MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 90e4c273928aedc62dbfffbf1a70b9a62ca513c2182f2e8c9e36e354c122b775. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 90e4c273928aedc62dbfffbf1a70b9a62ca513c2182f2e8c9e36e354c122b775
SHA3-384 hash: d4a374cbccbd797b05c270f6942cebf3e6417940c5b2712fc3f65854a5875ed8635f2b292beca35409a04882dd69b60f
SHA1 hash: 65361a4b7d2f9a1a3cfbf67f931b4401c175a94b
MD5 hash: ac93b519bf2275e90a1bdf4400d55577
humanhash: winner-oregon-sodium-emma
File name:mips
Download: download sample
Signature Mirai
File size:222'384 bytes
First seen:2025-11-21 05:01:27 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 6144:4FEhusS8OcikMUH1yY+vYXy3p+F/1FRLMeTpdnZode8WUb3FNXOlRf:l3MWEIf
TLSH T18E24841E5E228F7DF7A8873047B79E20975C23D637E1D645E1ADC2205E6028E641FFA8
telfhash t19f4171580d7817e0a3355c5d09adff7bd6a330db7e162d378e11e85aab69a835d10c0c
Magika elf
Reporter abuse_ch
Tags:elf mirai upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 b996086e3bc5fa52f39a8e2d40e36c113f816399305321a0562febb1782066df
File size (compressed) :62'672 bytes
File size (de-compressed) :222'384 bytes
Format:linux/mips
Packed file: b996086e3bc5fa52f39a8e2d40e36c113f816399305321a0562febb1782066df

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2025-11-21T03:13:00Z UTC
Last seen:
2025-11-21T07:06:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=1553e4f1-1700-0000-576d-e81f690b0000 pid=2921 /usr/bin/sudo guuid=71da20f5-1700-0000-576d-e81f700b0000 pid=2928 /tmp/sample.bin guuid=1553e4f1-1700-0000-576d-e81f690b0000 pid=2921->guuid=71da20f5-1700-0000-576d-e81f700b0000 pid=2928 execve
Gathering data
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Linux.Backdoor.Mirai
Status:
Malicious
First seen:
2025-11-21 05:02:19 UTC
File Type:
ELF32 Big (Exe)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai discovery
Behaviour
System Network Configuration Discovery
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-8041698-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 90e4c273928aedc62dbfffbf1a70b9a62ca513c2182f2e8c9e36e354c122b775

(this sample)

Comments