MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 64a4e16d85137289ead8ad58e53eaba4da9561e7ee0c0f7abde0125bca4c9f7e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 64a4e16d85137289ead8ad58e53eaba4da9561e7ee0c0f7abde0125bca4c9f7e
SHA3-384 hash: dcd5ddffcdcccf927d6c299e430ad5e8d53533da3479a80ee8af746b68ec037ab11f0132ebff23cf776b276a68d7311b
SHA1 hash: 045d4473b42ce1e8eed7d0668362ca7574628862
MD5 hash: 8ec3584169702c5ce7528bcedae17949
humanhash: carolina-beer-hot-kitten
File name:64a4e16d85137289ead8ad58e53eaba4da9561e7ee0c0f7abde0125bca4c9f7e.elf
Download: download sample
Signature Mirai
File size:61'420 bytes
First seen:2026-08-18 03:15:37 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 1536:AIwvwIi70PaDQN7TlDEY+CY/3ozSL/K+0pIEv:NwpBGI7hLY/SCLA
TLSH T12D5301E4E21A37FCC7E5B5765A1D40CCE13B74139A0B47AA8CA911FDF076788CB10628
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter whack_sh
Tags:elf exe UPX whack.sh
File size (compressed) :61'420 bytes
File size (de-compressed) :124'808 bytes
Format:linux/amd64
Unpacked file: c53d0b4968d92236ed2d4cc3daa0c29811a3625f6d89b0075a3ac28ee9996ce0

Intelligence


File Origin
# of uploads :
1
# of downloads :
152
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Changes the time when the file was created, accessed, or modified
Opens a port
Creating a file
Launching a process
Connection attempt
Sets a written file as executable
Runs as daemon
Creates or modifies symbolic links
Changes access rights for a written file
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Writes files to system directory
Deleting of the original file
Creates or modifies files in /init.d to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Creates or modifies files to set up autorun
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
packed upx
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
UPX
Botnet:
unknown
Number of open files:
17
Number of processes launched:
14
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Persistence
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=39165dcf-1900-0000-8e15-502b620a0000 pid=2658 /usr/bin/sudo guuid=354c94d1-1900-0000-8e15-502b670a0000 pid=2663 /tmp/sample.bin delete-file mprotect-exec net write-config write-file guuid=39165dcf-1900-0000-8e15-502b620a0000 pid=2658->guuid=354c94d1-1900-0000-8e15-502b670a0000 pid=2663 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=354c94d1-1900-0000-8e15-502b670a0000 pid=2663->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4f9c71d2-1900-0000-8e15-502b6a0a0000 pid=2666 /usr/bin/dash guuid=354c94d1-1900-0000-8e15-502b670a0000 pid=2663->guuid=4f9c71d2-1900-0000-8e15-502b6a0a0000 pid=2666 execve guuid=c990c3d2-1900-0000-8e15-502b6c0a0000 pid=2668 /usr/bin/dash guuid=354c94d1-1900-0000-8e15-502b670a0000 pid=2663->guuid=c990c3d2-1900-0000-8e15-502b6c0a0000 pid=2668 execve guuid=10eb91d3-1900-0000-8e15-502b710a0000 pid=2673 /usr/bin/chattr zombie guuid=354c94d1-1900-0000-8e15-502b670a0000 pid=2663->guuid=10eb91d3-1900-0000-8e15-502b710a0000 pid=2673 execve guuid=dd8e98d3-1900-0000-8e15-502b720a0000 pid=2674 /usr/bin/chattr zombie guuid=354c94d1-1900-0000-8e15-502b670a0000 pid=2663->guuid=dd8e98d3-1900-0000-8e15-502b720a0000 pid=2674 execve guuid=72139ed3-1900-0000-8e15-502b730a0000 pid=2675 /usr/bin/chattr zombie guuid=354c94d1-1900-0000-8e15-502b670a0000 pid=2663->guuid=72139ed3-1900-0000-8e15-502b730a0000 pid=2675 execve guuid=031aa1d3-1900-0000-8e15-502b740a0000 pid=2676 /usr/bin/busybox zombie guuid=354c94d1-1900-0000-8e15-502b670a0000 pid=2663->guuid=031aa1d3-1900-0000-8e15-502b740a0000 pid=2676 execve guuid=d699a4d3-1900-0000-8e15-502b750a0000 pid=2677 /usr/bin/busybox zombie guuid=354c94d1-1900-0000-8e15-502b670a0000 pid=2663->guuid=d699a4d3-1900-0000-8e15-502b750a0000 pid=2677 execve guuid=256ba8d3-1900-0000-8e15-502b760a0000 pid=2678 /usr/bin/busybox zombie guuid=354c94d1-1900-0000-8e15-502b670a0000 pid=2663->guuid=256ba8d3-1900-0000-8e15-502b760a0000 pid=2678 execve guuid=63c9add3-1900-0000-8e15-502b770a0000 pid=2679 /tmp/sample.bin net send-data zombie guuid=354c94d1-1900-0000-8e15-502b670a0000 pid=2663->guuid=63c9add3-1900-0000-8e15-502b770a0000 pid=2679 clone guuid=eb7424d3-1900-0000-8e15-502b6e0a0000 pid=2670 /usr/bin/dash guuid=c990c3d2-1900-0000-8e15-502b6c0a0000 pid=2668->guuid=eb7424d3-1900-0000-8e15-502b6e0a0000 pid=2670 clone guuid=6e712cd3-1900-0000-8e15-502b6f0a0000 pid=2671 /usr/bin/dash guuid=c990c3d2-1900-0000-8e15-502b6c0a0000 pid=2668->guuid=6e712cd3-1900-0000-8e15-502b6f0a0000 pid=2671 clone guuid=63c9add3-1900-0000-8e15-502b770a0000 pid=2679->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 706d8119-5804-563f-93fb-1ad04086f3d8 64.89.163.215:666 guuid=63c9add3-1900-0000-8e15-502b770a0000 pid=2679->706d8119-5804-563f-93fb-1ad04086f3d8 send: 90B guuid=aefeb5d3-1900-0000-8e15-502b790a0000 pid=2681 /tmp/sample.bin guuid=63c9add3-1900-0000-8e15-502b770a0000 pid=2679->guuid=aefeb5d3-1900-0000-8e15-502b790a0000 pid=2681 clone guuid=5febb8d3-1900-0000-8e15-502b7a0a0000 pid=2682 /tmp/sample.bin guuid=63c9add3-1900-0000-8e15-502b770a0000 pid=2679->guuid=5febb8d3-1900-0000-8e15-502b7a0a0000 pid=2682 clone guuid=112dbdd3-1900-0000-8e15-502b7b0a0000 pid=2683 /tmp/sample.bin guuid=63c9add3-1900-0000-8e15-502b770a0000 pid=2679->guuid=112dbdd3-1900-0000-8e15-502b7b0a0000 pid=2683 clone
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
Reads runtime system information
Changes its process name
Modifies Bash startup script
UPX packed file
Creates/modifies Cron job
Creates/modifies environment variables
Modifies init.d
Modifies rc script
Modifies systemd
Deletes itself
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 64a4e16d85137289ead8ad58e53eaba4da9561e7ee0c0f7abde0125bca4c9f7e

(this sample)

Comments