MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 51ad8bfc5314bb1f7ee50ce49e37c3c3123c904bf41053f1e5d7aea1f5fcc200. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 51ad8bfc5314bb1f7ee50ce49e37c3c3123c904bf41053f1e5d7aea1f5fcc200
SHA3-384 hash: 90468a45c9b08af6f1c507edf70400256518db234af547fe1580a7cc891dcc9a9180af535e3d8c56f55dc7e6a3ad5573
SHA1 hash: c29f54caf86773898b4fc5083d5a5b9cdda43f7c
MD5 hash: 27e2bee202a97181087dc66565af4c50
humanhash: item-ten-princess-winner
File name:Josho.spc
Download: download sample
Signature Mirai
File size:60'144 bytes
First seen:2025-11-28 19:48:13 UTC
Last seen:2025-11-28 21:23:55 UTC
File type: elf
MIME type:application/x-executable
ssdeep 1536:v67ehQcypdywmScHgKP/se/D7Ao8jKMk4eM:STZ3eLP/Z7FM
TLSH T1FE431A227A362F1BC0D6E4F912F30725B1A57D6E1AA4C54ABC721E8FFF1169066036F4
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
3
# of downloads :
85
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
gcc masquerade
Result
Gathering data
Verdict:
Malicious
File Type:
ELF 32 BE
Detections:
HEUR:Backdoor.Linux.Mirai.b
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1822566 Sample: Josho.spc.elf Startdate: 28/11/2025 Architecture: LINUX Score: 48 16 176.97.124.206, 1549 ARCHERNETRU Ukraine 2->16 18 Multi AV Scanner detection for submitted file 2->18 8 Josho.spc.elf 2->8         started        signatures3 process4 process5 10 Josho.spc.elf 8->10         started        12 Josho.spc.elf 8->12         started        process6 14 Josho.spc.elf 10->14         started       
Threat name:
Linux.Backdoor.Mirai
Status:
Malicious
First seen:
2025-11-28 19:49:14 UTC
File Type:
ELF32 Big (Exe)
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:josho linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 51ad8bfc5314bb1f7ee50ce49e37c3c3123c904bf41053f1e5d7aea1f5fcc200

(this sample)

  
Delivery method
Distributed via web download

Comments