-1700-0000-fc56-0e809d0c0000 pid=3229 /tmp/sample.bin zombie guuid=01569f0f-1700-0000-fc56-0e80990c0000 pid=3225->guuid=72716311-1700-0000-fc56-0e809d0c0000 pid=3229 clone guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230 /tmp/sample.bin delete-file net send-data write-file zombie guuid=72716311-1700-0000-fc56-0e809d0c0000 pid=3229->guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230 clone 43107d06-e1b8-559a-8721-01616c7cb4c1 83.168.69.141:9482 guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->43107d06-e1b8-559a-8721-01616c7cb4c1 send: 551B guuid=ea2e7511-1700-0000-fc56-0e809f0c0000 pid=3231 /tmp/sample.bin guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=ea2e7511-1700-0000-fc56-0e809f0c0000 pid=3231 clone guuid=06829611-1700-0000-fc56-0e80a20c0000 pid=3234 /tmp/sample.bin write-config guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=06829611-1700-0000-fc56-0e80a20c0000 pid=3234 clone guuid=d70fa411-1700-0000-fc56-0e80a30c0000 pid=3235 /usr/bin/dash guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=d70fa411-1700-0000-fc56-0e80a30c0000 pid=3235 execve guuid=c3025612-1700-0000-fc56-0e80a80c0000 pid=3240 /usr/bin/dash write-file guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=c3025612-1700-0000-fc56-0e80a80c0000 pid=3240 execve guuid=8b3d8912-1700-0000-fc56-0e80a90c0000 pid=3241 /usr/bin/dash write-file guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=8b3d8912-1700-0000-fc56-0e80a90c0000 pid=3241 execve guuid=7cd3b912-1700-0000-fc56-0e80aa0c0000 pid=3242 /usr/bin/dash write-file guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=7cd3b912-1700-0000-fc56-0e80aa0c0000 pid=3242 execve guuid=88fff812-1700-0000-fc56-0e80ac0c0000 pid=3244 /usr/bin/dash guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=88fff812-1700-0000-fc56-0e80ac0c0000 pid=3244 execve guuid=97483613-1700-0000-fc56-0e80ad0c0000 pid=3245 /usr/bin/dash guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=97483613-1700-0000-fc56-0e80ad0c0000 pid=3245 execve guuid=a8c07b13-1700-0000-fc56-0e80af0c0000 pid=3247 /usr/bin/dash guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=a8c07b13-1700-0000-fc56-0e80af0c0000 pid=3247 execve guuid=fac3b113-1700-0000-fc56-0e80b10c0000 pid=3249 /usr/bin/dash guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=fac3b113-1700-0000-fc56-0e80b10c0000 pid=3249 execve guuid=b8ac0a82-1700-0000-fc56-0e80d90d0000 pid=3545 /usr/bin/dash guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=b8ac0a82-1700-0000-fc56-0e80d90d0000 pid=3545 execve guuid=59ec7785-1700-0000-fc56-0e80e70d0000 pid=3559 /usr/bin/dash guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=59ec7785-1700-0000-fc56-0e80e70d0000 pid=3559 execve guuid=770255e7-1700-0000-fc56-0e803d0f0000 pid=3901 /usr/bin/dash guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=770255e7-1700-0000-fc56-0e803d0f0000 pid=3901 execve guuid=19ba66e8-1700-0000-fc56-0e80460f0000 pid=3910 /usr/bin/dash guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=19ba66e8-1700-0000-fc56-0e80460f0000 pid=3910 execve guuid=6dcf1d46-1800-0000-fc56-0e80ce100000 pid=4302 /usr/bin/dash guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=6dcf1d46-1800-0000-fc56-0e80ce100000 pid=4302 execve guuid=7f994a47-1800-0000-fc56-0e80d5100000 pid=4309 /usr/bin/dash guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=7f994a47-1800-0000-fc56-0e80d5100000 pid=4309 execve guuid=465277a0-1800-0000-fc56-0e8033120000 pid=4659 /usr/bin/dash guuid=c9e56c11-1700-0000-fc56-0e809e0c0000 pid=3230->guuid=465277a0-1800-0000-fc56-0e8033120000 pid=4659 execve guuid=c16f9011-1700-0000-fc56-0e80a10c0000 pid=3233 /tmp/sample.bin guuid=ea2e7511-1700-0000-fc56-0e809f0c0000 pid=3231->guuid=c16f9011-1700-0000-fc56-0e80a10c0000 pid=3233 clone guuid=238cf7a1-1800-0000-fc56-0e8035120000 pid=4661 /tmp/sample.bin write-file guuid=ea2e7511-1700-0000-fc56-0e809f0c0000 pid=3231->guuid=238cf7a1-1800-0000-fc56-0e8035120000 pid=4661 clone guuid=9c951112-1700-0000-fc56-0e80a50c0000 pid=3237 /usr/bin/ln guuid=d70fa411-1700-0000-fc56-0e80a30c0000 pid=3235->guuid=9c951112-1700-0000-fc56-0e80a50c0000 pid=3237 execve guuid=7fd4db13-1700-0000-fc56-0e80b20c0000 pid=3250 /usr/bin/systemctl guuid=fac3b113-1700-0000-fc56-0e80b10c0000 pid=3249->guuid=7fd4db13-1700-0000-fc56-0e80b20c0000 pid=3250 execve guuid=29ef1814-1700-0000-fc56-0e80b40c0000 pid=3252 /usr/bin/basename guuid=7fd4db13-1700-0000-fc56-0e80b20c0000 pid=3250->guuid=29ef1814-1700-0000-fc56-0e80b40c0000 pid=3252 execve guuid=f2a26514-1700-0000-fc56-0e80b60c0000 pid=3254 /usr/bin/basename guuid=7fd4db13-1700-0000-fc56-0e80b20c0000 pid=3250->guuid=f2a26514-1700-0000-fc56-0e80b60c0000 pid=3254 execve guuid=b0eca414-1700-0000-fc56-0e80b80c0000 pid=3256 /usr/bin/dash guuid=7fd4db13-1700-0000-fc56-0e80b20c0000 pid=3250->guuid=b0eca414-1700-0000-fc56-0e80b80c0000 pid=3256 clone guuid=55c9ab14-1700-0000-fc56-0e80b90c0000 pid=3257 /usr/bin/systemctl guuid=b0eca414-1700-0000-fc56-0e80b80c0000 pid=3256->guuid=55c9ab14-1700-0000-fc56-0e80b90c0000 pid=3257 execve guuid=aed4af14-1700-0000-fc56-0e80ba0c0000 pid=3258 /usr/bin/sed guuid=b0eca414-1700-0000-fc56-0e80b80c0000 pid=3256->guuid=aed4af14-1700-0000-fc56-0e80ba0c0000 pid=3258 execve guuid=73d53382-1700-0000-fc56-0e80db0d0000 pid=3547 /usr/bin/systemctl guuid=b8ac0a82-1700-0000-fc56-0e80d90d0000 pid=3545->guuid=73d53382-1700-0000-fc56-0e80db0d0000 pid=3547 execve guuid=a80f9985-1700-0000-fc56-0e80e80d0000 pid=3560 /usr/bin/systemctl guuid=59ec7785-1700-0000-fc56-0e80e70d0000 pid=3559->guuid=a80f9985-1700-0000-fc56-0e80e80d0000 pid=3560 execve guuid=917bc285-1700-0000-fc56-0e80e90d0000 pid=3561 /usr/bin/basename guuid=a80f9985-1700-0000-fc56-0e80e80d0000 pid=3560->guuid=917bc285-1700-0000-fc56-0e80e90d0000 pid=3561 execve guuid=26f0fb85-1700-0000-fc56-0e80ea0d0000 pid=3562 /usr/bin/basename guuid=a80f9985-1700-0000-fc56-0e80e80d0000 pid=3560->guuid=26f0fb85-1700-0000-fc56-0e80ea0d0000 pid=3562 execve guuid=df0d4186-1700-0000-fc56-0e80eb0d0000 pid=3563 /usr/bin/dash guuid=a80f9985-1700-0000-fc56-0e80e80d0000 pid=3560->guuid=df0d4186-1700-0000-fc56-0e80eb0d0000 pid=3563 clone guuid=59ec4786-1700-0000-fc56-0e80ec0d0000 pid=3564 /usr/bin/systemctl guuid=df0d4186-1700-0000-fc56-0e80eb0d0000 pid=3563->guuid=59ec4786-1700-0000-fc56-0e80ec0d0000 pid=3564 execve guuid=06ee4b86-1700-0000-fc56-0e80ed0d0000 pid=3565 /usr/bin/sed guuid=df0d4186-1700-0000-fc56-0e80eb0d0000 pid=3563->guuid=06ee4b86-1700-0000-fc56-0e80ed0d0000 pid=3565 execve guuid=d77774e7-1700-0000-fc56-0e803f0f0000 pid=3903 /usr/bin/systemctl guuid=770255e7-1700-0000-fc56-0e803d0f0000 pid=3901->guuid=d77774e7-1700-0000-fc56-0e803f0f0000 pid=3903 execve guuid=bef794e8-1700-0000-fc56-0e80480f0000 pid=3912 /usr/bin/systemctl guuid=19ba66e8-1700-0000-fc56-0e80460f0000 pid=3910->guuid=bef794e8-1700-0000-fc56-0e80480f0000 pid=3912 execve guuid=4926c3e8-1700-0000-fc56-0e804a0f0000 pid=3914 /usr/bin/basename guuid=bef794e8-1700-0000-fc56-0e80480f0000 pid=3912->guuid=4926c3e8-1700-0000-fc56-0e804a0f0000 pid=3914 execve guuid=b7b0fde8-1700-0000-fc56-0e804b0f0000 pid=3915 /usr/bin/basename guuid=bef794e8-1700-0000-fc56-0e80480f0000 pid=3912->guuid=b7b0fde8-1700-0000-fc56-0e804b0f0000 pid=3915 execve guuid=878b41e9-1700-0000-fc56-0e804d0f0000 pid=3917 /usr/bin/dash guuid=bef794e8-1700-0000-fc56-0e80480f0000 pid=3912->guuid=878b41e9-1700-0000-fc56-0e804d0f0000 pid=3917 clone guuid=c84449e9-1700-0000-fc56-0e804e0f0000 pid=3918 /usr/bin/systemctl guuid=878b41e9-1700-0000-fc56-0e804d0f0000 pid=3917->guuid=c84449e9-1700-0000-fc56-0e804e0f0000 pid=3918 execve guuid=53514fe9-1700-0000-fc56-0e80500f0000 pid=3920 /usr/bin/sed guuid=878b41e9-1700-0000-fc56-0e804d0f0000 pid=3917->guuid=53514fe9-1700-0000-fc56-0e80500f0000 pid=3920 execve guuid=9cb04546-1800-0000-fc56-0e80d0100000 pid=4304 /usr/bin/systemctl guuid=6dcf1d46-1800-0000-fc56-0e80ce100000 pid=4302->guuid=9cb04546-1800-0000-fc56-0e80d0100000 pid=4304 execve guuid=846c7847-1800-0000-fc56-0e80d9100000 pid=4313 /usr/bin/systemctl guuid=7f994a47-1800-0000-fc56-0e80d5100000 pid=4309->guuid=846c7847-1800-0000-fc56-0e80d9100000 pid=4313 execve guuid=c7a83848-1800-0000-fc56-0e80dc100000 pid=4316 /usr/bin/basename guuid=846c7847-1800-0000-fc56-0e80d9100000 pid=4313->guuid=c7a83848-1800-0000-fc56-0e80dc100000 pid=4316 execve guuid=f2287948-1800-0000-fc56-0e80de100000 pid=4318 /usr/bin/basename guuid=846c7847-1800-0000-fc56-0e80d9100000 pid=4313->guuid=f2287948-1800-0000-fc56-0e80de100000 pid=4318 execve guuid=84aac648-1800-0000-fc56-0e80e2100000 pid=4322 /usr/bin/dash guuid=846c7847-1800-0000-fc56-0e80d9100000 pid=4313->guuid=84aac648-1800-0000-fc56-0e80e2100000 pid=4322 clone guuid=e6f3ce48-1800-0000-fc56-0e80e3100000 pid=4323 /usr/bin/systemctl guuid=84aac648-1800-0000-fc56-0e80e2100000 pid=4322->guuid=e6f3ce48-1800-0000-fc56-0e80e3100000 pid=4323 execve guuid=2fefd448-1800-0000-fc56-0e80e4100000 pid=4324 /usr/bin/sed guuid=84aac648-1800-0000-fc56-0e80e2100000 pid=4322->guuid=2fefd448-1800-0000-fc56-0e80e4100000 pid=4324 execve guuid=4506b3a0-1800-0000-fc56-0e8034120000 pid=4660 /usr/bin/systemctl guuid=465277a0-1800-0000-fc56-0e8033120000 pid=4659->guuid=4506b3a0-1800-0000-fc56-0e8034120000 pid=4660 execve guuid=ed4e459e-1f00-0000-fc56-0e804d140000 pid=5197 /usr/bin/dash guuid=238cf7a1-1800-0000-fc56-0e8035120000 pid=4661->guuid=ed4e459e-1f00-0000-fc56-0e804d140000 pid=5197 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
72 / 100
Signature
Deletes security-related log files
Deletes system log files
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample is packed with UPX
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1953772 Sample: x86_64.elf Startdate: 07/08/2026 Architecture: LINUX Score: 72 85 83.168.69.141, 49624, 49626, 49628 SKYPASS-ASPL Poland 2->85 87 daisy.ubuntu.com 2->87 89 Malicious sample detected (through community Yara rule) 2->89 91 Multi AV Scanner detection for submitted file 2->91 93 Sample is packed with UPX 2->93 12 x86_64.elf 2->12         started        14 systemd true 2->14         started        16 systemd ufw-init 2->16         started        18 python3.8 dpkg 2->18         started        signatures3 process4 process5 20 x86_64.elf 12->20         started        process6 22 x86_64.elf 20->22         started        signatures7 95 Sample deletes itself 22->95 97 Deletes system log files 22->97 25 x86_64.elf sh 22->25         started        29 x86_64.elf sh 22->29         started        31 x86_64.elf sh 22->31         started        33 14 other processes 22->33 process8 file9 81 /var/log/secure, very 25->81 dropped 99 Deletes security-related log files 25->99 35 sh service systemctl 29->35         started        37 sh service systemctl 31->37         started        83 /var/log/auth.log, very 33->83 dropped 39 x86_64.elf 33->39         started        41 sh service systemctl 33->41         started        43 sh service systemctl 33->43         started        45 6 other processes 33->45 signatures10 process11 process12 47 service 35->47         started        55 3 other processes 35->55 49 service 37->49         started        57 3 other processes 37->57 59 6 other processes 39->59 51 service 41->51         started        61 3 other processes 41->61 53 service 43->53         started        63 3 other processes 43->63 process13 65 service systemctl 47->65         started        67 service sed 47->67         started        69 service systemctl 49->69         started        71 service sed 49->71         started        73 service systemctl 51->73         started        75 service sed 51->75         started        77 service systemctl 53->77         started        79 service sed 53->79         started       
Threat name:
Linux.Backdoor.Mirai
Status:
Malicious
First seen:
2026-08-07 01:40:46 UTC
File Type:
ELF64 Little (Exe)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux upx
Behaviour
Reads runtime system information
Changes its process name
Checks CPU configuration
Deletes log files
Disables SELinux
Enumerates running processes
Indicator Removal: Clear Command History
Deletes itself
Deletes system logs
Disables AppArmor Mandatory Access Control
Flushes firewall rules
Modifies the /etc/hosts DNS resolution file
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 4b7c709aba3af9f79945f21998b06e73ec951ec5a523bc038fd21d0bdecfe326

(this sample)

  
Delivery method
Distributed via web download

Comments