🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 84c97c076d5e1d5f88d1df21b2cebfa8e1cf87af21cc1165cb090318bf4ecaad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 5 File information Comments

SHA256 hash: 84c97c076d5e1d5f88d1df21b2cebfa8e1cf87af21cc1165cb090318bf4ecaad
SHA3-384 hash: c05d78d42ed5cedbf3992b622be24ad1d36091427d293a78647108d46ed42978f77f487427ea5cac7178659573a2eefc
SHA1 hash: 1480a7aebdc9f4f87ac811e7e1f2e9617561c1c9
MD5 hash: ffb4ab54958421b05cc3e5029beef379
humanhash: five-social-november-freddie
File name:x86_64
Download: download sample
Signature Mirai
File size:119'276 bytes
First seen:2026-09-24 23:43:34 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:xCyC7JCz/KEIiTjJFXe7q+dobJdJvOFlVp3xLP:xCB0z/KRijTeddoNXO3xLP
TLSH T151C312FB43EE887CC92A95771005D5D374EA34FC62C2E95F4887F4BA88649512E62F28
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai UPX
File size (compressed) :119'276 bytes
File size (de-compressed) :261'472 bytes
Format:linux/amd64
Unpacked file: fa74ec466360a516385de64cd0bebca32586f41c17234b4a271ccb1538ac30f7

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Opens a port
Launching a process
Deletes a file
Sets a written file as executable
Sends data to a server
Runs as daemon
Creates directories
Changes access rights for a written file
Connection attempt
Manages services
Receives data from a server
Changes the time when the file was created, accessed, or modified
Mounts file systems
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Writes files to system directory
Creates or modifies files to set up autorun
Creates or modifies files in /init.d to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
packed upx
Status:
terminated
Behavior Graph:
%3 guuid=48d3d761-1b00-0000-0e88-3472370c0000 pid=3127 /usr/bin/sudo guuid=83881364-1b00-0000-0e88-34723a0c0000 pid=3130 /tmp/sample.bin mprotect-exec net guuid=48d3d761-1b00-0000-0e88-3472370c0000 pid=3127->guuid=83881364-1b00-0000-0e88-34723a0c0000 pid=3130 execve 04407053-c071-5e85-b9d6-0cc72ff671fd 217.60.103.135:53 guuid=83881364-1b00-0000-0e88-34723a0c0000 pid=3130->04407053-c071-5e85-b9d6-0cc72ff671fd con guuid=84b0db65-1b00-0000-0e88-34723c0c0000 pid=3132 /tmp/sample.bin guuid=83881364-1b00-0000-0e88-34723a0c0000 pid=3130->guuid=84b0db65-1b00-0000-0e88-34723c0c0000 pid=3132 clone guuid=e34ae865-1b00-0000-0e88-34723d0c0000 pid=3133 /tmp/sample.bin guuid=84b0db65-1b00-0000-0e88-34723c0c0000 pid=3132->guuid=e34ae865-1b00-0000-0e88-34723d0c0000 pid=3133 clone guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134 /tmp/sample.bin delete-file net send-data write-config write-file guuid=e34ae865-1b00-0000-0e88-34723d0c0000 pid=3133->guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134 clone c89879ea-e323-5ddf-aafa-e03018d8dc55 217.60.103.135:35342 guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134->c89879ea-e323-5ddf-aafa-e03018d8dc55 send: 40B guuid=0fc57866-1b00-0000-0e88-34723f0c0000 pid=3135 /tmp/sample.bin guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134->guuid=0fc57866-1b00-0000-0e88-34723f0c0000 pid=3135 clone guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136 /tmp/sample.bin write-config write-file guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134->guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136 clone guuid=513e9c66-1b00-0000-0e88-3472410c0000 pid=3137 /tmp/sample.bin guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134->guuid=513e9c66-1b00-0000-0e88-3472410c0000 pid=3137 clone guuid=f8b7d067-1b00-0000-0e88-3472420c0000 pid=3138 /usr/bin/dash guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134->guuid=f8b7d067-1b00-0000-0e88-3472420c0000 pid=3138 execve guuid=571a38e7-1b00-0000-0e88-3472db0c0000 pid=3291 /usr/bin/dash guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134->guuid=571a38e7-1b00-0000-0e88-3472db0c0000 pid=3291 execve guuid=1330cc3b-1c00-0000-0e88-3472660d0000 pid=3430 /usr/bin/dash guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134->guuid=1330cc3b-1c00-0000-0e88-3472660d0000 pid=3430 execve guuid=9f915541-1c00-0000-0e88-3472700d0000 pid=3440 /usr/bin/dash guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134->guuid=9f915541-1c00-0000-0e88-3472700d0000 pid=3440 execve guuid=ee7a8aac-1c00-0000-0e88-3472f50d0000 pid=3573 /usr/bin/dash guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134->guuid=ee7a8aac-1c00-0000-0e88-3472f50d0000 pid=3573 execve guuid=a9bfedac-1c00-0000-0e88-3472f60d0000 pid=3574 /usr/bin/dash guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134->guuid=a9bfedac-1c00-0000-0e88-3472f60d0000 pid=3574 execve guuid=9d9b58ad-1c00-0000-0e88-3472f90d0000 pid=3577 /usr/bin/dash guuid=fc68f065-1b00-0000-0e88-34723e0c0000 pid=3134->guuid=9d9b58ad-1c00-0000-0e88-3472f90d0000 pid=3577 execve guuid=6f700f08-1d00-0000-0e88-3472c20e0000 pid=3778 /usr/bin/dash guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=6f700f08-1d00-0000-0e88-3472c20e0000 pid=3778 execve guuid=0a2ebf10-1d00-0000-0e88-3472d10e0000 pid=3793 /usr/bin/dash guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=0a2ebf10-1d00-0000-0e88-3472d10e0000 pid=3793 execve guuid=91c9441a-1d00-0000-0e88-3472ec0e0000 pid=3820 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=91c9441a-1d00-0000-0e88-3472ec0e0000 pid=3820 clone guuid=ab09831a-1d00-0000-0e88-3472ed0e0000 pid=3821 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=ab09831a-1d00-0000-0e88-3472ed0e0000 pid=3821 clone guuid=6694db1a-1d00-0000-0e88-3472ee0e0000 pid=3822 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=6694db1a-1d00-0000-0e88-3472ee0e0000 pid=3822 clone guuid=0a0f321b-1d00-0000-0e88-3472f00e0000 pid=3824 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=0a0f321b-1d00-0000-0e88-3472f00e0000 pid=3824 clone guuid=c3e2781b-1d00-0000-0e88-3472f20e0000 pid=3826 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=c3e2781b-1d00-0000-0e88-3472f20e0000 pid=3826 clone guuid=615da11b-1d00-0000-0e88-3472f30e0000 pid=3827 /usr/bin/dash guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=615da11b-1d00-0000-0e88-3472f30e0000 pid=3827 execve guuid=6251a123-1d00-0000-0e88-3472080f0000 pid=3848 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=6251a123-1d00-0000-0e88-3472080f0000 pid=3848 clone guuid=c1740e25-1d00-0000-0e88-34720a0f0000 pid=3850 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=c1740e25-1d00-0000-0e88-34720a0f0000 pid=3850 clone guuid=a9756b25-1d00-0000-0e88-34720c0f0000 pid=3852 /usr/bin/dash guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=a9756b25-1d00-0000-0e88-34720c0f0000 pid=3852 execve guuid=ceabb52f-1d00-0000-0e88-34721f0f0000 pid=3871 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=ceabb52f-1d00-0000-0e88-34721f0f0000 pid=3871 clone guuid=edfee930-1d00-0000-0e88-3472200f0000 pid=3872 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=edfee930-1d00-0000-0e88-3472200f0000 pid=3872 clone guuid=6227e035-1d00-0000-0e88-3472250f0000 pid=3877 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=6227e035-1d00-0000-0e88-3472250f0000 pid=3877 clone guuid=a223e535-1d00-0000-0e88-3472260f0000 pid=3878 /usr/bin/busybox guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=a223e535-1d00-0000-0e88-3472260f0000 pid=3878 execve guuid=a374ec35-1d00-0000-0e88-3472280f0000 pid=3880 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=a374ec35-1d00-0000-0e88-3472280f0000 pid=3880 clone guuid=3e7ff135-1d00-0000-0e88-3472290f0000 pid=3881 /usr/bin/busybox guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=3e7ff135-1d00-0000-0e88-3472290f0000 pid=3881 execve guuid=86c1f635-1d00-0000-0e88-34722a0f0000 pid=3882 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=86c1f635-1d00-0000-0e88-34722a0f0000 pid=3882 clone guuid=90edfb35-1d00-0000-0e88-34722b0f0000 pid=3883 /tmp/sample.bin guuid=4ffb8c66-1b00-0000-0e88-3472400c0000 pid=3136->guuid=90edfb35-1d00-0000-0e88-34722b0f0000 pid=3883 clone guuid=01892068-1b00-0000-0e88-3472430c0000 pid=3139 /usr/bin/systemctl guuid=f8b7d067-1b00-0000-0e88-3472420c0000 pid=3138->guuid=01892068-1b00-0000-0e88-3472430c0000 pid=3139 execve guuid=18e47ce7-1b00-0000-0e88-3472dd0c0000 pid=3293 /usr/bin/systemctl guuid=571a38e7-1b00-0000-0e88-3472db0c0000 pid=3291->guuid=18e47ce7-1b00-0000-0e88-3472dd0c0000 pid=3293 execve guuid=cab2663c-1c00-0000-0e88-3472680d0000 pid=3432 /usr/bin/systemctl guuid=1330cc3b-1c00-0000-0e88-3472660d0000 pid=3430->guuid=cab2663c-1c00-0000-0e88-3472680d0000 pid=3432 execve guuid=4360bb41-1c00-0000-0e88-3472710d0000 pid=3441 /usr/sbin/update-rc.d guuid=9f915541-1c00-0000-0e88-3472700d0000 pid=3440->guuid=4360bb41-1c00-0000-0e88-3472710d0000 pid=3441 execve guuid=b151a050-1c00-0000-0e88-3472800d0000 pid=3456 /usr/bin/systemctl guuid=4360bb41-1c00-0000-0e88-3472710d0000 pid=3441->guuid=b151a050-1c00-0000-0e88-3472800d0000 pid=3456 execve guuid=87bb9dad-1c00-0000-0e88-3472fa0d0000 pid=3578 /usr/bin/dash guuid=9d9b58ad-1c00-0000-0e88-3472f90d0000 pid=3577->guuid=87bb9dad-1c00-0000-0e88-3472fa0d0000 pid=3578 clone guuid=c7aeb0ad-1c00-0000-0e88-3472fb0d0000 pid=3579 /usr/bin/dash guuid=9d9b58ad-1c00-0000-0e88-3472f90d0000 pid=3577->guuid=c7aeb0ad-1c00-0000-0e88-3472fb0d0000 pid=3579 clone
Result
Threat name:
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Drops files in suspicious directories
Executes the "crontab" command typically for achieving persistence
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Multi AV Scanner detection for submitted file
Protects files from modification
Sample deletes itself
Sample is packed with UPX
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Sample tries to set files in /etc globally writable
Searches for VM related strings in files or piped streams (probably for evasion)
Writes ELF files to hidden directories
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1977970 Sample: x86_64.elf Startdate: 25/09/2026 Architecture: LINUX Score: 100 114 169.254.169.254, 80 USDOS-USDepartmentofStateUS ZZ 2->114 116 217.60.103.135, 34770, 35342 HOSTSNAP-NETWORK-HostSNAPLLCUS Switzerland 2->116 118 daisy.ubuntu.com 91.189.95.56, 443, 53442, 53444 CANONICAL-ASGB United Kingdom 2->118 120 Multi AV Scanner detection for submitted file 2->120 122 Yara detected Mirai 2->122 124 Sample is packed with UPX 2->124 12 systemd (deleted) whoopsie-upload-all 2->12         started        14 x86_64.elf 2->14         started        16 systemd (deleted) snapd-env-generator 2->16         started        18 26 other processes 2->18 signatures3 process4 process5 20 whoopsie-upload-all fgrep grep 12->20         started        23 whoopsie-upload-all fgrep grep 12->23         started        25 whoopsie-upload-all fgrep grep 12->25         started        29 234 other processes 12->29 27 x86_64.elf 14->27         started        signatures6 126 Searches for VM related strings in files or piped streams (probably for evasion) 20->126 31 x86_64.elf 27->31         started        33 ldd 29->33         started        35 ldd 29->35         started        37 ldd 29->37         started        39 17 other processes 29->39 process7 process8 41 x86_64.elf 31->41         started        45 ldd 33->45         started        47 ldd 35->47         started        49 ldd 37->49         started        51 ldd ld-linux.so.2 39->51         started        53 ldd ld-linux-x86-64.so.2 39->53         started        55 ldd ld-linux.so.2 39->55         started        57 3 other processes 39->57 file9 102 /var/tmp/.cache/sysd, ELF 41->102 dropped 104 /etc/systemd/system/system-service.service, ASCII 41->104 dropped 106 /etc/rc.local, POSIX 41->106 dropped 108 /etc/init.d/system-service, POSIX 41->108 dropped 128 Sample tries to set files in /etc globally writable 41->128 130 Writes ELF files to hidden directories 41->130 132 Drops files in suspicious directories 41->132 134 2 other signatures 41->134 59 x86_64.elf 41->59         started        63 x86_64.elf sh 41->63         started        65 x86_64.elf sh 41->65         started        73 7 other processes 41->73 67 ldd ld-linux-x86-64.so.2 45->67         started        69 ldd ld-linux-x86-64.so.2 47->69         started        71 ldd ld-linux-x86-64.so.2 49->71         started        signatures10 process11 file12 110 /root/.bashrc, ASCII 59->110 dropped 112 /etc/profile, ASCII 59->112 dropped 144 Sample tries to persist itself using /etc/profile 59->144 146 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 59->146 75 x86_64.elf 59->75         started        78 x86_64.elf 59->78         started        80 x86_64.elf 59->80         started        91 16 other processes 59->91 82 sh crontab 63->82         started        85 sh 63->85         started        87 sh update-rc.d 65->87         started        148 Sample reads /proc/mounts (often used for finding a writable filesystem) 73->148 89 sh crontab 73->89         started        93 3 other processes 73->93 signatures13 process14 file15 136 Protects files from modification 75->136 100 /var/spool/cron/crontabs/tmp.VwjiTG, ASCII 82->100 dropped 138 Sample tries to persist itself using cron 82->138 140 Executes the "crontab" command typically for achieving persistence 82->140 95 sh crontab 85->95         started        142 Sample tries to persist itself using System V runlevels 87->142 98 update-rc.d systemctl 87->98         started        signatures16 process17 signatures18 150 Executes the "crontab" command typically for achieving persistence 95->150
Threat name:
Linux.Network.Generic
Status:
Suspicious
First seen:
2026-09-24 23:44:32 UTC
File Type:
ELF64 Little (Exe)
AV detection:
6 of 36 (16.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
credential_access defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Changes its process name
Reads system network configuration
Modifies Bash startup script
Reads process memory
Creates/modifies Cron job
Creates/modifies environment variables
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
Modifies systemd
Modifies the /etc/hosts DNS resolution file
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_IoT_DVR_Botnet_Hama_UPX
Author:Serhii Kocherhan
Description:Detects packed and unpacked ELF IoT/DVR botnet variants targeting UPX compression structures and uncompressed code
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 84c97c076d5e1d5f88d1df21b2cebfa8e1cf87af21cc1165cb090318bf4ecaad

(this sample)

  
Delivery method
Distributed via web download

Comments