MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 91a54105a0aae3ad81a2e3eebc3ce15a40ba55b35fa2b34ebcda4b64ffd5a034. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 91a54105a0aae3ad81a2e3eebc3ce15a40ba55b35fa2b34ebcda4b64ffd5a034
SHA3-384 hash: 364377e30fe3d1d6e6ca4c6536b339c9cc1eec07bbdde9af4d7182beea8826927198118f18faf55b89afca68c4212364
SHA1 hash: d5004f1f0caa300526fd353af1d16d59bcab59a2
MD5 hash: 3c9f55a9c2917192970221f1abacc96f
humanhash: don-beryllium-burger-winter
File name:m68k
Download: download sample
Signature Mirai
File size:90'244 bytes
First seen:2025-11-05 07:18:27 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:Nfh5RffdMXYEBraD6FKv5hx/8ibyK0gFm6lKSo2zpTbg94GArgudTbEYo:NHRnberycKv5hxFyK0gISV9wArguJbEd
TLSH T1CC936CA1FC02EEBDF40FD77B84474919B230A3A125935F362397BE57A8351994C63E81
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
140
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2025-11-05T04:22:00Z UTC
Last seen:
2025-11-07T01:56:00Z UTC
Hits:
~10
Detections:
HEUR:Backdoor.Linux.Mirai.b
Status:
terminated
Behavior Graph:
%3 guuid=64eb330f-1700-0000-62f6-7189360e0000 pid=3638 /usr/bin/sudo guuid=5e1c5e11-1700-0000-62f6-71893f0e0000 pid=3647 /tmp/sample.bin guuid=64eb330f-1700-0000-62f6-7189360e0000 pid=3638->guuid=5e1c5e11-1700-0000-62f6-71893f0e0000 pid=3647 execve
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
56 / 100
Signature
Multi AV Scanner detection for submitted file
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1808357 Sample: m68k.elf Startdate: 05/11/2025 Architecture: LINUX Score: 56 12 109.202.202.202, 80 INIT7CH Switzerland 2->12 14 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->14 16 2 other IPs or domains 2->16 18 Multi AV Scanner detection for submitted file 2->18 20 Yara detected Mirai 2->20 6 dash rm 2->6         started        8 dash rm 2->8         started        10 m68k.elf 2->10         started        signatures3 process4
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-11-05 07:19:37 UTC
File Type:
ELF32 Big (Exe)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai linux
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-6981989-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 91a54105a0aae3ad81a2e3eebc3ce15a40ba55b35fa2b34ebcda4b64ffd5a034

(this sample)

  
Delivery method
Distributed via web download

Comments