🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6c8a287385b29abae710af6b755b8a5a5ad56ede36b3b0d4ca31cc167bbecea7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA 11 File information Comments

SHA256 hash: 6c8a287385b29abae710af6b755b8a5a5ad56ede36b3b0d4ca31cc167bbecea7
SHA3-384 hash: 29c27ee2871e6d9fded79b2c4d62ed67c12ade513030dd6d9417a69a69333fea375619274d060ea019968fa80a740f2b
SHA1 hash: ac01dc24f73928ff51a2a132b7a87a75528fab00
MD5 hash: 484827950743abb12b067a7875d8adc0
humanhash: oxygen-sodium-thirteen-mississippi
File name:main_x86
Download: download sample
Signature Mirai
File size:82'279 bytes
First seen:2026-09-08 16:57:02 UTC
Last seen:2026-09-08 21:51:17 UTC
File type: elf
MIME type:application/x-executable
ssdeep 1536:0cmo1ouFVETMnVvIiN+9Nn1f6ndfwaQy+vjKdUoNXoPEh1V:0TuFVET8VvTNMN1f91y+v2dUoNYPEh1V
TLSH T1D7832AC25A42CAB3D4921BF915E75B320632EC2A1B2E9F56F77C7CF49E02688711635C
telfhash t17031ce36a7214722aa61cc649ced93a3022dc7275248fb73df31855c541a0ade637c4f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
3
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Runs as daemon
Receives data from a server
Kills processes
Creating a file
Sends data to a server
Traces processes
Substitutes an application name
Deleting of the original file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
gcc mirai
Status:
terminated
Behavior Graph:
%3 guuid=4d8fd029-1a00-0000-9312-8949f0060000 pid=1776 /usr/bin/sudo guuid=a97d0a2e-1a00-0000-9312-8949f4060000 pid=1780 /tmp/sample.bin delete-file net guuid=4d8fd029-1a00-0000-9312-8949f0060000 pid=1776->guuid=a97d0a2e-1a00-0000-9312-8949f4060000 pid=1780 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=a97d0a2e-1a00-0000-9312-8949f4060000 pid=1780->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9454582e-1a00-0000-9312-8949f5060000 pid=1781 /tmp/sample.bin net send-data zombie guuid=a97d0a2e-1a00-0000-9312-8949f4060000 pid=1780->guuid=9454582e-1a00-0000-9312-8949f5060000 pid=1781 clone guuid=9454582e-1a00-0000-9312-8949f5060000 pid=1781->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 78856aab-82d1-5d9a-88df-1c93fd887c0b 37.16.74.19:1312 guuid=9454582e-1a00-0000-9312-8949f5060000 pid=1781->78856aab-82d1-5d9a-88df-1c93fd887c0b send: 64B guuid=68c8832e-1a00-0000-9312-8949f6060000 pid=1782 /tmp/sample.bin guuid=9454582e-1a00-0000-9312-8949f5060000 pid=1781->guuid=68c8832e-1a00-0000-9312-8949f6060000 pid=1782 clone guuid=921e922e-1a00-0000-9312-8949f7060000 pid=1783 /tmp/sample.bin net net-scan send-data guuid=9454582e-1a00-0000-9312-8949f5060000 pid=1781->guuid=921e922e-1a00-0000-9312-8949f7060000 pid=1783 clone guuid=921e922e-1a00-0000-9312-8949f7060000 pid=1783|network network activity to 88 IP addresses review logs to see them all guuid=921e922e-1a00-0000-9312-8949f7060000 pid=1783->guuid=921e922e-1a00-0000-9312-8949f7060000 pid=1783|network network
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-09-08 16:57:27 UTC
File Type:
ELF32 Little (Exe)
AV detection:
17 of 36 (47.22%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet credential_access discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads process memory
Enumerates running processes
Deletes itself
Traces itself
Contacts a large (23846) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:Linux_Trojan_Mirai_0bce98a2
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_88de437f
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_8aa7b5d3
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_b14f4c5d
Author:Elastic Security
Rule name:MAL_ARM_LNX_Mirai_Mar13_2022
Author:Mehmet Ali Kerimoglu a.k.a. CYB3RMX
Description:Detects new ARM Mirai variant
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 6c8a287385b29abae710af6b755b8a5a5ad56ede36b3b0d4ca31cc167bbecea7

(this sample)

  
Delivery method
Distributed via web download

Comments