MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4c0896abd837f7263217ec3a9735eb5f888acfbc70f9ef4cacaf7740ded45cd8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 6 File information Comments

SHA256 hash: 4c0896abd837f7263217ec3a9735eb5f888acfbc70f9ef4cacaf7740ded45cd8
SHA3-384 hash: a76afc436504e1de8e31830588451e1cf191b99033a990adb70698b3df64c4ca1932545d208e9922d96f043328aff93d
SHA1 hash: 953a4be999988c7f890151192dd8896cf5f13764
MD5 hash: 8b746277f33d45978f31e0888cf6fd55
humanhash: five-uncle-hawaii-robert
File name:i686
Download: download sample
Signature Mirai
File size:102'012 bytes
First seen:2026-01-04 09:10:13 UTC
Last seen:2026-01-04 10:34:10 UTC
File type: elf
MIME type:application/x-executable
ssdeep 1536:BbtkAP0v6MwnVN2AW/a1bwt3zERIFG2MSZN/GUMOmSzQP9:RP0vemC1bwtjERIc6oU3Ju9
TLSH T1D3A3F582AF43DFB3D45320F542B7AB258A31FC3B8C36D685E375BDA18A115D1A616338
telfhash t1bf5148f53e7908ecf7805c4cc71e6b936b06dbb716a135b244e2681637f6e8190b6839
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
3
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Runs as daemon
Kills processes
Opens a port
Changes access rights for a written file
Launching a process
Locks files
Sends data to a server
Sets a written file as executable
Creating a file
Collects information on the CPU
Changes the time when the file was created, accessed, or modified
Creating a file in the %temp% directory
Connection attempt
Collects information on the OS
Writes files to system directory
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Creates or modifies files in /init.d to set up autorun
Verdict:
Unknown
File Type:
elf.32.le
First seen:
2026-01-03T22:10:00Z UTC
Last seen:
2026-01-04T06:52:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=e08ef3c3-6000-0000-ae27-9da67d040000 pid=1149 /usr/bin/sudo guuid=d752abc6-6000-0000-ae27-9da67e040000 pid=1150 /tmp/sample.bin net write-config write-file guuid=e08ef3c3-6000-0000-ae27-9da67d040000 pid=1149->guuid=d752abc6-6000-0000-ae27-9da67e040000 pid=1150 execve 24601723-ce49-57fd-8a20-658824355076 127.0.0.1:2625 guuid=d752abc6-6000-0000-ae27-9da67e040000 pid=1150->24601723-ce49-57fd-8a20-658824355076 con guuid=3a051622-6600-0000-ae27-9da67f040000 pid=1151 /usr/bin/dash guuid=d752abc6-6000-0000-ae27-9da67e040000 pid=1150->guuid=3a051622-6600-0000-ae27-9da67f040000 pid=1151 execve guuid=8cf0a423-6600-0000-ae27-9da682040000 pid=1154 /usr/bin/dash guuid=d752abc6-6000-0000-ae27-9da67e040000 pid=1150->guuid=8cf0a423-6600-0000-ae27-9da682040000 pid=1154 execve guuid=dc060424-6600-0000-ae27-9da685040000 pid=1157 /usr/bin/dash write-config guuid=d752abc6-6000-0000-ae27-9da67e040000 pid=1150->guuid=dc060424-6600-0000-ae27-9da685040000 pid=1157 execve guuid=5fc2c224-6600-0000-ae27-9da687040000 pid=1159 /usr/bin/dash guuid=d752abc6-6000-0000-ae27-9da67e040000 pid=1150->guuid=5fc2c224-6600-0000-ae27-9da687040000 pid=1159 execve guuid=77e71d26-6600-0000-ae27-9da689040000 pid=1161 /tmp/sample.bin guuid=d752abc6-6000-0000-ae27-9da67e040000 pid=1150->guuid=77e71d26-6600-0000-ae27-9da689040000 pid=1161 clone guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162 /tmp/sample.bin net send-data zombie guuid=d752abc6-6000-0000-ae27-9da67e040000 pid=1150->guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162 clone guuid=d4b95d22-6600-0000-ae27-9da680040000 pid=1152 /usr/bin/cp guuid=3a051622-6600-0000-ae27-9da67f040000 pid=1151->guuid=d4b95d22-6600-0000-ae27-9da680040000 pid=1152 execve guuid=afac1e23-6600-0000-ae27-9da681040000 pid=1153 /usr/bin/chmod guuid=3a051622-6600-0000-ae27-9da67f040000 pid=1151->guuid=afac1e23-6600-0000-ae27-9da681040000 pid=1153 execve guuid=018bcf23-6600-0000-ae27-9da683040000 pid=1155 /usr/bin/dash guuid=8cf0a423-6600-0000-ae27-9da682040000 pid=1154->guuid=018bcf23-6600-0000-ae27-9da683040000 pid=1155 clone guuid=e53ed523-6600-0000-ae27-9da684040000 pid=1156 /usr/bin/dash guuid=8cf0a423-6600-0000-ae27-9da682040000 pid=1154->guuid=e53ed523-6600-0000-ae27-9da684040000 pid=1156 clone guuid=7e155824-6600-0000-ae27-9da686040000 pid=1158 /usr/bin/grep guuid=dc060424-6600-0000-ae27-9da685040000 pid=1157->guuid=7e155824-6600-0000-ae27-9da686040000 pid=1158 execve guuid=55511a25-6600-0000-ae27-9da688040000 pid=1160 /usr/bin/chmod guuid=5fc2c224-6600-0000-ae27-9da687040000 pid=1159->guuid=55511a25-6600-0000-ae27-9da688040000 pid=1160 execve 8724242f-5b7b-562e-b78a-57b7928f987a 45.153.34.74:12344 guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->8724242f-5b7b-562e-b78a-57b7928f987a send: 13B guuid=64843826-6600-0000-ae27-9da68b040000 pid=1163 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=64843826-6600-0000-ae27-9da68b040000 pid=1163 execve guuid=707b1627-6600-0000-ae27-9da68e040000 pid=1166 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=707b1627-6600-0000-ae27-9da68e040000 pid=1166 execve guuid=d01d5a2f-6600-0000-ae27-9da691040000 pid=1169 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=d01d5a2f-6600-0000-ae27-9da691040000 pid=1169 execve guuid=70a5f415-6700-0000-ae27-9da693040000 pid=1171 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=70a5f415-6700-0000-ae27-9da693040000 pid=1171 execve guuid=a6196619-6700-0000-ae27-9da695040000 pid=1173 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=a6196619-6700-0000-ae27-9da695040000 pid=1173 execve guuid=8f41ed1c-6700-0000-ae27-9da697040000 pid=1175 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=8f41ed1c-6700-0000-ae27-9da697040000 pid=1175 execve guuid=f0632b21-6700-0000-ae27-9da699040000 pid=1177 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=f0632b21-6700-0000-ae27-9da699040000 pid=1177 execve guuid=14458923-6700-0000-ae27-9da69b040000 pid=1179 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=14458923-6700-0000-ae27-9da69b040000 pid=1179 execve guuid=2049fe28-6700-0000-ae27-9da69d040000 pid=1181 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=2049fe28-6700-0000-ae27-9da69d040000 pid=1181 execve guuid=65183c2b-6700-0000-ae27-9da69f040000 pid=1183 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=65183c2b-6700-0000-ae27-9da69f040000 pid=1183 execve guuid=c04c972d-6700-0000-ae27-9da6a1040000 pid=1185 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=c04c972d-6700-0000-ae27-9da6a1040000 pid=1185 execve guuid=ccfcf62f-6700-0000-ae27-9da6a3040000 pid=1187 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=ccfcf62f-6700-0000-ae27-9da6a3040000 pid=1187 execve guuid=e00d4f32-6700-0000-ae27-9da6a5040000 pid=1189 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=e00d4f32-6700-0000-ae27-9da6a5040000 pid=1189 execve guuid=8fe8b134-6700-0000-ae27-9da6a7040000 pid=1191 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=8fe8b134-6700-0000-ae27-9da6a7040000 pid=1191 execve guuid=3dd20937-6700-0000-ae27-9da6a9040000 pid=1193 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=3dd20937-6700-0000-ae27-9da6a9040000 pid=1193 execve guuid=00804339-6700-0000-ae27-9da6ab040000 pid=1195 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=00804339-6700-0000-ae27-9da6ab040000 pid=1195 execve guuid=ce657f3b-6700-0000-ae27-9da6ad040000 pid=1197 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=ce657f3b-6700-0000-ae27-9da6ad040000 pid=1197 execve guuid=a990dc3d-6700-0000-ae27-9da6af040000 pid=1199 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=a990dc3d-6700-0000-ae27-9da6af040000 pid=1199 execve guuid=25271e40-6700-0000-ae27-9da6b1040000 pid=1201 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=25271e40-6700-0000-ae27-9da6b1040000 pid=1201 execve guuid=2bb1f942-6700-0000-ae27-9da6b3040000 pid=1203 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=2bb1f942-6700-0000-ae27-9da6b3040000 pid=1203 execve guuid=1a8f8445-6700-0000-ae27-9da6b5040000 pid=1205 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=1a8f8445-6700-0000-ae27-9da6b5040000 pid=1205 execve guuid=786ef447-6700-0000-ae27-9da6b7040000 pid=1207 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=786ef447-6700-0000-ae27-9da6b7040000 pid=1207 execve guuid=016e724a-6700-0000-ae27-9da6b9040000 pid=1209 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=016e724a-6700-0000-ae27-9da6b9040000 pid=1209 execve guuid=e9e9e14c-6700-0000-ae27-9da6bb040000 pid=1211 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=e9e9e14c-6700-0000-ae27-9da6bb040000 pid=1211 execve guuid=6451f64f-6700-0000-ae27-9da6bd040000 pid=1213 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=6451f64f-6700-0000-ae27-9da6bd040000 pid=1213 execve guuid=5f84bc52-6700-0000-ae27-9da6bf040000 pid=1215 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=5f84bc52-6700-0000-ae27-9da6bf040000 pid=1215 execve guuid=0740da55-6700-0000-ae27-9da6c1040000 pid=1217 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=0740da55-6700-0000-ae27-9da6c1040000 pid=1217 execve guuid=b324e658-6700-0000-ae27-9da6c3040000 pid=1219 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=b324e658-6700-0000-ae27-9da6c3040000 pid=1219 execve guuid=ff8b085c-6700-0000-ae27-9da6c5040000 pid=1221 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=ff8b085c-6700-0000-ae27-9da6c5040000 pid=1221 execve guuid=0d697e5f-6700-0000-ae27-9da6c7040000 pid=1223 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=0d697e5f-6700-0000-ae27-9da6c7040000 pid=1223 execve guuid=3af74963-6700-0000-ae27-9da6c9040000 pid=1225 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=3af74963-6700-0000-ae27-9da6c9040000 pid=1225 execve guuid=ce1e5166-6700-0000-ae27-9da6cb040000 pid=1227 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=ce1e5166-6700-0000-ae27-9da6cb040000 pid=1227 execve guuid=a772a669-6700-0000-ae27-9da6cd040000 pid=1229 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=a772a669-6700-0000-ae27-9da6cd040000 pid=1229 execve guuid=942afb6c-6700-0000-ae27-9da6cf040000 pid=1231 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=942afb6c-6700-0000-ae27-9da6cf040000 pid=1231 execve guuid=2cf18a70-6700-0000-ae27-9da6d1040000 pid=1233 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=2cf18a70-6700-0000-ae27-9da6d1040000 pid=1233 execve guuid=c9c31173-6700-0000-ae27-9da6d3040000 pid=1235 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=c9c31173-6700-0000-ae27-9da6d3040000 pid=1235 execve guuid=5eb76575-6700-0000-ae27-9da6d5040000 pid=1237 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=5eb76575-6700-0000-ae27-9da6d5040000 pid=1237 execve guuid=5b12c577-6700-0000-ae27-9da6d7040000 pid=1239 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=5b12c577-6700-0000-ae27-9da6d7040000 pid=1239 execve guuid=6ad9217a-6700-0000-ae27-9da6d9040000 pid=1241 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=6ad9217a-6700-0000-ae27-9da6d9040000 pid=1241 execve guuid=dcdd6f7c-6700-0000-ae27-9da6db040000 pid=1243 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=dcdd6f7c-6700-0000-ae27-9da6db040000 pid=1243 execve guuid=e48ec17e-6700-0000-ae27-9da6dd040000 pid=1245 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=e48ec17e-6700-0000-ae27-9da6dd040000 pid=1245 execve guuid=32a12281-6700-0000-ae27-9da6df040000 pid=1247 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=32a12281-6700-0000-ae27-9da6df040000 pid=1247 execve guuid=d4f59f81-6700-0000-ae27-9da6e1040000 pid=1249 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=d4f59f81-6700-0000-ae27-9da6e1040000 pid=1249 execve guuid=9ad82082-6700-0000-ae27-9da6e3040000 pid=1251 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=9ad82082-6700-0000-ae27-9da6e3040000 pid=1251 execve guuid=f8b78c82-6700-0000-ae27-9da6e5040000 pid=1253 /usr/bin/dash guuid=c00b2726-6600-0000-ae27-9da68a040000 pid=1162->guuid=f8b78c82-6700-0000-ae27-9da6e5040000 pid=1253 execve guuid=1d918a26-6600-0000-ae27-9da68c040000 pid=1164 /usr/bin/dash guuid=64843826-6600-0000-ae27-9da68b040000 pid=1163->guuid=1d918a26-6600-0000-ae27-9da68c040000 pid=1164 clone guuid=2eee9026-6600-0000-ae27-9da68d040000 pid=1165 /usr/bin/grep guuid=64843826-6600-0000-ae27-9da68b040000 pid=1163->guuid=2eee9026-6600-0000-ae27-9da68d040000 pid=1165 execve guuid=ae2b5627-6600-0000-ae27-9da68f040000 pid=1167 /usr/bin/dash guuid=707b1627-6600-0000-ae27-9da68e040000 pid=1166->guuid=ae2b5627-6600-0000-ae27-9da68f040000 pid=1167 clone guuid=0d355d27-6600-0000-ae27-9da690040000 pid=1168 /usr/bin/dash guuid=707b1627-6600-0000-ae27-9da68e040000 pid=1166->guuid=0d355d27-6600-0000-ae27-9da690040000 pid=1168 clone guuid=7c509f2f-6600-0000-ae27-9da692040000 pid=1170 /usr/bin/pgrep guuid=d01d5a2f-6600-0000-ae27-9da691040000 pid=1169->guuid=7c509f2f-6600-0000-ae27-9da692040000 pid=1170 execve guuid=ac0a5c16-6700-0000-ae27-9da694040000 pid=1172 /usr/bin/pgrep guuid=70a5f415-6700-0000-ae27-9da693040000 pid=1171->guuid=ac0a5c16-6700-0000-ae27-9da694040000 pid=1172 execve guuid=a532aa19-6700-0000-ae27-9da696040000 pid=1174 /usr/bin/pgrep guuid=a6196619-6700-0000-ae27-9da695040000 pid=1173->guuid=a532aa19-6700-0000-ae27-9da696040000 pid=1174 execve guuid=fa33201d-6700-0000-ae27-9da698040000 pid=1176 /usr/bin/pgrep guuid=8f41ed1c-6700-0000-ae27-9da697040000 pid=1175->guuid=fa33201d-6700-0000-ae27-9da698040000 pid=1176 execve guuid=fec15921-6700-0000-ae27-9da69a040000 pid=1178 /usr/bin/pgrep guuid=f0632b21-6700-0000-ae27-9da699040000 pid=1177->guuid=fec15921-6700-0000-ae27-9da69a040000 pid=1178 execve guuid=b56fc123-6700-0000-ae27-9da69c040000 pid=1180 /usr/bin/pgrep guuid=14458923-6700-0000-ae27-9da69b040000 pid=1179->guuid=b56fc123-6700-0000-ae27-9da69c040000 pid=1180 execve guuid=19443429-6700-0000-ae27-9da69e040000 pid=1182 /usr/bin/pgrep guuid=2049fe28-6700-0000-ae27-9da69d040000 pid=1181->guuid=19443429-6700-0000-ae27-9da69e040000 pid=1182 execve guuid=79506a2b-6700-0000-ae27-9da6a0040000 pid=1184 /usr/bin/pgrep guuid=65183c2b-6700-0000-ae27-9da69f040000 pid=1183->guuid=79506a2b-6700-0000-ae27-9da6a0040000 pid=1184 execve guuid=0cdbc42d-6700-0000-ae27-9da6a2040000 pid=1186 /usr/bin/pgrep guuid=c04c972d-6700-0000-ae27-9da6a1040000 pid=1185->guuid=0cdbc42d-6700-0000-ae27-9da6a2040000 pid=1186 execve guuid=2a362b30-6700-0000-ae27-9da6a4040000 pid=1188 /usr/bin/pgrep guuid=ccfcf62f-6700-0000-ae27-9da6a3040000 pid=1187->guuid=2a362b30-6700-0000-ae27-9da6a4040000 pid=1188 execve guuid=03958632-6700-0000-ae27-9da6a6040000 pid=1190 /usr/bin/pgrep guuid=e00d4f32-6700-0000-ae27-9da6a5040000 pid=1189->guuid=03958632-6700-0000-ae27-9da6a6040000 pid=1190 execve guuid=c23ae134-6700-0000-ae27-9da6a8040000 pid=1192 /usr/bin/pgrep guuid=8fe8b134-6700-0000-ae27-9da6a7040000 pid=1191->guuid=c23ae134-6700-0000-ae27-9da6a8040000 pid=1192 execve guuid=55aa3337-6700-0000-ae27-9da6aa040000 pid=1194 /usr/bin/pgrep guuid=3dd20937-6700-0000-ae27-9da6a9040000 pid=1193->guuid=55aa3337-6700-0000-ae27-9da6aa040000 pid=1194 execve guuid=a80e6f39-6700-0000-ae27-9da6ac040000 pid=1196 /usr/bin/pgrep guuid=00804339-6700-0000-ae27-9da6ab040000 pid=1195->guuid=a80e6f39-6700-0000-ae27-9da6ac040000 pid=1196 execve guuid=94ccbc3b-6700-0000-ae27-9da6ae040000 pid=1198 /usr/bin/pgrep guuid=ce657f3b-6700-0000-ae27-9da6ad040000 pid=1197->guuid=94ccbc3b-6700-0000-ae27-9da6ae040000 pid=1198 execve guuid=302e073e-6700-0000-ae27-9da6b0040000 pid=1200 /usr/bin/pgrep guuid=a990dc3d-6700-0000-ae27-9da6af040000 pid=1199->guuid=302e073e-6700-0000-ae27-9da6b0040000 pid=1200 execve guuid=8e2a4640-6700-0000-ae27-9da6b2040000 pid=1202 /usr/bin/pgrep guuid=25271e40-6700-0000-ae27-9da6b1040000 pid=1201->guuid=8e2a4640-6700-0000-ae27-9da6b2040000 pid=1202 execve guuid=d8893043-6700-0000-ae27-9da6b4040000 pid=1204 /usr/bin/pgrep guuid=2bb1f942-6700-0000-ae27-9da6b3040000 pid=1203->guuid=d8893043-6700-0000-ae27-9da6b4040000 pid=1204 execve guuid=b668c045-6700-0000-ae27-9da6b6040000 pid=1206 /usr/bin/pgrep guuid=1a8f8445-6700-0000-ae27-9da6b5040000 pid=1205->guuid=b668c045-6700-0000-ae27-9da6b6040000 pid=1206 execve guuid=7c2a3248-6700-0000-ae27-9da6b8040000 pid=1208 /usr/bin/pgrep guuid=786ef447-6700-0000-ae27-9da6b7040000 pid=1207->guuid=7c2a3248-6700-0000-ae27-9da6b8040000 pid=1208 execve guuid=5f16a84a-6700-0000-ae27-9da6ba040000 pid=1210 /usr/bin/pgrep guuid=016e724a-6700-0000-ae27-9da6b9040000 pid=1209->guuid=5f16a84a-6700-0000-ae27-9da6ba040000 pid=1210 execve guuid=7381114d-6700-0000-ae27-9da6bc040000 pid=1212 /usr/bin/pgrep guuid=e9e9e14c-6700-0000-ae27-9da6bb040000 pid=1211->guuid=7381114d-6700-0000-ae27-9da6bc040000 pid=1212 execve guuid=b0882f50-6700-0000-ae27-9da6be040000 pid=1214 /usr/bin/pgrep guuid=6451f64f-6700-0000-ae27-9da6bd040000 pid=1213->guuid=b0882f50-6700-0000-ae27-9da6be040000 pid=1214 execve guuid=fd53eb52-6700-0000-ae27-9da6c0040000 pid=1216 /usr/bin/pgrep guuid=5f84bc52-6700-0000-ae27-9da6bf040000 pid=1215->guuid=fd53eb52-6700-0000-ae27-9da6c0040000 pid=1216 execve guuid=e6c80f56-6700-0000-ae27-9da6c2040000 pid=1218 /usr/bin/pgrep guuid=0740da55-6700-0000-ae27-9da6c1040000 pid=1217->guuid=e6c80f56-6700-0000-ae27-9da6c2040000 pid=1218 execve guuid=620d2359-6700-0000-ae27-9da6c4040000 pid=1220 /usr/bin/pgrep guuid=b324e658-6700-0000-ae27-9da6c3040000 pid=1219->guuid=620d2359-6700-0000-ae27-9da6c4040000 pid=1220 execve guuid=6632365c-6700-0000-ae27-9da6c6040000 pid=1222 /usr/bin/pgrep guuid=ff8b085c-6700-0000-ae27-9da6c5040000 pid=1221->guuid=6632365c-6700-0000-ae27-9da6c6040000 pid=1222 execve guuid=a298be5f-6700-0000-ae27-9da6c8040000 pid=1224 /usr/bin/pgrep guuid=0d697e5f-6700-0000-ae27-9da6c7040000 pid=1223->guuid=a298be5f-6700-0000-ae27-9da6c8040000 pid=1224 execve guuid=ea359a63-6700-0000-ae27-9da6ca040000 pid=1226 /usr/bin/pgrep guuid=3af74963-6700-0000-ae27-9da6c9040000 pid=1225->guuid=ea359a63-6700-0000-ae27-9da6ca040000 pid=1226 execve guuid=517aa266-6700-0000-ae27-9da6cc040000 pid=1228 /usr/bin/pgrep guuid=ce1e5166-6700-0000-ae27-9da6cb040000 pid=1227->guuid=517aa266-6700-0000-ae27-9da6cc040000 pid=1228 execve guuid=4317da69-6700-0000-ae27-9da6ce040000 pid=1230 /usr/bin/pgrep guuid=a772a669-6700-0000-ae27-9da6cd040000 pid=1229->guuid=4317da69-6700-0000-ae27-9da6ce040000 pid=1230 execve guuid=e736346d-6700-0000-ae27-9da6d0040000 pid=1232 /usr/bin/pgrep guuid=942afb6c-6700-0000-ae27-9da6cf040000 pid=1231->guuid=e736346d-6700-0000-ae27-9da6d0040000 pid=1232 execve guuid=8b3cbc70-6700-0000-ae27-9da6d2040000 pid=1234 /usr/bin/pgrep guuid=2cf18a70-6700-0000-ae27-9da6d1040000 pid=1233->guuid=8b3cbc70-6700-0000-ae27-9da6d2040000 pid=1234 execve guuid=96f64073-6700-0000-ae27-9da6d4040000 pid=1236 /usr/bin/pgrep guuid=c9c31173-6700-0000-ae27-9da6d3040000 pid=1235->guuid=96f64073-6700-0000-ae27-9da6d4040000 pid=1236 execve guuid=28239675-6700-0000-ae27-9da6d6040000 pid=1238 /usr/bin/pgrep guuid=5eb76575-6700-0000-ae27-9da6d5040000 pid=1237->guuid=28239675-6700-0000-ae27-9da6d6040000 pid=1238 execve guuid=f7b3f577-6700-0000-ae27-9da6d8040000 pid=1240 /usr/bin/pgrep guuid=5b12c577-6700-0000-ae27-9da6d7040000 pid=1239->guuid=f7b3f577-6700-0000-ae27-9da6d8040000 pid=1240 execve guuid=63954e7a-6700-0000-ae27-9da6da040000 pid=1242 /usr/bin/pgrep guuid=6ad9217a-6700-0000-ae27-9da6d9040000 pid=1241->guuid=63954e7a-6700-0000-ae27-9da6da040000 pid=1242 execve guuid=d3c0a17c-6700-0000-ae27-9da6dc040000 pid=1244 /usr/bin/pgrep guuid=dcdd6f7c-6700-0000-ae27-9da6db040000 pid=1243->guuid=d3c0a17c-6700-0000-ae27-9da6dc040000 pid=1244 execve guuid=a693ef7e-6700-0000-ae27-9da6de040000 pid=1246 /usr/bin/pgrep guuid=e48ec17e-6700-0000-ae27-9da6dd040000 pid=1245->guuid=a693ef7e-6700-0000-ae27-9da6de040000 pid=1246 execve guuid=c9e55281-6700-0000-ae27-9da6e0040000 pid=1248 /usr/bin/rm guuid=32a12281-6700-0000-ae27-9da6df040000 pid=1247->guuid=c9e55281-6700-0000-ae27-9da6e0040000 pid=1248 execve guuid=6475ce81-6700-0000-ae27-9da6e2040000 pid=1250 /usr/bin/rm guuid=d4f59f81-6700-0000-ae27-9da6e1040000 pid=1249->guuid=6475ce81-6700-0000-ae27-9da6e2040000 pid=1250 execve guuid=6be84b82-6700-0000-ae27-9da6e4040000 pid=1252 /usr/bin/rm guuid=9ad82082-6700-0000-ae27-9da6e3040000 pid=1251->guuid=6be84b82-6700-0000-ae27-9da6e4040000 pid=1252 execve guuid=99fdb482-6700-0000-ae27-9da6e6040000 pid=1254 /usr/bin/rm guuid=f8b78c82-6700-0000-ae27-9da6e5040000 pid=1253->guuid=99fdb482-6700-0000-ae27-9da6e6040000 pid=1254 execve
Result
Threat name:
Detection:
malicious
Classification:
spre.troj.evad.mine
Score:
92 / 100
Signature
Drops files in suspicious directories
Executes the "crontab" command typically for achieving persistence
Found strings related to Crypto-Mining
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Sample tries to set files in /etc globally writable
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1844395 Sample: i686.elf Startdate: 04/01/2026 Architecture: LINUX Score: 92 69 45.153.34.74, 12344, 52168 SKYLINKNL Germany 2->69 71 109.202.202.202, 80 INIT7CH Switzerland 2->71 73 3 other IPs or domains 2->73 83 Malicious sample detected (through community Yara rule) 2->83 85 Multi AV Scanner detection for submitted file 2->85 87 Yara detected Mirai 2->87 9 i686.elf 2->9         started        12 dash rm 2->12         started        14 dash rm 2->14         started        signatures3 process4 signatures5 91 Found strings related to Crypto-Mining 9->91 16 i686.elf 9->16         started        18 i686.elf sh 9->18         started        20 i686.elf sh 9->20         started        22 3 other processes 9->22 process6 file7 26 i686.elf sh 16->26         started        28 i686.elf sh 16->28         started        30 i686.elf sh 16->30         started        42 41 other processes 16->42 32 sh crontab 18->32         started        36 sh 18->36         started        38 sh cp 20->38         started        40 sh chmod 20->40         started        67 /etc/rc.local, ASCII 22->67 dropped 89 Sample tries to persist itself using System V runlevels 22->89 44 2 other processes 22->44 signatures8 process9 file10 46 sh pkill 26->46         started        49 sh pkill 28->49         started        51 sh pkill 30->51         started        63 /var/spool/cron/crontabs/tmp.vzZ7h5, ASCII 32->63 dropped 75 Sample tries to persist itself using cron 32->75 77 Executes the "crontab" command typically for achieving persistence 32->77 53 sh crontab 36->53         started        65 /usr/bin/systemd-update, ELF 38->65 dropped 79 Drops files in suspicious directories 38->79 55 sh crontab 42->55         started        57 sh pkill 42->57         started        59 sh pkill 42->59         started        61 39 other processes 42->61 81 Sample tries to set files in /etc globally writable 44->81 signatures11 process12 signatures13 93 Sample tries to kill multiple processes (SIGKILL) 46->93 95 Executes the "crontab" command typically for achieving persistence 53->95
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-01-04 06:19:44 UTC
File Type:
ELF32 Little (Exe)
AV detection:
12 of 37 (32.43%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
Modifies rc script
Modifies systemd
Write file to user bin folder
File and Directory Permissions Modification
Modifies hosts file
Verdict:
Unknown
Tags:
trojan mirai
YARA:
Linux_Trojan_Mirai_cc93863b
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_Mirai
Author:NDA0E
Description:Detects multiple Mirai variants
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Mirai_cc93863b
Author:Elastic Security
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 4c0896abd837f7263217ec3a9735eb5f888acfbc70f9ef4cacaf7740ded45cd8

(this sample)

  
Delivery method
Distributed via web download

Comments