MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8402e5704c40778694c3bc16bb76c1e906e3527a976d43b6dbf2cfa3de59da9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 19 File information Comments

SHA256 hash: 8402e5704c40778694c3bc16bb76c1e906e3527a976d43b6dbf2cfa3de59da9b
SHA3-384 hash: da0195f28e40c846133380846e84f8a4f66a933002613ab8c4f26483b7b423d2b9955b10f28646bc7ba7382bd4d70644
SHA1 hash: eda3df5299cc95c3d9edee76eacb8a06950cb8ac
MD5 hash: 5c0486d686736ca7b8a0f3e8e32fd181
humanhash: video-blue-seven-march
File name:x86_64
Download: download sample
Signature Mirai
File size:180'200 bytes
First seen:2026-08-19 16:27:29 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:jiSbx1u5E67Xi42yBbcOJiGI1rcw1GWT6fFvY1A4QNwE9IVQHoS:jxs5Eo7aTgu8AUHoS
TLSH T12D046C1BB5D188FDC8D6C1B84B9EE236DA72F0091138761F27D46E226E4DF306B6DA50
telfhash t1d861e2603e9e359430f79379b30be9e5fc3119211ee271e6ae6764e5ce037c80d96056
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 210edf2fb2b4cc1f9cc73b05858cd5524d402a00e4700e583aa1a746fae3b717
File size (compressed) :70'932 bytes
File size (de-compressed) :180'200 bytes
Format:linux/amd64
Packed file: 210edf2fb2b4cc1f9cc73b05858cd5524d402a00e4700e583aa1a746fae3b717

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Sets a file as executable
Runs as daemon
Deletes a file
Locks files
Kills processes
Creating a file
Kills critical processes
Substitutes an application name
Deleting of the original file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm anti-vm bash dropper lolbin mirai
Status:
terminated
Behavior Graph:
%3 guuid=14a84047-1700-0000-8867-ec28bc0d0000 pid=3516 /usr/bin/sudo guuid=fb289e49-1700-0000-8867-ec28c50d0000 pid=3525 /tmp/sample.bin guuid=14a84047-1700-0000-8867-ec28bc0d0000 pid=3516->guuid=fb289e49-1700-0000-8867-ec28c50d0000 pid=3525 execve guuid=5f08334a-1700-0000-8867-ec28c70d0000 pid=3527 /tmp/sample.bin zombie guuid=fb289e49-1700-0000-8867-ec28c50d0000 pid=3525->guuid=5f08334a-1700-0000-8867-ec28c70d0000 pid=3527 clone guuid=6d883c4a-1700-0000-8867-ec28c80d0000 pid=3528 /tmp/sample.bin delete-file net send-data write-file zombie guuid=5f08334a-1700-0000-8867-ec28c70d0000 pid=3527->guuid=6d883c4a-1700-0000-8867-ec28c80d0000 pid=3528 clone 43107d06-e1b8-559a-8721-01616c7cb4c1 83.168.69.141:9482 guuid=6d883c4a-1700-0000-8867-ec28c80d0000 pid=3528->43107d06-e1b8-559a-8721-01616c7cb4c1 send: 1134B guuid=ba364e4a-1700-0000-8867-ec28c90d0000 pid=3529 /tmp/sample.bin guuid=6d883c4a-1700-0000-8867-ec28c80d0000 pid=3528->guuid=ba364e4a-1700-0000-8867-ec28c90d0000 pid=3529 clone guuid=1b8a5b4a-1700-0000-8867-ec28cb0d0000 pid=3531 /tmp/sample.bin guuid=6d883c4a-1700-0000-8867-ec28c80d0000 pid=3528->guuid=1b8a5b4a-1700-0000-8867-ec28cb0d0000 pid=3531 clone guuid=bb7b674a-1700-0000-8867-ec28cc0d0000 pid=3532 /usr/sbin/xtables-nft-multi guuid=6d883c4a-1700-0000-8867-ec28c80d0000 pid=3528->guuid=bb7b674a-1700-0000-8867-ec28cc0d0000 pid=3532 execve guuid=659eb554-1700-0000-8867-ec28f30d0000 pid=3571 /usr/sbin/xtables-nft-multi guuid=6d883c4a-1700-0000-8867-ec28c80d0000 pid=3528->guuid=659eb554-1700-0000-8867-ec28f30d0000 pid=3571 execve guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573 /tmp/sample.bin delete-file write-config write-file guuid=6d883c4a-1700-0000-8867-ec28c80d0000 pid=3528->guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573 clone guuid=ef5d554a-1700-0000-8867-ec28ca0d0000 pid=3530 /tmp/sample.bin guuid=ba364e4a-1700-0000-8867-ec28c90d0000 pid=3529->guuid=ef5d554a-1700-0000-8867-ec28ca0d0000 pid=3530 clone guuid=dcc60a57-1700-0000-8867-ec28fa0d0000 pid=3578 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=dcc60a57-1700-0000-8867-ec28fa0d0000 pid=3578 execve guuid=147d5157-1700-0000-8867-ec28fc0d0000 pid=3580 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=147d5157-1700-0000-8867-ec28fc0d0000 pid=3580 execve guuid=dc029257-1700-0000-8867-ec28fe0d0000 pid=3582 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=dc029257-1700-0000-8867-ec28fe0d0000 pid=3582 execve guuid=4cc8ee57-1700-0000-8867-ec28ff0d0000 pid=3583 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=4cc8ee57-1700-0000-8867-ec28ff0d0000 pid=3583 execve guuid=5aa35a58-1700-0000-8867-ec28020e0000 pid=3586 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=5aa35a58-1700-0000-8867-ec28020e0000 pid=3586 execve guuid=a32cce62-1700-0000-8867-ec28210e0000 pid=3617 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=a32cce62-1700-0000-8867-ec28210e0000 pid=3617 execve guuid=f433cb63-1700-0000-8867-ec28230e0000 pid=3619 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=f433cb63-1700-0000-8867-ec28230e0000 pid=3619 execve guuid=b56c2a64-1700-0000-8867-ec28240e0000 pid=3620 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=b56c2a64-1700-0000-8867-ec28240e0000 pid=3620 execve guuid=c96fbf64-1700-0000-8867-ec28290e0000 pid=3625 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=c96fbf64-1700-0000-8867-ec28290e0000 pid=3625 execve guuid=86351265-1700-0000-8867-ec282d0e0000 pid=3629 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=86351265-1700-0000-8867-ec282d0e0000 pid=3629 execve guuid=c3a86c65-1700-0000-8867-ec28300e0000 pid=3632 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=c3a86c65-1700-0000-8867-ec28300e0000 pid=3632 execve guuid=de63c165-1700-0000-8867-ec28340e0000 pid=3636 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=de63c165-1700-0000-8867-ec28340e0000 pid=3636 execve guuid=5ce11266-1700-0000-8867-ec28380e0000 pid=3640 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=5ce11266-1700-0000-8867-ec28380e0000 pid=3640 execve guuid=64b97266-1700-0000-8867-ec283a0e0000 pid=3642 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=64b97266-1700-0000-8867-ec283a0e0000 pid=3642 execve guuid=8253dc66-1700-0000-8867-ec283c0e0000 pid=3644 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=8253dc66-1700-0000-8867-ec283c0e0000 pid=3644 execve guuid=0c47ce6d-1700-0000-8867-ec28590e0000 pid=3673 /usr/bin/systemctl guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=0c47ce6d-1700-0000-8867-ec28590e0000 pid=3673 execve guuid=07f50e99-1700-0000-8867-ec281a0f0000 pid=3866 /usr/bin/systemctl guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=07f50e99-1700-0000-8867-ec281a0f0000 pid=3866 execve guuid=c7a46cbb-1700-0000-8867-ec28920f0000 pid=3986 /tmp/sample.bin write-file guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=c7a46cbb-1700-0000-8867-ec28920f0000 pid=3986 clone guuid=bddbc0d0-1700-0000-8867-ec28c20f0000 pid=4034 /usr/sbin/xtables-nft-multi guuid=8926fd54-1700-0000-8867-ec28f50d0000 pid=3573->guuid=bddbc0d0-1700-0000-8867-ec28c20f0000 pid=4034 execve
Threat name:
Linux.Trojan.FlyLegitBot
Status:
Malicious
First seen:
2026-08-19 16:35:46 UTC
File Type:
ELF64 Little (Exe)
AV detection:
12 of 36 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Changes its process name
Checks CPU configuration
Reads system network configuration
Deletes log files
Enumerates active TCP sockets
Enumerates running processes
Deletes Audit logs
Deletes itself
Deletes journal logs
Deletes system logs
Modifies the /etc/hosts DNS resolution file
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_Mirai
Author:NDA0E
Description:Detects multiple Mirai variants
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:has_telegram_urls
Author:Aaron DeVera<aaron@backchannel.re>
Description:Detects Telegram URLs
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
Rule name:test_rule_vldslv
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
Rule name:virustotal
Author:Tracel
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 8402e5704c40778694c3bc16bb76c1e906e3527a976d43b6dbf2cfa3de59da9b

(this sample)

  
Delivery method
Distributed via web download

Comments