MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 809401926fcb38d01dbd1816b0a8206be7a65ec2be0d882f031bfbf540d6bb8e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 11


Intelligence 11 IOCs YARA 5 File information Comments

SHA256 hash: 809401926fcb38d01dbd1816b0a8206be7a65ec2be0d882f031bfbf540d6bb8e
SHA3-384 hash: efab3c094aef53f4ab1a92fff4a1059db791f6f7c244f4674e4a434c1b7b85d2d7b1ed5a7d838232486c9660367388b5
SHA1 hash: fb9adb25be55e490a75aee05d0d6371d960a7725
MD5 hash: c014b397253f15fc6e6c7a62d97dc0d9
humanhash: snake-yellow-sixteen-quebec
File name:arm5
Download: download sample
Signature Mirai
File size:157'476 bytes
First seen:2025-10-22 22:16:37 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:kwB5ggGZ13k1DV+UdG/h1y4DUwkChmMJt5+LeeRVNG:kwvGL3hOG7y4DhkChmMX8LeeRVNG
TLSH T148F31945FC508F27C6D522BBFB5E428D372657A8D2EE72039D256F24378A85B0E37242
telfhash t1e9f06213cc6c6ffce4d842b580be301772e8f08d36492832cc69ed8a8233d853026824
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
expand lolbin rust
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2025-10-22T19:22:00Z UTC
Last seen:
2025-10-23T00:41:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=2747aad3-1700-0000-eb79-31c78a0b0000 pid=2954 /usr/bin/sudo guuid=114735d6-1700-0000-eb79-31c78d0b0000 pid=2957 /tmp/sample.bin guuid=2747aad3-1700-0000-eb79-31c78a0b0000 pid=2954->guuid=114735d6-1700-0000-eb79-31c78d0b0000 pid=2957 execve
Result
Threat name:
Gafgyt, Mirai
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Connects to many ports of the same IP (likely port scanning)
Multi AV Scanner detection for submitted file
Reads system files that contain records of logged in users
Sample deletes itself
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Suricata IDS alerts for network traffic
Yara detected Gafgyt
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1800198 Sample: arm5.elf Startdate: 23/10/2025 Architecture: LINUX Score: 100 130 41.208.211.129, 37215 rainZA South Africa 2->130 132 41.203.64.87 globacom-asNG Nigeria 2->132 134 98 other IPs or domains 2->134 142 Suricata IDS alerts for network traffic 2->142 144 Multi AV Scanner detection for submitted file 2->144 146 Yara detected Gafgyt 2->146 148 2 other signatures 2->148 15 systemd gdm3 2->15         started        17 arm5.elf 2->17         started        20 systemd gpu-manager 2->20         started        22 36 other processes 2->22 signatures3 process4 file5 25 gdm3 gdm-session-worker 15->25         started        27 gdm3 gdm-session-worker 15->27         started        38 3 other processes 15->38 136 Sample deletes itself 17->136 138 Sample reads /proc/mounts (often used for finding a writable filesystem) 17->138 29 arm5.elf 17->29         started        32 arm5.elf 17->32         started        34 arm5.elf 17->34         started        36 arm5.elf 17->36         started        40 8 other processes 20->40 128 /var/log/wtmp, data 22->128 dropped 140 Reads system files that contain records of logged in users 22->140 42 5 other processes 22->42 signatures6 process7 signatures8 44 gdm-session-worker gdm-x-session 25->44         started        46 gdm-session-worker gdm-wayland-session 27->46         started        162 Sample tries to kill multiple processes (SIGKILL) 29->162 164 Sample reads /proc/mounts (often used for finding a writable filesystem) 29->164 48 arm5.elf 32->48         started        50 sh grep 40->50         started        52 sh grep 40->52         started        54 sh grep 40->54         started        58 5 other processes 40->58 56 language-validate 42->56         started        process9 process10 60 gdm-x-session dbus-run-session 44->60         started        62 gdm-x-session Xorg Xorg.wrap Xorg 44->62         started        64 gdm-x-session Default 44->64         started        66 gdm-wayland-session dbus-run-session 46->66         started        process11 68 dbus-run-session dbus-daemon 60->68         started        71 dbus-run-session gnome-session gnome-session-binary 1 60->71         started        73 Xorg sh 62->73         started        75 Xorg sh 62->75         started        77 dbus-run-session dbus-daemon 66->77         started        79 dbus-run-session gnome-session gnome-session-binary 1 66->79         started        signatures12 150 Sample tries to kill multiple processes (SIGKILL) 68->150 152 Sample reads /proc/mounts (often used for finding a writable filesystem) 68->152 81 dbus-daemon 68->81         started        83 dbus-daemon 68->83         started        92 8 other processes 68->92 85 gnome-session-binary sh gnome-shell 71->85         started        94 18 other processes 71->94 88 sh xkbcomp 73->88         started        90 sh xkbcomp 75->90         started        96 7 other processes 77->96 98 2 other processes 79->98 process13 signatures14 100 dbus-daemon at-spi-bus-launcher 81->100         started        102 dbus-daemon gjs 83->102         started        154 Sample reads /proc/mounts (often used for finding a writable filesystem) 85->154 105 gnome-shell ibus-daemon 85->105         started        113 8 other processes 92->113 107 gsd-print-notifications 94->107         started        115 2 other processes 94->115 109 dbus-daemon false 96->109         started        111 dbus-daemon false 96->111         started        117 5 other processes 96->117 process15 signatures16 119 at-spi-bus-launcher dbus-daemon 100->119         started        156 Sample reads /proc/mounts (often used for finding a writable filesystem) 102->156 122 gsd-print-notifications gsd-printer 107->122         started        process17 signatures18 158 Sample tries to kill multiple processes (SIGKILL) 119->158 160 Sample reads /proc/mounts (often used for finding a writable filesystem) 119->160 124 dbus-daemon 119->124         started        process19 process20 126 dbus-daemon at-spi2-registryd 124->126         started       
Threat name:
Linux.Backdoor.Mirai
Status:
Malicious
First seen:
2025-10-22 22:17:45 UTC
File Type:
ELF32 Little (Exe)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
hailbot
Score:
  10/10
Tags:
family:hailbot
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-9441505-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CVE_2017_17215
Author:NDA0E
Description:Detects exploitation attempt of CVE-2017-17215
Rule name:ELF_Mirai
Author:NDA0E
Description:Detects multiple Mirai variants
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Generic_Threat_d94e1020
Author:Elastic Security
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 809401926fcb38d01dbd1816b0a8206be7a65ec2be0d882f031bfbf540d6bb8e

(this sample)

  
Delivery method
Distributed via web download

Comments