🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 97d433c19f469b548abdf32a0121b627e51afde5f2e590c52b89cb894874cae9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 14 File information Comments

SHA256 hash: 97d433c19f469b548abdf32a0121b627e51afde5f2e590c52b89cb894874cae9
SHA3-384 hash: 42a93d1e7c0ef3c2b4feb4f7c719e92125caf8f0dd9524eeb2d074d51b0d3ab92457768df33e44df212f93ec5b3d0602
SHA1 hash: 826d2f7dc31cd6c975af89c7ffce6e4d7ae58f17
MD5 hash: b282e0a93d164f0ceaaa86db11ddc55b
humanhash: oregon-hotel-orange-zulu
File name:getty
Download: download sample
Signature Mirai
File size:87'425 bytes
First seen:2026-09-17 10:46:17 UTC
Last seen:2026-09-17 11:43:36 UTC
File type: elf
MIME type:application/x-executable
ssdeep 1536:JKzaD1BEzNAsWZE9dwOx5MBGqHgPyUwYKXy7ZDdyDoPO/fPAn/fFXn:71BEse9WOx+8qyhwxylDADuO/fPk/fF3
TLSH T133833AD6E643C6B7C8870BB103B7EA3A1522B83B0B1ADE05F7287CB49B674C87125755
telfhash t17411204272be8e286bf25928acb807f1199116237381be30ef4ec1c4553b00ab574e9f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
67
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
gcc
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2026-09-17T06:08:00Z UTC
Last seen:
2026-09-17T07:03:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=8656b1d1-1700-0000-5aba-9ce6c30c0000 pid=3267 /usr/bin/sudo guuid=50dbd2d4-1700-0000-5aba-9ce6c50c0000 pid=3269 /tmp/sample.bin net guuid=8656b1d1-1700-0000-5aba-9ce6c30c0000 pid=3267->guuid=50dbd2d4-1700-0000-5aba-9ce6c50c0000 pid=3269 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=50dbd2d4-1700-0000-5aba-9ce6c50c0000 pid=3269->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=116721d6-1700-0000-5aba-9ce6c90c0000 pid=3273 /tmp/sample.bin guuid=50dbd2d4-1700-0000-5aba-9ce6c50c0000 pid=3269->guuid=116721d6-1700-0000-5aba-9ce6c90c0000 pid=3273 clone guuid=5ad327d6-1700-0000-5aba-9ce6ca0c0000 pid=3274 /tmp/sample.bin net send-data write-config write-file zombie guuid=116721d6-1700-0000-5aba-9ce6c90c0000 pid=3273->guuid=5ad327d6-1700-0000-5aba-9ce6ca0c0000 pid=3274 clone 42c01841-bc96-5dd0-af36-e6323e227624 64.89.160.222:55487 guuid=5ad327d6-1700-0000-5aba-9ce6ca0c0000 pid=3274->42c01841-bc96-5dd0-af36-e6323e227624 send: 107B guuid=bd5763d6-1700-0000-5aba-9ce6cc0c0000 pid=3276 /usr/bin/dash guuid=5ad327d6-1700-0000-5aba-9ce6ca0c0000 pid=3274->guuid=bd5763d6-1700-0000-5aba-9ce6cc0c0000 pid=3276 execve guuid=a1040d32-1800-0000-5aba-9ce66a0d0000 pid=3434 /usr/bin/dash guuid=5ad327d6-1700-0000-5aba-9ce6ca0c0000 pid=3274->guuid=a1040d32-1800-0000-5aba-9ce66a0d0000 pid=3434 execve guuid=a91c7432-1800-0000-5aba-9ce66d0d0000 pid=3437 /usr/bin/dash guuid=5ad327d6-1700-0000-5aba-9ce6ca0c0000 pid=3274->guuid=a91c7432-1800-0000-5aba-9ce66d0d0000 pid=3437 execve guuid=131d91fc-1800-0000-5aba-9ce6740f0000 pid=3956 /usr/bin/dash guuid=5ad327d6-1700-0000-5aba-9ce6ca0c0000 pid=3274->guuid=131d91fc-1800-0000-5aba-9ce6740f0000 pid=3956 execve guuid=f200d5fd-1800-0000-5aba-9ce67b0f0000 pid=3963 /usr/bin/dash guuid=5ad327d6-1700-0000-5aba-9ce6ca0c0000 pid=3274->guuid=f200d5fd-1800-0000-5aba-9ce67b0f0000 pid=3963 execve guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969 /tmp/sample.bin net send-data guuid=5ad327d6-1700-0000-5aba-9ce6ca0c0000 pid=3274->guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969 clone guuid=4e6595d6-1700-0000-5aba-9ce6cd0c0000 pid=3277 /usr/sbin/update-rc.d guuid=bd5763d6-1700-0000-5aba-9ce6cc0c0000 pid=3276->guuid=4e6595d6-1700-0000-5aba-9ce6cd0c0000 pid=3277 execve guuid=2b85eed9-1700-0000-5aba-9ce6d60c0000 pid=3286 /usr/bin/systemctl guuid=4e6595d6-1700-0000-5aba-9ce6cd0c0000 pid=3277->guuid=2b85eed9-1700-0000-5aba-9ce6d60c0000 pid=3286 execve guuid=d9425532-1800-0000-5aba-9ce66c0d0000 pid=3436 /usr/bin/dash guuid=a1040d32-1800-0000-5aba-9ce66a0d0000 pid=3434->guuid=d9425532-1800-0000-5aba-9ce66c0d0000 pid=3436 clone guuid=45a4c232-1800-0000-5aba-9ce66f0d0000 pid=3439 /usr/bin/systemctl guuid=a91c7432-1800-0000-5aba-9ce66d0d0000 pid=3437->guuid=45a4c232-1800-0000-5aba-9ce66f0d0000 pid=3439 execve guuid=f5abe933-1800-0000-5aba-9ce6730d0000 pid=3443 /usr/lib/systemd/systemd-sysv-install guuid=45a4c232-1800-0000-5aba-9ce66f0d0000 pid=3439->guuid=f5abe933-1800-0000-5aba-9ce6730d0000 pid=3443 execve guuid=6d745e34-1800-0000-5aba-9ce6750d0000 pid=3445 /usr/bin/getopt guuid=f5abe933-1800-0000-5aba-9ce6730d0000 pid=3443->guuid=6d745e34-1800-0000-5aba-9ce6750d0000 pid=3445 execve guuid=0d02f335-1800-0000-5aba-9ce67a0d0000 pid=3450 /usr/sbin/update-rc.d guuid=f5abe933-1800-0000-5aba-9ce6730d0000 pid=3443->guuid=0d02f335-1800-0000-5aba-9ce67a0d0000 pid=3450 execve guuid=fb7b5186-1800-0000-5aba-9ce6190e0000 pid=3609 /usr/sbin/update-rc.d guuid=f5abe933-1800-0000-5aba-9ce6730d0000 pid=3443->guuid=fb7b5186-1800-0000-5aba-9ce6190e0000 pid=3609 execve guuid=39340339-1800-0000-5aba-9ce6820d0000 pid=3458 /usr/bin/systemctl guuid=0d02f335-1800-0000-5aba-9ce67a0d0000 pid=3450->guuid=39340339-1800-0000-5aba-9ce6820d0000 pid=3458 execve guuid=45e8458a-1800-0000-5aba-9ce6250e0000 pid=3621 /usr/bin/systemctl guuid=fb7b5186-1800-0000-5aba-9ce6190e0000 pid=3609->guuid=45e8458a-1800-0000-5aba-9ce6250e0000 pid=3621 execve guuid=29275dfd-1800-0000-5aba-9ce6760f0000 pid=3958 /usr/bin/dash guuid=131d91fc-1800-0000-5aba-9ce6740f0000 pid=3956->guuid=29275dfd-1800-0000-5aba-9ce6760f0000 pid=3958 clone guuid=1d7889fd-1800-0000-5aba-9ce6770f0000 pid=3959 /usr/bin/dash guuid=131d91fc-1800-0000-5aba-9ce6740f0000 pid=3956->guuid=1d7889fd-1800-0000-5aba-9ce6770f0000 pid=3959 clone guuid=3a7139fe-1800-0000-5aba-9ce67c0f0000 pid=3964 /usr/bin/cp guuid=f200d5fd-1800-0000-5aba-9ce67b0f0000 pid=3963->guuid=3a7139fe-1800-0000-5aba-9ce67c0f0000 pid=3964 execve guuid=a1d227ff-1800-0000-5aba-9ce67d0f0000 pid=3965 /usr/bin/chmod guuid=f200d5fd-1800-0000-5aba-9ce67b0f0000 pid=3963->guuid=a1d227ff-1800-0000-5aba-9ce67d0f0000 pid=3965 execve ef56fac5-f8a8-5636-b66a-57fb9f3e2e54 238.251.12.32:23 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->ef56fac5-f8a8-5636-b66a-57fb9f3e2e54 con 6877ef8c-0e38-5825-b050-ff0237b6e5d9 238.251.12.32:2323 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->6877ef8c-0e38-5825-b050-ff0237b6e5d9 con 3f7d02c4-9bdf-5df8-9c16-618fa31cfc8f 4.230.135.225:23 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->3f7d02c4-9bdf-5df8-9c16-618fa31cfc8f con 12328275-a098-5a40-ade9-4d032800b5d0 4.230.135.225:2323 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->12328275-a098-5a40-ade9-4d032800b5d0 con ca48797f-5794-58bf-a8e8-e78782d49f19 204.75.83.216:23 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->ca48797f-5794-58bf-a8e8-e78782d49f19 con 8b661bea-b6db-5c64-be50-0c956ca35b50 204.75.83.216:2323 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->8b661bea-b6db-5c64-be50-0c956ca35b50 con 4f156632-63c6-54fe-8303-2342b1c07975 211.189.18.99:23 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->4f156632-63c6-54fe-8303-2342b1c07975 con c2c592df-05e6-5013-b3b4-662fd7024e61 211.189.18.99:2323 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->c2c592df-05e6-5013-b3b4-662fd7024e61 con e7c2fdda-51d2-554d-b4f8-22094a0dcbcb 29.27.56.92:23 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->e7c2fdda-51d2-554d-b4f8-22094a0dcbcb con a9cbdb26-2420-57e5-81ee-b652e7612815 29.27.56.92:2323 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->a9cbdb26-2420-57e5-81ee-b652e7612815 con f284ca5c-fdc2-54f9-8e52-9705bda3e309 28.16.49.79:23 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->f284ca5c-fdc2-54f9-8e52-9705bda3e309 con 0a842290-cd1a-569e-ae8c-eb57a7257ca0 28.16.49.79:2323 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->0a842290-cd1a-569e-ae8c-eb57a7257ca0 con c8d01528-de64-5735-98a4-aaf841eaa730 217.16.216.129:23 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->c8d01528-de64-5735-98a4-aaf841eaa730 con 0857e727-a749-5bda-8a73-f9a120374f96 217.16.216.129:2323 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->0857e727-a749-5bda-8a73-f9a120374f96 con 0f5d1800-ed17-5eb3-89b3-ca5bd73c9d0d 238.246.191.158:23 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->0f5d1800-ed17-5eb3-89b3-ca5bd73c9d0d con 4de46a53-428c-5661-a10c-c4ca5731cc01 238.246.191.158:2323 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->4de46a53-428c-5661-a10c-c4ca5731cc01 con 05552242-4dc6-5112-8acd-a06ac12a9c46 4.231.246.183:23 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->05552242-4dc6-5112-8acd-a06ac12a9c46 con 97ee5f82-48e9-5d3a-accb-953f95b1c195 4.231.246.183:2323 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->97ee5f82-48e9-5d3a-accb-953f95b1c195 con 5e5223a2-fcca-5ace-abab-3dfd798244d5 204.75.10.122:23 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->5e5223a2-fcca-5ace-abab-3dfd798244d5 con 22867216-75ab-5968-8149-c08e925121c4 204.75.10.122:2323 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->22867216-75ab-5968-8149-c08e925121c4 con 0c57c5c2-adfd-57a3-9d98-871bd9e157a2 211.187.163.141:23 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->0c57c5c2-adfd-57a3-9d98-871bd9e157a2 con 09cc78ef-e23e-534f-b84c-de7b8465b3c8 211.187.163.141:2323 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->09cc78ef-e23e-534f-b84c-de7b8465b3c8 send: 6B de6bbb7d-e955-5d74-ab42-da32c15e09a5 29.25.54.202:23 guuid=2184fbff-1800-0000-5aba-9ce6810f0000 pid=3969->de6bbb7d-e955-5d74-ab42-da32c15e09a5 con
Threat name:
Linux.Trojan.LnxGafgyt
Status:
Malicious
First seen:
2026-09-17 10:47:31 UTC
File Type:
ELF32 Little (Exe)
AV detection:
25 of 36 (69.44%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads system network configuration
Modifies Bash startup script
Creates/modifies Cron job
Creates/modifies environment variables
Modifies init.d
Modifies rc script
Modifies systemd
Reads system routing table
Schedules an At job
File and Directory Permissions Modification
Detected Gafgyt variant
Family: Gafgyt/Bashlite
Malware Config
C2 Extraction:
64.89.160.222:55487
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202503_elf_Mirai
Author:abuse.ch
Description:Detects Mirai 'TSource' ELF files
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:ELF_DDoS_Gafgyt_Variant
Author:Serhii Kocherhan
Description:Detects Gafgyt (Qbot) / Mirai variant with specific DDoS functions (vseattack, ftcp, SendHTTPHex) and recon routines
Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Gafgyt_1b2e2a3a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_6122acdf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9127f7be
Author:Elastic Security
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 97d433c19f469b548abdf32a0121b627e51afde5f2e590c52b89cb894874cae9

(this sample)

  
Delivery method
Distributed via web download

Comments