MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8e3b4d67fe786c9d8669241cdd3db09457ed3fb7019fdb6b3856a2085b1d29fd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 8e3b4d67fe786c9d8669241cdd3db09457ed3fb7019fdb6b3856a2085b1d29fd
SHA3-384 hash: 875721e46df1e942af935cb10dcbcc6fbf7755f63deb5c52162cc5185d536331c6f71a426d113a4318763c678284aa65
SHA1 hash: f99c178dbabb6b21c62b7624786e2a2056466920
MD5 hash: 8ff62bfe2bf73d81d785c6fdecb5ad94
humanhash: uranus-beer-burger-green
File name:m68k
Download: download sample
Signature Mirai
File size:71'956 bytes
First seen:2025-11-01 12:36:47 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:DHOOyVbzvuG01CtI8TnyWIqJsiiACuBXJ5P2GgwxaEV9j:DuOyVbzvtCCt9yWIqJquB5lIEV5
TLSH T1AF633BD5F801DE7DF41EE7BE8453090AF730A36152C30F3A26ABBC57A97216519A3E81
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
128
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2025-11-01T08:51:00Z UTC
Last seen:
2025-11-01T13:38:00Z UTC
Hits:
~10
Detections:
HEUR:Backdoor.Linux.Mirai.b
Status:
terminated
Behavior Graph:
%3 guuid=15112f59-1900-0000-c0d1-6b9c2b0b0000 pid=2859 /usr/bin/sudo guuid=495d735b-1900-0000-c0d1-6b9c320b0000 pid=2866 /tmp/sample.bin guuid=15112f59-1900-0000-c0d1-6b9c2b0b0000 pid=2859->guuid=495d735b-1900-0000-c0d1-6b9c320b0000 pid=2866 execve
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
56 / 100
Signature
Multi AV Scanner detection for submitted file
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1806281 Sample: m68k.elf Startdate: 01/11/2025 Architecture: LINUX Score: 56 18 flibberwock.cfd 185.14.92.55, 23, 34306, 34308 INTERCOLO-ASintercoloIP-BackboneDE Germany 2->18 20 109.202.202.202, 80 INIT7CH Switzerland 2->20 22 4 other IPs or domains 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Yara detected Mirai 2->26 8 m68k.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 m68k.elf 8->14         started        process6 16 m68k.elf 14->16         started       
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-11-01 11:46:49 UTC
File Type:
ELF32 Big (Exe)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 8e3b4d67fe786c9d8669241cdd3db09457ed3fb7019fdb6b3856a2085b1d29fd

(this sample)

  
Delivery method
Distributed via web download

Comments