MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 80907f1a80aee9e4d55d7d9eb2db86dbfb5650e0860d8593d3c24b53386a5243. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 80907f1a80aee9e4d55d7d9eb2db86dbfb5650e0860d8593d3c24b53386a5243
SHA3-384 hash: 2c9a9f101dec6adf2d1afb864e2cc674703cb3985946215bba1afbba7bb0b9a8ce6ffc22053426bd1967ac17b64a0cda
SHA1 hash: ab5d39e848a960ae5ad645b3a7e5ea74c199943d
MD5 hash: 57c6b3328f64f9c63d61e955a5d2725e
humanhash: green-hotel-magnesium-florida
File name:ppc
Download: download sample
Signature Mirai
File size:80'376 bytes
First seen:2025-11-09 18:13:17 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:d3Q9oaK9YQF1wUXO6fuenvZj7kRKdj+Eq20/qQNUQ:dg9dAD1wf6fuE7ld0rJ
TLSH T173732A02731C0E43D5A3ADB4253F27E0C3BFA59120F4BB88655E9B4693B5E325586FCA
Magika elf
Reporter abuse_ch
Tags:elf mirai upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 5c8a74f905ce07e090b74674dd7e30cd89171c63458a5780479db20f70dd9936
File size (compressed) :35'836 bytes
File size (de-compressed) :80'376 bytes
Format:linux/ppc32
Packed file: 5c8a74f905ce07e090b74674dd7e30cd89171c63458a5780479db20f70dd9936

Intelligence


File Origin
# of uploads :
1
# of downloads :
136
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Connection attempt
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2025-11-09T16:26:00Z UTC
Last seen:
2025-11-09T21:32:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=040fdb2f-1900-0000-fb2e-75a5c20b0000 pid=3010 /usr/bin/sudo guuid=1234bb31-1900-0000-fb2e-75a5c80b0000 pid=3016 /tmp/sample.bin guuid=040fdb2f-1900-0000-fb2e-75a5c20b0000 pid=3010->guuid=1234bb31-1900-0000-fb2e-75a5c80b0000 pid=3016 execve
Gathering data
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-11-09 18:14:19 UTC
File Type:
ELF32 Big (Exe)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai linux
Verdict:
Malicious
Tags:
Unix.Dropper.Mirai-7135957-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 80907f1a80aee9e4d55d7d9eb2db86dbfb5650e0860d8593d3c24b53386a5243

(this sample)

  
Delivery method
Distributed via web download

Comments