MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9a6cac4c1a037f48ffedbba6844d021ef09320ffffa144a938cb3c3d0aed7137. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 12


Intelligence 12 IOCs YARA 13 File information Comments

SHA256 hash: 9a6cac4c1a037f48ffedbba6844d021ef09320ffffa144a938cb3c3d0aed7137
SHA3-384 hash: 48da4f37b79beb08f98a9745e182bb723ad30348eed83db35bcfa079d2bc15027eaa7ebd5b3a7759ef83866b12865659
SHA1 hash: cebc82de37c0b67bea660c3997e35aa7ea721fab
MD5 hash: 1aea315937aa7a7ddbacecbc67ec32fc
humanhash: east-ten-avocado-georgia
File name:iotmirai_x86
Download: download sample
Signature Mirai
File size:95'112 bytes
First seen:2025-07-24 21:20:40 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:zhi7L7jdbbdtqC4R19Z/gxx9pyoZh99fstWxoQAwsuSeQlpk:zhcL7jdbbaCazZ/g3j9YWOnh3rDk
TLSH T17A935CC4F643D4F6EC5705B16077EB379B32E5B9101AEA83C369AE32DC91501EA06B6C
telfhash t1fd5107f71e6e09fcf3c06c08c31f6bd16a29d73b147076a245b25ca423e6d825066c39
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Connection attempt
Kills processes
Runs as daemon
Traces processes
Substitutes an application name
Deleting of the original file
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
bash lolbin mirai
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
1
Number of processes launched:
5
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Process Renaming
Anti-Debugging
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=d3e7f066-1900-0000-c6f1-174c3b140000 pid=5179 /usr/bin/sudo guuid=6bdba968-1900-0000-c6f1-174c48140000 pid=5192 /tmp/sample.bin delete-file net guuid=d3e7f066-1900-0000-c6f1-174c3b140000 pid=5179->guuid=6bdba968-1900-0000-c6f1-174c48140000 pid=5192 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=6bdba968-1900-0000-c6f1-174c48140000 pid=5192->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fb55d868-1900-0000-c6f1-174c4b140000 pid=5195 /tmp/sample.bin zombie guuid=6bdba968-1900-0000-c6f1-174c48140000 pid=5192->guuid=fb55d868-1900-0000-c6f1-174c4b140000 pid=5195 clone guuid=1c98ed68-1900-0000-c6f1-174c4c140000 pid=5196 /tmp/sample.bin guuid=fb55d868-1900-0000-c6f1-174c4b140000 pid=5195->guuid=1c98ed68-1900-0000-c6f1-174c4c140000 pid=5196 clone guuid=7441f268-1900-0000-c6f1-174c4d140000 pid=5197 /tmp/sample.bin guuid=fb55d868-1900-0000-c6f1-174c4b140000 pid=5195->guuid=7441f268-1900-0000-c6f1-174c4d140000 pid=5197 clone guuid=b4290369-1900-0000-c6f1-174c4e140000 pid=5198 /tmp/sample.bin delete-file write-config zombie guuid=7441f268-1900-0000-c6f1-174c4d140000 pid=5197->guuid=b4290369-1900-0000-c6f1-174c4e140000 pid=5198 clone guuid=da06206c-1900-0000-c6f1-174c62140000 pid=5218 /usr/bin/dash guuid=b4290369-1900-0000-c6f1-174c4e140000 pid=5198->guuid=da06206c-1900-0000-c6f1-174c62140000 pid=5218 execve guuid=ae5cc16c-1900-0000-c6f1-174c64140000 pid=5220 /usr/bin/dash guuid=b4290369-1900-0000-c6f1-174c4e140000 pid=5198->guuid=ae5cc16c-1900-0000-c6f1-174c64140000 pid=5220 execve guuid=1603fa6c-1900-0000-c6f1-174c65140000 pid=5221 /tmp/sample.bin guuid=b4290369-1900-0000-c6f1-174c4e140000 pid=5198->guuid=1603fa6c-1900-0000-c6f1-174c65140000 pid=5221 clone guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222 /tmp/sample.bin net send-data guuid=b4290369-1900-0000-c6f1-174c4e140000 pid=5198->guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222 clone guuid=3202496c-1900-0000-c6f1-174c63140000 pid=5219 /usr/bin/cp guuid=da06206c-1900-0000-c6f1-174c62140000 pid=5218->guuid=3202496c-1900-0000-c6f1-174c63140000 pid=5219 execve guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1170B 32d458a0-a40f-565e-b5ae-91358dd4506a 115.11.111.11:22 guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->32d458a0-a40f-565e-b5ae-91358dd4506a send: 2B guuid=3ed10d6d-1900-0000-c6f1-174c67140000 pid=5223 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=3ed10d6d-1900-0000-c6f1-174c67140000 pid=5223 execve guuid=8bdba86d-1900-0000-c6f1-174c69140000 pid=5225 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=8bdba86d-1900-0000-c6f1-174c69140000 pid=5225 execve guuid=e4332d6e-1900-0000-c6f1-174c6b140000 pid=5227 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=e4332d6e-1900-0000-c6f1-174c6b140000 pid=5227 execve guuid=2a31a56e-1900-0000-c6f1-174c6d140000 pid=5229 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=2a31a56e-1900-0000-c6f1-174c6d140000 pid=5229 execve guuid=f2be1e6f-1900-0000-c6f1-174c6f140000 pid=5231 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=f2be1e6f-1900-0000-c6f1-174c6f140000 pid=5231 execve guuid=67329f6f-1900-0000-c6f1-174c71140000 pid=5233 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=67329f6f-1900-0000-c6f1-174c71140000 pid=5233 execve guuid=a6c02870-1900-0000-c6f1-174c73140000 pid=5235 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=a6c02870-1900-0000-c6f1-174c73140000 pid=5235 execve guuid=3fdeb570-1900-0000-c6f1-174c75140000 pid=5237 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=3fdeb570-1900-0000-c6f1-174c75140000 pid=5237 execve guuid=b46c4d71-1900-0000-c6f1-174c77140000 pid=5239 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=b46c4d71-1900-0000-c6f1-174c77140000 pid=5239 execve guuid=61f10272-1900-0000-c6f1-174c79140000 pid=5241 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=61f10272-1900-0000-c6f1-174c79140000 pid=5241 execve guuid=d3ddbf72-1900-0000-c6f1-174c7b140000 pid=5243 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=d3ddbf72-1900-0000-c6f1-174c7b140000 pid=5243 execve guuid=c94a7e73-1900-0000-c6f1-174c7d140000 pid=5245 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=c94a7e73-1900-0000-c6f1-174c7d140000 pid=5245 execve guuid=3790c474-1900-0000-c6f1-174c7f140000 pid=5247 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=3790c474-1900-0000-c6f1-174c7f140000 pid=5247 execve guuid=e8a8c175-1900-0000-c6f1-174c81140000 pid=5249 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=e8a8c175-1900-0000-c6f1-174c81140000 pid=5249 execve guuid=b434c976-1900-0000-c6f1-174c83140000 pid=5251 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=b434c976-1900-0000-c6f1-174c83140000 pid=5251 execve guuid=607cc577-1900-0000-c6f1-174c85140000 pid=5253 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=607cc577-1900-0000-c6f1-174c85140000 pid=5253 execve guuid=1c578c78-1900-0000-c6f1-174c87140000 pid=5255 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=1c578c78-1900-0000-c6f1-174c87140000 pid=5255 execve guuid=89339579-1900-0000-c6f1-174c89140000 pid=5257 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=89339579-1900-0000-c6f1-174c89140000 pid=5257 execve guuid=67ed407a-1900-0000-c6f1-174c8b140000 pid=5259 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=67ed407a-1900-0000-c6f1-174c8b140000 pid=5259 execve guuid=a24af07a-1900-0000-c6f1-174c8d140000 pid=5261 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=a24af07a-1900-0000-c6f1-174c8d140000 pid=5261 execve guuid=9d9e957b-1900-0000-c6f1-174c8f140000 pid=5263 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=9d9e957b-1900-0000-c6f1-174c8f140000 pid=5263 execve guuid=b9903b7c-1900-0000-c6f1-174c91140000 pid=5265 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=b9903b7c-1900-0000-c6f1-174c91140000 pid=5265 execve guuid=d91aeb7c-1900-0000-c6f1-174c93140000 pid=5267 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=d91aeb7c-1900-0000-c6f1-174c93140000 pid=5267 execve guuid=5379027f-1900-0000-c6f1-174c95140000 pid=5269 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=5379027f-1900-0000-c6f1-174c95140000 pid=5269 execve guuid=fbf91e80-1900-0000-c6f1-174c98140000 pid=5272 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=fbf91e80-1900-0000-c6f1-174c98140000 pid=5272 execve guuid=91fa0f81-1900-0000-c6f1-174c9c140000 pid=5276 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=91fa0f81-1900-0000-c6f1-174c9c140000 pid=5276 execve guuid=9a6f0182-1900-0000-c6f1-174c9e140000 pid=5278 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=9a6f0182-1900-0000-c6f1-174c9e140000 pid=5278 execve guuid=5479b682-1900-0000-c6f1-174ca0140000 pid=5280 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=5479b682-1900-0000-c6f1-174ca0140000 pid=5280 execve guuid=d6935783-1900-0000-c6f1-174ca2140000 pid=5282 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=d6935783-1900-0000-c6f1-174ca2140000 pid=5282 execve guuid=e62bf283-1900-0000-c6f1-174ca4140000 pid=5284 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=e62bf283-1900-0000-c6f1-174ca4140000 pid=5284 execve guuid=29197c84-1900-0000-c6f1-174ca6140000 pid=5286 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=29197c84-1900-0000-c6f1-174ca6140000 pid=5286 execve guuid=09231f85-1900-0000-c6f1-174ca8140000 pid=5288 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=09231f85-1900-0000-c6f1-174ca8140000 pid=5288 execve guuid=fda3e385-1900-0000-c6f1-174cac140000 pid=5292 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=fda3e385-1900-0000-c6f1-174cac140000 pid=5292 execve guuid=0ded4087-1900-0000-c6f1-174cb4140000 pid=5300 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=0ded4087-1900-0000-c6f1-174cb4140000 pid=5300 execve guuid=06b81088-1900-0000-c6f1-174cb6140000 pid=5302 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=06b81088-1900-0000-c6f1-174cb6140000 pid=5302 execve guuid=a8fae088-1900-0000-c6f1-174cb8140000 pid=5304 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=a8fae088-1900-0000-c6f1-174cb8140000 pid=5304 execve guuid=92db8389-1900-0000-c6f1-174cba140000 pid=5306 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=92db8389-1900-0000-c6f1-174cba140000 pid=5306 execve guuid=ce6e168a-1900-0000-c6f1-174cbc140000 pid=5308 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=ce6e168a-1900-0000-c6f1-174cbc140000 pid=5308 execve guuid=525fa58a-1900-0000-c6f1-174cbe140000 pid=5310 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=525fa58a-1900-0000-c6f1-174cbe140000 pid=5310 execve guuid=b3aa1f8b-1900-0000-c6f1-174cc0140000 pid=5312 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=b3aa1f8b-1900-0000-c6f1-174cc0140000 pid=5312 execve guuid=25b1b28b-1900-0000-c6f1-174cc2140000 pid=5314 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=25b1b28b-1900-0000-c6f1-174cc2140000 pid=5314 execve guuid=9579538c-1900-0000-c6f1-174cc4140000 pid=5316 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=9579538c-1900-0000-c6f1-174cc4140000 pid=5316 execve guuid=abfee88c-1900-0000-c6f1-174cc6140000 pid=5318 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=abfee88c-1900-0000-c6f1-174cc6140000 pid=5318 execve guuid=f4c58e8d-1900-0000-c6f1-174cc8140000 pid=5320 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=f4c58e8d-1900-0000-c6f1-174cc8140000 pid=5320 execve guuid=0e59318e-1900-0000-c6f1-174cca140000 pid=5322 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=0e59318e-1900-0000-c6f1-174cca140000 pid=5322 execve guuid=504f028f-1900-0000-c6f1-174ccc140000 pid=5324 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=504f028f-1900-0000-c6f1-174ccc140000 pid=5324 execve guuid=9a8dbe8f-1900-0000-c6f1-174cce140000 pid=5326 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=9a8dbe8f-1900-0000-c6f1-174cce140000 pid=5326 execve guuid=4b1f7890-1900-0000-c6f1-174cd0140000 pid=5328 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=4b1f7890-1900-0000-c6f1-174cd0140000 pid=5328 execve guuid=69282c91-1900-0000-c6f1-174cd2140000 pid=5330 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=69282c91-1900-0000-c6f1-174cd2140000 pid=5330 execve guuid=202ec591-1900-0000-c6f1-174cd4140000 pid=5332 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=202ec591-1900-0000-c6f1-174cd4140000 pid=5332 execve guuid=c9175a92-1900-0000-c6f1-174cd6140000 pid=5334 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=c9175a92-1900-0000-c6f1-174cd6140000 pid=5334 execve guuid=0599df92-1900-0000-c6f1-174cd8140000 pid=5336 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=0599df92-1900-0000-c6f1-174cd8140000 pid=5336 execve guuid=41a36193-1900-0000-c6f1-174cda140000 pid=5338 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=41a36193-1900-0000-c6f1-174cda140000 pid=5338 execve guuid=0c41f593-1900-0000-c6f1-174cdc140000 pid=5340 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=0c41f593-1900-0000-c6f1-174cdc140000 pid=5340 execve guuid=63258b94-1900-0000-c6f1-174cde140000 pid=5342 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=63258b94-1900-0000-c6f1-174cde140000 pid=5342 execve guuid=d95f4095-1900-0000-c6f1-174ce0140000 pid=5344 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=d95f4095-1900-0000-c6f1-174ce0140000 pid=5344 execve guuid=4ee0ee95-1900-0000-c6f1-174ce2140000 pid=5346 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=4ee0ee95-1900-0000-c6f1-174ce2140000 pid=5346 execve guuid=328a9d96-1900-0000-c6f1-174ce4140000 pid=5348 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=328a9d96-1900-0000-c6f1-174ce4140000 pid=5348 execve guuid=2e013a97-1900-0000-c6f1-174ce6140000 pid=5350 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=2e013a97-1900-0000-c6f1-174ce6140000 pid=5350 execve guuid=e57fdf97-1900-0000-c6f1-174ce8140000 pid=5352 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=e57fdf97-1900-0000-c6f1-174ce8140000 pid=5352 execve guuid=0c908998-1900-0000-c6f1-174cea140000 pid=5354 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=0c908998-1900-0000-c6f1-174cea140000 pid=5354 execve guuid=ee63eb99-1900-0000-c6f1-174cec140000 pid=5356 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=ee63eb99-1900-0000-c6f1-174cec140000 pid=5356 execve guuid=a9d7029b-1900-0000-c6f1-174cee140000 pid=5358 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=a9d7029b-1900-0000-c6f1-174cee140000 pid=5358 execve guuid=28013a9c-1900-0000-c6f1-174cf0140000 pid=5360 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=28013a9c-1900-0000-c6f1-174cf0140000 pid=5360 execve guuid=7fbdaf9d-1900-0000-c6f1-174cf2140000 pid=5362 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=7fbdaf9d-1900-0000-c6f1-174cf2140000 pid=5362 execve guuid=78fad59e-1900-0000-c6f1-174cf4140000 pid=5364 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=78fad59e-1900-0000-c6f1-174cf4140000 pid=5364 execve guuid=b1d601a0-1900-0000-c6f1-174cf6140000 pid=5366 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=b1d601a0-1900-0000-c6f1-174cf6140000 pid=5366 execve guuid=57d12ba1-1900-0000-c6f1-174cf8140000 pid=5368 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=57d12ba1-1900-0000-c6f1-174cf8140000 pid=5368 execve guuid=05f839a2-1900-0000-c6f1-174cfa140000 pid=5370 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=05f839a2-1900-0000-c6f1-174cfa140000 pid=5370 execve guuid=f9dc5ea3-1900-0000-c6f1-174cfc140000 pid=5372 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=f9dc5ea3-1900-0000-c6f1-174cfc140000 pid=5372 execve guuid=80488ca4-1900-0000-c6f1-174cfe140000 pid=5374 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=80488ca4-1900-0000-c6f1-174cfe140000 pid=5374 execve guuid=6b74a6a5-1900-0000-c6f1-174c00150000 pid=5376 /usr/bin/dash guuid=8194026d-1900-0000-c6f1-174c66140000 pid=5222->guuid=6b74a6a5-1900-0000-c6f1-174c00150000 pid=5376 execve guuid=3276496d-1900-0000-c6f1-174c68140000 pid=5224 /usr/bin/mv guuid=3ed10d6d-1900-0000-c6f1-174c67140000 pid=5223->guuid=3276496d-1900-0000-c6f1-174c68140000 pid=5224 execve guuid=59e7d56d-1900-0000-c6f1-174c6a140000 pid=5226 /usr/bin/mv guuid=8bdba86d-1900-0000-c6f1-174c69140000 pid=5225->guuid=59e7d56d-1900-0000-c6f1-174c6a140000 pid=5226 execve guuid=585b516e-1900-0000-c6f1-174c6c140000 pid=5228 /usr/bin/mv guuid=e4332d6e-1900-0000-c6f1-174c6b140000 pid=5227->guuid=585b516e-1900-0000-c6f1-174c6c140000 pid=5228 execve guuid=ec1dca6e-1900-0000-c6f1-174c6e140000 pid=5230 /usr/bin/mv guuid=2a31a56e-1900-0000-c6f1-174c6d140000 pid=5229->guuid=ec1dca6e-1900-0000-c6f1-174c6e140000 pid=5230 execve guuid=ca6e436f-1900-0000-c6f1-174c70140000 pid=5232 /usr/bin/mv guuid=f2be1e6f-1900-0000-c6f1-174c6f140000 pid=5231->guuid=ca6e436f-1900-0000-c6f1-174c70140000 pid=5232 execve guuid=f998c86f-1900-0000-c6f1-174c72140000 pid=5234 /usr/bin/mv guuid=67329f6f-1900-0000-c6f1-174c71140000 pid=5233->guuid=f998c86f-1900-0000-c6f1-174c72140000 pid=5234 execve guuid=afc25270-1900-0000-c6f1-174c74140000 pid=5236 /usr/bin/mv guuid=a6c02870-1900-0000-c6f1-174c73140000 pid=5235->guuid=afc25270-1900-0000-c6f1-174c74140000 pid=5236 execve guuid=1256e670-1900-0000-c6f1-174c76140000 pid=5238 /usr/bin/mv guuid=3fdeb570-1900-0000-c6f1-174c75140000 pid=5237->guuid=1256e670-1900-0000-c6f1-174c76140000 pid=5238 execve guuid=2b4f8571-1900-0000-c6f1-174c78140000 pid=5240 /usr/bin/mv guuid=b46c4d71-1900-0000-c6f1-174c77140000 pid=5239->guuid=2b4f8571-1900-0000-c6f1-174c78140000 pid=5240 execve guuid=dbc44172-1900-0000-c6f1-174c7a140000 pid=5242 /usr/bin/mv guuid=61f10272-1900-0000-c6f1-174c79140000 pid=5241->guuid=dbc44172-1900-0000-c6f1-174c7a140000 pid=5242 execve guuid=606a0a73-1900-0000-c6f1-174c7c140000 pid=5244 /usr/bin/mv guuid=d3ddbf72-1900-0000-c6f1-174c7b140000 pid=5243->guuid=606a0a73-1900-0000-c6f1-174c7c140000 pid=5244 execve guuid=4f61f773-1900-0000-c6f1-174c7e140000 pid=5246 /usr/bin/mv guuid=c94a7e73-1900-0000-c6f1-174c7d140000 pid=5245->guuid=4f61f773-1900-0000-c6f1-174c7e140000 pid=5246 execve guuid=185a0975-1900-0000-c6f1-174c80140000 pid=5248 /usr/bin/mv guuid=3790c474-1900-0000-c6f1-174c7f140000 pid=5247->guuid=185a0975-1900-0000-c6f1-174c80140000 pid=5248 execve guuid=ae600376-1900-0000-c6f1-174c82140000 pid=5250 /usr/bin/mv guuid=e8a8c175-1900-0000-c6f1-174c81140000 pid=5249->guuid=ae600376-1900-0000-c6f1-174c82140000 pid=5250 execve guuid=38082077-1900-0000-c6f1-174c84140000 pid=5252 /usr/bin/mv guuid=b434c976-1900-0000-c6f1-174c83140000 pid=5251->guuid=38082077-1900-0000-c6f1-174c84140000 pid=5252 execve guuid=a9470278-1900-0000-c6f1-174c86140000 pid=5254 /usr/bin/mv guuid=607cc577-1900-0000-c6f1-174c85140000 pid=5253->guuid=a9470278-1900-0000-c6f1-174c86140000 pid=5254 execve guuid=f48dbf78-1900-0000-c6f1-174c88140000 pid=5256 /usr/bin/mv guuid=1c578c78-1900-0000-c6f1-174c87140000 pid=5255->guuid=f48dbf78-1900-0000-c6f1-174c88140000 pid=5256 execve guuid=2117c879-1900-0000-c6f1-174c8a140000 pid=5258 /usr/bin/mv guuid=89339579-1900-0000-c6f1-174c89140000 pid=5257->guuid=2117c879-1900-0000-c6f1-174c8a140000 pid=5258 execve guuid=f575747a-1900-0000-c6f1-174c8c140000 pid=5260 /usr/bin/mv guuid=67ed407a-1900-0000-c6f1-174c8b140000 pid=5259->guuid=f575747a-1900-0000-c6f1-174c8c140000 pid=5260 execve guuid=6b53217b-1900-0000-c6f1-174c8e140000 pid=5262 /usr/bin/mv guuid=a24af07a-1900-0000-c6f1-174c8d140000 pid=5261->guuid=6b53217b-1900-0000-c6f1-174c8e140000 pid=5262 execve guuid=018bc57b-1900-0000-c6f1-174c90140000 pid=5264 /usr/bin/mv guuid=9d9e957b-1900-0000-c6f1-174c8f140000 pid=5263->guuid=018bc57b-1900-0000-c6f1-174c90140000 pid=5264 execve guuid=b4ea767c-1900-0000-c6f1-174c92140000 pid=5266 /usr/bin/mv guuid=b9903b7c-1900-0000-c6f1-174c91140000 pid=5265->guuid=b4ea767c-1900-0000-c6f1-174c92140000 pid=5266 execve guuid=6ad0237d-1900-0000-c6f1-174c94140000 pid=5268 /usr/bin/mv guuid=d91aeb7c-1900-0000-c6f1-174c93140000 pid=5267->guuid=6ad0237d-1900-0000-c6f1-174c94140000 pid=5268 execve guuid=5709717f-1900-0000-c6f1-174c96140000 pid=5270 /usr/bin/mv guuid=5379027f-1900-0000-c6f1-174c95140000 pid=5269->guuid=5709717f-1900-0000-c6f1-174c96140000 pid=5270 execve guuid=aff86f80-1900-0000-c6f1-174c9a140000 pid=5274 /usr/bin/mv guuid=fbf91e80-1900-0000-c6f1-174c98140000 pid=5272->guuid=aff86f80-1900-0000-c6f1-174c9a140000 pid=5274 execve guuid=414b6281-1900-0000-c6f1-174c9d140000 pid=5277 /usr/bin/mv guuid=91fa0f81-1900-0000-c6f1-174c9c140000 pid=5276->guuid=414b6281-1900-0000-c6f1-174c9d140000 pid=5277 execve guuid=9ca23182-1900-0000-c6f1-174c9f140000 pid=5279 /usr/bin/mv guuid=9a6f0182-1900-0000-c6f1-174c9e140000 pid=5278->guuid=9ca23182-1900-0000-c6f1-174c9f140000 pid=5279 execve guuid=bb7cec82-1900-0000-c6f1-174ca1140000 pid=5281 /usr/bin/mv guuid=5479b682-1900-0000-c6f1-174ca0140000 pid=5280->guuid=bb7cec82-1900-0000-c6f1-174ca1140000 pid=5281 execve guuid=0dda9183-1900-0000-c6f1-174ca3140000 pid=5283 /usr/bin/mv guuid=d6935783-1900-0000-c6f1-174ca2140000 pid=5282->guuid=0dda9183-1900-0000-c6f1-174ca3140000 pid=5283 execve guuid=2a491e84-1900-0000-c6f1-174ca5140000 pid=5285 /usr/bin/mv guuid=e62bf283-1900-0000-c6f1-174ca4140000 pid=5284->guuid=2a491e84-1900-0000-c6f1-174ca5140000 pid=5285 execve guuid=e4e8c284-1900-0000-c6f1-174ca7140000 pid=5287 /usr/bin/mv guuid=29197c84-1900-0000-c6f1-174ca6140000 pid=5286->guuid=e4e8c284-1900-0000-c6f1-174ca7140000 pid=5287 execve guuid=6c464785-1900-0000-c6f1-174caa140000 pid=5290 /usr/bin/mv guuid=09231f85-1900-0000-c6f1-174ca8140000 pid=5288->guuid=6c464785-1900-0000-c6f1-174caa140000 pid=5290 execve guuid=60156486-1900-0000-c6f1-174caf140000 pid=5295 /usr/bin/mv guuid=fda3e385-1900-0000-c6f1-174cac140000 pid=5292->guuid=60156486-1900-0000-c6f1-174caf140000 pid=5295 execve guuid=0dcb9587-1900-0000-c6f1-174cb5140000 pid=5301 /usr/bin/mv guuid=0ded4087-1900-0000-c6f1-174cb4140000 pid=5300->guuid=0dcb9587-1900-0000-c6f1-174cb5140000 pid=5301 execve guuid=861a4488-1900-0000-c6f1-174cb7140000 pid=5303 /usr/bin/mv guuid=06b81088-1900-0000-c6f1-174cb6140000 pid=5302->guuid=861a4488-1900-0000-c6f1-174cb7140000 pid=5303 execve guuid=67061089-1900-0000-c6f1-174cb9140000 pid=5305 /usr/bin/mv guuid=a8fae088-1900-0000-c6f1-174cb8140000 pid=5304->guuid=67061089-1900-0000-c6f1-174cb9140000 pid=5305 execve guuid=af7bb189-1900-0000-c6f1-174cbb140000 pid=5307 /usr/bin/mv guuid=92db8389-1900-0000-c6f1-174cba140000 pid=5306->guuid=af7bb189-1900-0000-c6f1-174cbb140000 pid=5307 execve guuid=05e2418a-1900-0000-c6f1-174cbd140000 pid=5309 /usr/bin/mv guuid=ce6e168a-1900-0000-c6f1-174cbc140000 pid=5308->guuid=05e2418a-1900-0000-c6f1-174cbd140000 pid=5309 execve guuid=2787ca8a-1900-0000-c6f1-174cbf140000 pid=5311 /usr/bin/mv guuid=525fa58a-1900-0000-c6f1-174cbe140000 pid=5310->guuid=2787ca8a-1900-0000-c6f1-174cbf140000 pid=5311 execve guuid=651d528b-1900-0000-c6f1-174cc1140000 pid=5313 /usr/bin/mv guuid=b3aa1f8b-1900-0000-c6f1-174cc0140000 pid=5312->guuid=651d528b-1900-0000-c6f1-174cc1140000 pid=5313 execve guuid=99faec8b-1900-0000-c6f1-174cc3140000 pid=5315 /usr/bin/mv guuid=25b1b28b-1900-0000-c6f1-174cc2140000 pid=5314->guuid=99faec8b-1900-0000-c6f1-174cc3140000 pid=5315 execve guuid=fa95878c-1900-0000-c6f1-174cc5140000 pid=5317 /usr/bin/mv guuid=9579538c-1900-0000-c6f1-174cc4140000 pid=5316->guuid=fa95878c-1900-0000-c6f1-174cc5140000 pid=5317 execve guuid=0b78218d-1900-0000-c6f1-174cc7140000 pid=5319 /usr/bin/mv guuid=abfee88c-1900-0000-c6f1-174cc6140000 pid=5318->guuid=0b78218d-1900-0000-c6f1-174cc7140000 pid=5319 execve guuid=d38cd18d-1900-0000-c6f1-174cc9140000 pid=5321 /usr/bin/mv guuid=f4c58e8d-1900-0000-c6f1-174cc8140000 pid=5320->guuid=d38cd18d-1900-0000-c6f1-174cc9140000 pid=5321 execve guuid=76a2718e-1900-0000-c6f1-174ccb140000 pid=5323 /usr/bin/mv guuid=0e59318e-1900-0000-c6f1-174cca140000 pid=5322->guuid=76a2718e-1900-0000-c6f1-174ccb140000 pid=5323 execve guuid=7e832d8f-1900-0000-c6f1-174ccd140000 pid=5325 /usr/bin/mv guuid=504f028f-1900-0000-c6f1-174ccc140000 pid=5324->guuid=7e832d8f-1900-0000-c6f1-174ccd140000 pid=5325 execve guuid=69e4e98f-1900-0000-c6f1-174ccf140000 pid=5327 /usr/bin/mv guuid=9a8dbe8f-1900-0000-c6f1-174cce140000 pid=5326->guuid=69e4e98f-1900-0000-c6f1-174ccf140000 pid=5327 execve guuid=c646a390-1900-0000-c6f1-174cd1140000 pid=5329 /usr/bin/mv guuid=4b1f7890-1900-0000-c6f1-174cd0140000 pid=5328->guuid=c646a390-1900-0000-c6f1-174cd1140000 pid=5329 execve guuid=defb5291-1900-0000-c6f1-174cd3140000 pid=5331 /usr/bin/mv guuid=69282c91-1900-0000-c6f1-174cd2140000 pid=5330->guuid=defb5291-1900-0000-c6f1-174cd3140000 pid=5331 execve guuid=9334ec91-1900-0000-c6f1-174cd5140000 pid=5333 /usr/bin/mv guuid=202ec591-1900-0000-c6f1-174cd4140000 pid=5332->guuid=9334ec91-1900-0000-c6f1-174cd5140000 pid=5333 execve guuid=811c7e92-1900-0000-c6f1-174cd7140000 pid=5335 /usr/bin/mv guuid=c9175a92-1900-0000-c6f1-174cd6140000 pid=5334->guuid=811c7e92-1900-0000-c6f1-174cd7140000 pid=5335 execve guuid=e3870693-1900-0000-c6f1-174cd9140000 pid=5337 /usr/bin/mv guuid=0599df92-1900-0000-c6f1-174cd8140000 pid=5336->guuid=e3870693-1900-0000-c6f1-174cd9140000 pid=5337 execve guuid=89438a93-1900-0000-c6f1-174cdb140000 pid=5339 /usr/bin/mv guuid=41a36193-1900-0000-c6f1-174cda140000 pid=5338->guuid=89438a93-1900-0000-c6f1-174cdb140000 pid=5339 execve guuid=f1021b94-1900-0000-c6f1-174cdd140000 pid=5341 /usr/bin/mv guuid=0c41f593-1900-0000-c6f1-174cdc140000 pid=5340->guuid=f1021b94-1900-0000-c6f1-174cdd140000 pid=5341 execve guuid=9b6cb994-1900-0000-c6f1-174cdf140000 pid=5343 /usr/bin/mv guuid=63258b94-1900-0000-c6f1-174cde140000 pid=5342->guuid=9b6cb994-1900-0000-c6f1-174cdf140000 pid=5343 execve guuid=79546d95-1900-0000-c6f1-174ce1140000 pid=5345 /usr/bin/mv guuid=d95f4095-1900-0000-c6f1-174ce0140000 pid=5344->guuid=79546d95-1900-0000-c6f1-174ce1140000 pid=5345 execve guuid=e5721c96-1900-0000-c6f1-174ce3140000 pid=5347 /usr/bin/mv guuid=4ee0ee95-1900-0000-c6f1-174ce2140000 pid=5346->guuid=e5721c96-1900-0000-c6f1-174ce3140000 pid=5347 execve guuid=db49c996-1900-0000-c6f1-174ce5140000 pid=5349 /usr/bin/mv guuid=328a9d96-1900-0000-c6f1-174ce4140000 pid=5348->guuid=db49c996-1900-0000-c6f1-174ce5140000 pid=5349 execve guuid=227e6e97-1900-0000-c6f1-174ce7140000 pid=5351 /usr/bin/mv guuid=2e013a97-1900-0000-c6f1-174ce6140000 pid=5350->guuid=227e6e97-1900-0000-c6f1-174ce7140000 pid=5351 execve guuid=959c1e98-1900-0000-c6f1-174ce9140000 pid=5353 /usr/bin/mv guuid=e57fdf97-1900-0000-c6f1-174ce8140000 pid=5352->guuid=959c1e98-1900-0000-c6f1-174ce9140000 pid=5353 execve guuid=991acb98-1900-0000-c6f1-174ceb140000 pid=5355 /usr/bin/mv guuid=0c908998-1900-0000-c6f1-174cea140000 pid=5354->guuid=991acb98-1900-0000-c6f1-174ceb140000 pid=5355 execve guuid=621e339a-1900-0000-c6f1-174ced140000 pid=5357 /usr/bin/mv guuid=ee63eb99-1900-0000-c6f1-174cec140000 pid=5356->guuid=621e339a-1900-0000-c6f1-174ced140000 pid=5357 execve guuid=95c6609b-1900-0000-c6f1-174cef140000 pid=5359 /usr/bin/mv guuid=a9d7029b-1900-0000-c6f1-174cee140000 pid=5358->guuid=95c6609b-1900-0000-c6f1-174cef140000 pid=5359 execve guuid=bad5a69c-1900-0000-c6f1-174cf1140000 pid=5361 /usr/bin/mv guuid=28013a9c-1900-0000-c6f1-174cf0140000 pid=5360->guuid=bad5a69c-1900-0000-c6f1-174cf1140000 pid=5361 execve guuid=23d11d9e-1900-0000-c6f1-174cf3140000 pid=5363 /usr/bin/mv guuid=7fbdaf9d-1900-0000-c6f1-174cf2140000 pid=5362->guuid=23d11d9e-1900-0000-c6f1-174cf3140000 pid=5363 execve guuid=0f443f9f-1900-0000-c6f1-174cf5140000 pid=5365 /usr/bin/mv guuid=78fad59e-1900-0000-c6f1-174cf4140000 pid=5364->guuid=0f443f9f-1900-0000-c6f1-174cf5140000 pid=5365 execve guuid=10256ba0-1900-0000-c6f1-174cf7140000 pid=5367 /usr/bin/mv guuid=b1d601a0-1900-0000-c6f1-174cf6140000 pid=5366->guuid=10256ba0-1900-0000-c6f1-174cf7140000 pid=5367 execve guuid=62518ba1-1900-0000-c6f1-174cf9140000 pid=5369 /usr/bin/mv guuid=57d12ba1-1900-0000-c6f1-174cf8140000 pid=5368->guuid=62518ba1-1900-0000-c6f1-174cf9140000 pid=5369 execve guuid=2d76a3a2-1900-0000-c6f1-174cfb140000 pid=5371 /usr/bin/mv guuid=05f839a2-1900-0000-c6f1-174cfa140000 pid=5370->guuid=2d76a3a2-1900-0000-c6f1-174cfb140000 pid=5371 execve guuid=e9e7c8a3-1900-0000-c6f1-174cfd140000 pid=5373 /usr/bin/mv guuid=f9dc5ea3-1900-0000-c6f1-174cfc140000 pid=5372->guuid=e9e7c8a3-1900-0000-c6f1-174cfd140000 pid=5373 execve guuid=883af3a4-1900-0000-c6f1-174cff140000 pid=5375 /usr/bin/mv guuid=80488ca4-1900-0000-c6f1-174cfe140000 pid=5374->guuid=883af3a4-1900-0000-c6f1-174cff140000 pid=5375 execve guuid=d11a0aa6-1900-0000-c6f1-174c01150000 pid=5377 /usr/bin/mv guuid=6b74a6a5-1900-0000-c6f1-174c00150000 pid=5376->guuid=d11a0aa6-1900-0000-c6f1-174c01150000 pid=5377 execve
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
76 / 100
Signature
Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1743759 Sample: iotmirai_x86.elf Startdate: 24/07/2025 Architecture: LINUX Score: 76 19 109.202.202.202, 80 INIT7CH Switzerland 2->19 21 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->21 23 2 other IPs or domains 2->23 25 Malicious sample detected (through community Yara rule) 2->25 27 Antivirus / Scanner detection for submitted sample 2->27 29 Multi AV Scanner detection for submitted file 2->29 31 Yara detected Mirai 2->31 8 iotmirai_x86.elf 2->8         started        11 dash rm 2->11         started        13 dash rm 2->13         started        signatures3 process4 signatures5 33 Sample deletes itself 8->33 15 iotmirai_x86.elf 8->15         started        process6 process7 17 iotmirai_x86.elf 15->17         started       
Verdict:
Malicious
Threat:
HEUR:Backdoor.Linux.Mirai
Threat name:
Linux.Backdoor.Mirai
Status:
Malicious
First seen:
2025-07-24 21:21:26 UTC
File Type:
ELF32 Little (Exe)
AV detection:
17 of 23 (73.91%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery linux persistence
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Modifies init.d
Modifies rc script
Deletes itself
Executes dropped EXE
Traces itself
Verdict:
Malicious
Tags:
trojan mirai gafgyt Unix.Trojan.Mirai-9441505-0
YARA:
Linux_Trojan_Gafgyt_28a2fe0c Linux_Trojan_Gafgyt_5bf62ce4 Linux_Trojan_Gafgyt_ea92cca8 Linux_Trojan_Mirai_b14f4c5d Linux_Trojan_Mirai_5f7b67b8 Linux_Trojan_Mirai_88de437f Linux_Trojan_Mirai_389ee3e9 Linux_Trojan_Mirai_cc93863b Linux_Trojan_Mirai_8aa7b5d3 Linux_Gafgyt_May_2024
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_Yakuza
Author:NDA0E
Description:Yakuza botnet
Rule name:ELF_Mirai
Author:NDA0E
Description:Detects multiple Mirai variants
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Gafgyt_28a2fe0c
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_5bf62ce4
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_ea92cca8
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_389ee3e9
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_5f7b67b8
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_88de437f
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_8aa7b5d3
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_b14f4c5d
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_cc93863b
Author:Elastic Security
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 9a6cac4c1a037f48ffedbba6844d021ef09320ffffa144a938cb3c3d0aed7137

(this sample)

  
Delivery method
Distributed via web download

Comments