MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6a606126df8031b2c2d16cea3e459a7beed6580eb746f368eaf75cfcaffd3f97. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 6a606126df8031b2c2d16cea3e459a7beed6580eb746f368eaf75cfcaffd3f97
SHA3-384 hash: a40d4ca5098cfd0dc024f4833dc03f3357e145206f5a72f6dfc533ed817789719940500d509350c0ceb501f979db340a
SHA1 hash: c9c8771e85e34ff53b6478572e1066133d922261
MD5 hash: 3d52a1ce177562fc9b54f462939bf6ff
humanhash: monkey-avocado-alpha-five
File name:rondo.m68k
Download: download sample
Signature Mirai
File size:130'932 bytes
First seen:2025-12-20 00:23:54 UTC
Last seen:2025-12-20 06:47:10 UTC
File type: elf
MIME type:application/x-executable
ssdeep 3072:8wHIbpsjtInaY6YMXy0+K5dZOupJwVEUtVSF:XobpshIruy0Z5doMJMtVa
TLSH T1CAD35CC6B500DF7DFC0BD33786430916B23AA76435A20A77767B686BED311E6182EE41
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
101
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade mirai obfuscated
Verdict:
Unknown
File Type:
elf.32.be
First seen:
2025-12-19T22:53:00Z UTC
Last seen:
2025-12-19T22:59:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=0448d749-1900-0000-bb46-30626c140000 pid=5228 /usr/bin/sudo guuid=b4088b4c-1900-0000-bb46-30626d140000 pid=5229 /tmp/sample.bin guuid=0448d749-1900-0000-bb46-30626c140000 pid=5228->guuid=b4088b4c-1900-0000-bb46-30626d140000 pid=5229 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1836576 Sample: rondo.m68k.elf Startdate: 20/12/2025 Architecture: LINUX Score: 48 12 109.202.202.202, 80 INIT7CH Switzerland 2->12 14 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->14 16 2 other IPs or domains 2->16 18 Multi AV Scanner detection for submitted file 2->18 6 dash rm 2->6         started        8 dash rm 2->8         started        10 rondo.m68k.elf 2->10         started        signatures3 process4
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-20 00:24:19 UTC
File Type:
ELF32 Big (Exe)
AV detection:
5 of 36 (13.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-6981989-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 6a606126df8031b2c2d16cea3e459a7beed6580eb746f368eaf75cfcaffd3f97

(this sample)

  
Delivery method
Distributed via web download

Comments