MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9ed79240bf9bfdc58e8b4a705ff1eba11fbdda327d66e32b8d5d449b7a38a1f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 8 File information Comments

SHA256 hash: 9ed79240bf9bfdc58e8b4a705ff1eba11fbdda327d66e32b8d5d449b7a38a1f1
SHA3-384 hash: ad4a758ed7dc80bf84cc2bf3625850b6cd34f426f0c6e167983c736c9225f4cad65274e2aefe5d3f79f7eec1e702c3db
SHA1 hash: a029098f78e33511dccb443390c9aeab8134b575
MD5 hash: e35b7d656973332ed2b2b3d270c27eb5
humanhash: may-tennessee-network-butter
File name:boatnet.ppc
Download: download sample
Signature Mirai
File size:154'680 bytes
First seen:2026-08-11 15:03:44 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:67RfDIqswvZl33CuD+gxo/SoSu1VLXB3nATyqR2ovAwY6rSYqHhjqprqjGO0v3yK:Ofkq1v3D+gxtoSsiTfRKwR+GWlIR
TLSH T1DEE32806B31C0903D1A32EB0363F3BE1A7AFDAC222E4F201255F569991B2D775946EDD
Magika elf
Reporter abuse_ch
Tags:elf mirai upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 fb019693fd5af3747c1c74e7278fe105b143bf3cfa34122be507df51f1387ad1
File size (compressed) :52'488 bytes
File size (de-compressed) :154'680 bytes
Format:linux/ppc32
Packed file: fb019693fd5af3747c1c74e7278fe105b143bf3cfa34122be507df51f1387ad1

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Kills processes
Deletes a file
Launching a process
Runs as daemon
Changes access rights for a written file
Receives data from a server
Changes the time when the file was created, accessed, or modified
Connection attempt
DNS request
Creating a file
Deleting a recently created file
Creating a file in the %temp% directory
Removes directories
Sets a written file as executable
Sends data to a server
Changes access rights for a file
Removes directories from a temporary directory
Creates or modifies files in /cron to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Creates or modifies files in /init.d to set up autorun
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
dropper masquerade mirai
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2026-08-11T13:39:00Z UTC
Last seen:
2026-08-11T13:57:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=cdeb8315-1900-0000-8d15-d0d4720d0000 pid=3442 /usr/bin/sudo guuid=65f3271a-1900-0000-8d15-d0d4780d0000 pid=3448 /tmp/sample.bin guuid=cdeb8315-1900-0000-8d15-d0d4720d0000 pid=3442->guuid=65f3271a-1900-0000-8d15-d0d4780d0000 pid=3448 execve
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Deletes system log files
Drops files in suspicious directories
Executes the "crontab" command typically for achieving persistence
Malicious sample detected (through community Yara rule)
Manipulation of devices in /dev
Multi AV Scanner detection for submitted file
Sample tries to persist itself using cron
Uses dynamic DNS services
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1956136 Sample: boatnet.ppc.elf Startdate: 11/08/2026 Architecture: LINUX Score: 100 100 reavercncv4.duckdns.org 2->100 102 reavercncv4.duckdns.org 217.60.195.187, 49828, 8529 NETPOOLIN Netherlands 2->102 106 Malicious sample detected (through community Yara rule) 2->106 108 Antivirus detection for dropped file 2->108 110 Antivirus / Scanner detection for submitted sample 2->110 114 2 other signatures 2->114 12 boatnet.ppc.elf 2->12         started        signatures3 112 Uses dynamic DNS services 100->112 process4 process5 14 boatnet.ppc.elf 12->14         started        16 boatnet.ppc.elf 12->16         started        process6 18 boatnet.ppc.elf 14->18         started        signatures7 104 Drops files in suspicious directories 18->104 21 boatnet.ppc.elf 18->21         started        25 boatnet.ppc.elf sh 18->25         started        27 boatnet.ppc.elf 18->27         started        29 3 other processes 18->29 process8 file9 94 /usr/local/bin/infinitd, ELF 21->94 dropped 96 /etc/init.d/infinitech, ASCII 21->96 dropped 120 Drops files in suspicious directories 21->120 31 boatnet.ppc.elf sh 21->31         started        33 boatnet.ppc.elf sh 21->33         started        35 boatnet.ppc.elf sh 21->35         started        47 13 other processes 21->47 37 sh crontab 25->37         started        41 sh 25->41         started        43 boatnet.ppc.elf 27->43         started        45 sh update-rc.d 29->45         started        49 2 other processes 29->49 signatures10 process11 file12 51 sh crontab 31->51         started        55 sh 31->55         started        57 sh crontab 33->57         started        59 sh 33->59         started        61 sh crontab 35->61         started        63 sh 35->63         started        98 /var/spool/cron/crontabs/tmp.t6vT2K, ASCII 37->98 dropped 122 Sample tries to persist itself using cron 37->122 124 Executes the "crontab" command typically for achieving persistence 37->124 65 sh crontab 41->65         started        126 Manipulation of devices in /dev 43->126 128 Deletes system log files 43->128 67 update-rc.d 45->67         started        69 14 other processes 47->69 signatures13 process14 file15 86 /var/spool/cron/cr...mp.nYelZ1 (deleted), ASCII 51->86 dropped 116 Sample tries to persist itself using cron 51->116 118 Executes the "crontab" command typically for achieving persistence 51->118 71 sh crontab 55->71         started        88 /var/spool/cron/cr...mp.5dOUVP (deleted), ASCII 57->88 dropped 74 sh crontab 59->74         started        90 /var/spool/cron/cr...mp.WoO1CF (deleted), ASCII 61->90 dropped 76 sh crontab 63->76         started        92 /var/spool/cron/cr...mp.0kedQr (deleted), ASCII 69->92 dropped 78 sh crontab 69->78         started        80 update-rc.d 69->80         started        82 update-rc.d 69->82         started        84 2 other processes 69->84 signatures16 process17 signatures18 130 Executes the "crontab" command typically for achieving persistence 71->130
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-08-11 15:04:36 UTC
File Type:
ELF32 Big (Exe)
AV detection:
19 of 36 (52.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202503_elf_Mirai
Author:abuse.ch
Description:Detects Mirai 'TSource' ELF files
Rule name:botnet_Yakuza
Author:NDA0E
Description:Yakuza botnet
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Gafgyt_28a2fe0c
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_ea92cca8
Author:Elastic Security
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 9ed79240bf9bfdc58e8b4a705ff1eba11fbdda327d66e32b8d5d449b7a38a1f1

(this sample)

  
Delivery method
Distributed via web download

Comments