MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5489d9efb6ff460c835ecff7cf0e0d948fe851b6f37bc9957e2b659be553a534. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 5489d9efb6ff460c835ecff7cf0e0d948fe851b6f37bc9957e2b659be553a534
SHA3-384 hash: 7dcd7ddf6d9eed0dd47ef7b3b3b8e4d77534e576b4538a1da4e3ddf4f84c1f82b0748dc00cf3363dd8a6f45573b39312
SHA1 hash: ad52d17168171ab1982e07aa903c21c0feca3170
MD5 hash: 89638aeeb8de332eb6991942a6b34dd5
humanhash: uranus-rugby-glucose-mirror
File name:87sbhas6as.m68k
Download: download sample
Signature Mirai
File size:39'040 bytes
First seen:2025-12-23 20:47:54 UTC
Last seen:2025-12-23 21:05:44 UTC
File type: elf
MIME type:application/x-executable
ssdeep 768:vIQJ3fiZ0t+FqD806l8lGAq2GfxTW3AGDQY:gMfiuIqw5l8saGfxTOA8
TLSH T1D2032A8AB4029E3CF94FF77F54124918F5617356D1D30B2A53A7FE53A8332682E52E82
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
95
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2025-12-23T18:04:00Z UTC
Last seen:
2025-12-24T12:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=b742423f-1a00-0000-2463-df18b70a0000 pid=2743 /usr/bin/sudo guuid=51485c41-1a00-0000-2463-df18bd0a0000 pid=2749 /tmp/sample.bin guuid=b742423f-1a00-0000-2463-df18b70a0000 pid=2743->guuid=51485c41-1a00-0000-2463-df18bd0a0000 pid=2749 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1838443 Sample: 87sbhas6as.m68k.elf Startdate: 23/12/2025 Architecture: LINUX Score: 48 14 130.12.180.134, 33966, 54740 DATAHOPDatahop-SixDegreesGB Canada 2->14 16 Multi AV Scanner detection for submitted file 2->16 8 87sbhas6as.m68k.elf 2->8         started        signatures3 process4 process5 10 87sbhas6as.m68k.elf 8->10         started        process6 12 87sbhas6as.m68k.elf 10->12         started       
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-23 20:48:35 UTC
File Type:
ELF32 Big (Exe)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-6981989-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 5489d9efb6ff460c835ecff7cf0e0d948fe851b6f37bc9957e2b659be553a534

(this sample)

  
Delivery method
Distributed via web download

Comments