MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a25c180db1c0bf0c233bb7cb936b6a6202e6b5e3ab792d3bfb198e4aeab94dfb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 5 File information Comments

SHA256 hash: a25c180db1c0bf0c233bb7cb936b6a6202e6b5e3ab792d3bfb198e4aeab94dfb
SHA3-384 hash: f9e562bcf91cc567174d7072172a85eba535fdc21f05a1c6ed9ddf74bce3fd2514ff119ceecf32c79ee5078d50d5dc6b
SHA1 hash: a9ac0820ee10ab50611857b5ef0ec00c387da592
MD5 hash: a5751f98fa5dba426de5852cdb6fbe26
humanhash: cold-mountain-lamp-seventeen
File name:i486
Download: download sample
Signature Mirai
File size:86'764 bytes
First seen:2026-01-04 09:08:01 UTC
Last seen:2026-01-05 21:29:56 UTC
File type: elf
MIME type:application/x-executable
ssdeep 1536:JUr6rig+UFP+yhgwQxGFGq26XUm31MjPpgO5ohY93yt9d01QMLr:I6r+UFPtTQxv6xe1UKyQ/
TLSH T181834A86E793E4B1D84711B101BBAB798A31FD630630C91AD7A0BFF0AD316D1B65632D
telfhash t16b41ffe53de918e873e41c0cc21e6ba38b15d63b296136a689f1bc5537e374290b7c39
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
5
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Runs as daemon
Kills processes
Opens a port
Changes access rights for a written file
Launching a process
Sends data to a server
Collects information on the OS
Sets a written file as executable
Creating a file
Collects information on the CPU
Changes the time when the file was created, accessed, or modified
Connection attempt
Writes files to system directory
Substitutes an application name
Creates or modifies files in /cron to set up autorun
Creates or modifies files in /init.d to set up autorun
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
gcc obfuscated rust
Verdict:
Unknown
File Type:
elf.32.le
First seen:
2026-01-03T22:10:00Z UTC
Last seen:
2026-01-04T06:52:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=d197014d-1a00-0000-3845-a46c160b0000 pid=2838 /usr/bin/sudo guuid=5c3fdf4f-1a00-0000-3845-a46c180b0000 pid=2840 /tmp/sample.bin net write-config write-file guuid=d197014d-1a00-0000-3845-a46c160b0000 pid=2838->guuid=5c3fdf4f-1a00-0000-3845-a46c180b0000 pid=2840 execve 24601723-ce49-57fd-8a20-658824355076 127.0.0.1:2625 guuid=5c3fdf4f-1a00-0000-3845-a46c180b0000 pid=2840->24601723-ce49-57fd-8a20-658824355076 con guuid=16633ea4-1c00-0000-3845-a46c38100000 pid=4152 /usr/bin/dash guuid=5c3fdf4f-1a00-0000-3845-a46c180b0000 pid=2840->guuid=16633ea4-1c00-0000-3845-a46c38100000 pid=4152 execve guuid=5f7896a5-1c00-0000-3845-a46c3b100000 pid=4155 /usr/bin/dash guuid=5c3fdf4f-1a00-0000-3845-a46c180b0000 pid=2840->guuid=5f7896a5-1c00-0000-3845-a46c3b100000 pid=4155 execve guuid=0a8913a6-1c00-0000-3845-a46c3e100000 pid=4158 /usr/bin/dash write-config guuid=5c3fdf4f-1a00-0000-3845-a46c180b0000 pid=2840->guuid=0a8913a6-1c00-0000-3845-a46c3e100000 pid=4158 execve guuid=2fcd5fa7-1c00-0000-3845-a46c40100000 pid=4160 /usr/bin/dash guuid=5c3fdf4f-1a00-0000-3845-a46c180b0000 pid=2840->guuid=2fcd5fa7-1c00-0000-3845-a46c40100000 pid=4160 execve guuid=1f4bfaa7-1c00-0000-3845-a46c42100000 pid=4162 /tmp/sample.bin guuid=5c3fdf4f-1a00-0000-3845-a46c180b0000 pid=2840->guuid=1f4bfaa7-1c00-0000-3845-a46c42100000 pid=4162 clone guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163 /tmp/sample.bin net send-data zombie guuid=5c3fdf4f-1a00-0000-3845-a46c180b0000 pid=2840->guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163 clone guuid=b41670a4-1c00-0000-3845-a46c39100000 pid=4153 /usr/bin/cp guuid=16633ea4-1c00-0000-3845-a46c38100000 pid=4152->guuid=b41670a4-1c00-0000-3845-a46c39100000 pid=4153 execve guuid=6eb010a5-1c00-0000-3845-a46c3a100000 pid=4154 /usr/bin/chmod guuid=16633ea4-1c00-0000-3845-a46c38100000 pid=4152->guuid=6eb010a5-1c00-0000-3845-a46c3a100000 pid=4154 execve guuid=4740cba5-1c00-0000-3845-a46c3c100000 pid=4156 /usr/bin/dash guuid=5f7896a5-1c00-0000-3845-a46c3b100000 pid=4155->guuid=4740cba5-1c00-0000-3845-a46c3c100000 pid=4156 clone guuid=f2bae0a5-1c00-0000-3845-a46c3d100000 pid=4157 /usr/bin/dash guuid=5f7896a5-1c00-0000-3845-a46c3b100000 pid=4155->guuid=f2bae0a5-1c00-0000-3845-a46c3d100000 pid=4157 clone guuid=fc1d72a6-1c00-0000-3845-a46c3f100000 pid=4159 /usr/bin/grep guuid=0a8913a6-1c00-0000-3845-a46c3e100000 pid=4158->guuid=fc1d72a6-1c00-0000-3845-a46c3f100000 pid=4159 execve guuid=2ea79aa7-1c00-0000-3845-a46c41100000 pid=4161 /usr/bin/chmod guuid=2fcd5fa7-1c00-0000-3845-a46c40100000 pid=4160->guuid=2ea79aa7-1c00-0000-3845-a46c41100000 pid=4161 execve 8724242f-5b7b-562e-b78a-57b7928f987a 45.153.34.74:12344 guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->8724242f-5b7b-562e-b78a-57b7928f987a send: 13B guuid=045b10a8-1c00-0000-3845-a46c44100000 pid=4164 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=045b10a8-1c00-0000-3845-a46c44100000 pid=4164 execve guuid=9b3af1a8-1c00-0000-3845-a46c4a100000 pid=4170 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=9b3af1a8-1c00-0000-3845-a46c4a100000 pid=4170 execve guuid=ac9ffdb0-1c00-0000-3845-a46c6a100000 pid=4202 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=ac9ffdb0-1c00-0000-3845-a46c6a100000 pid=4202 execve guuid=636918b5-1c00-0000-3845-a46c7f100000 pid=4223 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=636918b5-1c00-0000-3845-a46c7f100000 pid=4223 execve guuid=f4cd0bb8-1c00-0000-3845-a46c8a100000 pid=4234 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=f4cd0bb8-1c00-0000-3845-a46c8a100000 pid=4234 execve guuid=5131ecba-1c00-0000-3845-a46c9b100000 pid=4251 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=5131ecba-1c00-0000-3845-a46c9b100000 pid=4251 execve guuid=143ef6be-1c00-0000-3845-a46cad100000 pid=4269 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=143ef6be-1c00-0000-3845-a46cad100000 pid=4269 execve guuid=e77f72c1-1c00-0000-3845-a46cbd100000 pid=4285 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=e77f72c1-1c00-0000-3845-a46cbd100000 pid=4285 execve guuid=ddf5eec3-1c00-0000-3845-a46ccb100000 pid=4299 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=ddf5eec3-1c00-0000-3845-a46ccb100000 pid=4299 execve guuid=de4b8ac6-1c00-0000-3845-a46cd2100000 pid=4306 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=de4b8ac6-1c00-0000-3845-a46cd2100000 pid=4306 execve guuid=645fdcca-1c00-0000-3845-a46cd7100000 pid=4311 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=645fdcca-1c00-0000-3845-a46cd7100000 pid=4311 execve guuid=952822d0-1c00-0000-3845-a46ceb100000 pid=4331 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=952822d0-1c00-0000-3845-a46ceb100000 pid=4331 execve guuid=46dea2d2-1c00-0000-3845-a46cfb100000 pid=4347 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=46dea2d2-1c00-0000-3845-a46cfb100000 pid=4347 execve guuid=4d491ed5-1c00-0000-3845-a46c07110000 pid=4359 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=4d491ed5-1c00-0000-3845-a46c07110000 pid=4359 execve guuid=ae6fa9d8-1c00-0000-3845-a46c1b110000 pid=4379 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=ae6fa9d8-1c00-0000-3845-a46c1b110000 pid=4379 execve guuid=4d0f11dc-1c00-0000-3845-a46c2c110000 pid=4396 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=4d0f11dc-1c00-0000-3845-a46c2c110000 pid=4396 execve guuid=88b6c6de-1c00-0000-3845-a46c3c110000 pid=4412 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=88b6c6de-1c00-0000-3845-a46c3c110000 pid=4412 execve guuid=877978e3-1c00-0000-3845-a46c50110000 pid=4432 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=877978e3-1c00-0000-3845-a46c50110000 pid=4432 execve guuid=cce47ee6-1c00-0000-3845-a46c61110000 pid=4449 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=cce47ee6-1c00-0000-3845-a46c61110000 pid=4449 execve guuid=ab4e52e9-1c00-0000-3845-a46c70110000 pid=4464 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=ab4e52e9-1c00-0000-3845-a46c70110000 pid=4464 execve guuid=712ab4ec-1c00-0000-3845-a46c80110000 pid=4480 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=712ab4ec-1c00-0000-3845-a46c80110000 pid=4480 execve guuid=7d065def-1c00-0000-3845-a46c8a110000 pid=4490 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=7d065def-1c00-0000-3845-a46c8a110000 pid=4490 execve guuid=c6336ff3-1c00-0000-3845-a46c9f110000 pid=4511 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=c6336ff3-1c00-0000-3845-a46c9f110000 pid=4511 execve guuid=70cafef6-1c00-0000-3845-a46cad110000 pid=4525 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=70cafef6-1c00-0000-3845-a46cad110000 pid=4525 execve guuid=687365fb-1c00-0000-3845-a46cbb110000 pid=4539 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=687365fb-1c00-0000-3845-a46cbb110000 pid=4539 execve guuid=4332fcfe-1c00-0000-3845-a46cc6110000 pid=4550 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=4332fcfe-1c00-0000-3845-a46cc6110000 pid=4550 execve guuid=3b0dc602-1d00-0000-3845-a46ccf110000 pid=4559 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=3b0dc602-1d00-0000-3845-a46ccf110000 pid=4559 execve guuid=8df25405-1d00-0000-3845-a46cd8110000 pid=4568 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=8df25405-1d00-0000-3845-a46cd8110000 pid=4568 execve guuid=d09d580a-1d00-0000-3845-a46ce5110000 pid=4581 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=d09d580a-1d00-0000-3845-a46ce5110000 pid=4581 execve guuid=0f15e60f-1d00-0000-3845-a46cfb110000 pid=4603 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=0f15e60f-1d00-0000-3845-a46cfb110000 pid=4603 execve guuid=af01bd12-1d00-0000-3845-a46c0a120000 pid=4618 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=af01bd12-1d00-0000-3845-a46c0a120000 pid=4618 execve guuid=ed8c6715-1d00-0000-3845-a46c17120000 pid=4631 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=ed8c6715-1d00-0000-3845-a46c17120000 pid=4631 execve guuid=2dfb5e18-1d00-0000-3845-a46c29120000 pid=4649 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=2dfb5e18-1d00-0000-3845-a46c29120000 pid=4649 execve guuid=9e05341b-1d00-0000-3845-a46c37120000 pid=4663 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=9e05341b-1d00-0000-3845-a46c37120000 pid=4663 execve guuid=a760a81e-1d00-0000-3845-a46c49120000 pid=4681 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=a760a81e-1d00-0000-3845-a46c49120000 pid=4681 execve guuid=1931c721-1d00-0000-3845-a46c54120000 pid=4692 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=1931c721-1d00-0000-3845-a46c54120000 pid=4692 execve guuid=3e22a024-1d00-0000-3845-a46c5f120000 pid=4703 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=3e22a024-1d00-0000-3845-a46c5f120000 pid=4703 execve guuid=efb86127-1d00-0000-3845-a46c66120000 pid=4710 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=efb86127-1d00-0000-3845-a46c66120000 pid=4710 execve guuid=242fe62a-1d00-0000-3845-a46c79120000 pid=4729 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=242fe62a-1d00-0000-3845-a46c79120000 pid=4729 execve guuid=40505a2e-1d00-0000-3845-a46c88120000 pid=4744 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=40505a2e-1d00-0000-3845-a46c88120000 pid=4744 execve guuid=ca1e0e31-1d00-0000-3845-a46c94120000 pid=4756 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=ca1e0e31-1d00-0000-3845-a46c94120000 pid=4756 execve guuid=a6b69735-1d00-0000-3845-a46caa120000 pid=4778 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=a6b69735-1d00-0000-3845-a46caa120000 pid=4778 execve guuid=bc914336-1d00-0000-3845-a46caf120000 pid=4783 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=bc914336-1d00-0000-3845-a46caf120000 pid=4783 execve guuid=79b7c136-1d00-0000-3845-a46cb2120000 pid=4786 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=79b7c136-1d00-0000-3845-a46cb2120000 pid=4786 execve guuid=61cc5e37-1d00-0000-3845-a46cb7120000 pid=4791 /usr/bin/dash guuid=f566ffa7-1c00-0000-3845-a46c43100000 pid=4163->guuid=61cc5e37-1d00-0000-3845-a46cb7120000 pid=4791 execve guuid=a0483ba8-1c00-0000-3845-a46c48100000 pid=4168 /usr/bin/dash guuid=045b10a8-1c00-0000-3845-a46c44100000 pid=4164->guuid=a0483ba8-1c00-0000-3845-a46c48100000 pid=4168 clone guuid=adae3fa8-1c00-0000-3845-a46c49100000 pid=4169 /usr/bin/grep guuid=045b10a8-1c00-0000-3845-a46c44100000 pid=4164->guuid=adae3fa8-1c00-0000-3845-a46c49100000 pid=4169 execve guuid=1cd347a9-1c00-0000-3845-a46c4b100000 pid=4171 /usr/bin/dash guuid=9b3af1a8-1c00-0000-3845-a46c4a100000 pid=4170->guuid=1cd347a9-1c00-0000-3845-a46c4b100000 pid=4171 clone guuid=829a50a9-1c00-0000-3845-a46c4c100000 pid=4172 /usr/bin/dash guuid=9b3af1a8-1c00-0000-3845-a46c4a100000 pid=4170->guuid=829a50a9-1c00-0000-3845-a46c4c100000 pid=4172 clone guuid=f4fe39b1-1c00-0000-3845-a46c6c100000 pid=4204 /usr/bin/pgrep guuid=ac9ffdb0-1c00-0000-3845-a46c6a100000 pid=4202->guuid=f4fe39b1-1c00-0000-3845-a46c6c100000 pid=4204 execve guuid=b4bd3db5-1c00-0000-3845-a46c80100000 pid=4224 /usr/bin/pgrep guuid=636918b5-1c00-0000-3845-a46c7f100000 pid=4223->guuid=b4bd3db5-1c00-0000-3845-a46c80100000 pid=4224 execve guuid=a44533b8-1c00-0000-3845-a46c8d100000 pid=4237 /usr/bin/pgrep guuid=f4cd0bb8-1c00-0000-3845-a46c8a100000 pid=4234->guuid=a44533b8-1c00-0000-3845-a46c8d100000 pid=4237 execve guuid=b86e1bbb-1c00-0000-3845-a46c9d100000 pid=4253 /usr/bin/pgrep guuid=5131ecba-1c00-0000-3845-a46c9b100000 pid=4251->guuid=b86e1bbb-1c00-0000-3845-a46c9d100000 pid=4253 execve guuid=c67e1fbf-1c00-0000-3845-a46cae100000 pid=4270 /usr/bin/pgrep guuid=143ef6be-1c00-0000-3845-a46cad100000 pid=4269->guuid=c67e1fbf-1c00-0000-3845-a46cae100000 pid=4270 execve guuid=ed3998c1-1c00-0000-3845-a46cbf100000 pid=4287 /usr/bin/pgrep guuid=e77f72c1-1c00-0000-3845-a46cbd100000 pid=4285->guuid=ed3998c1-1c00-0000-3845-a46cbf100000 pid=4287 execve guuid=f6b21dc4-1c00-0000-3845-a46ccc100000 pid=4300 /usr/bin/pgrep guuid=ddf5eec3-1c00-0000-3845-a46ccb100000 pid=4299->guuid=f6b21dc4-1c00-0000-3845-a46ccc100000 pid=4300 execve guuid=7539bec6-1c00-0000-3845-a46cd3100000 pid=4307 /usr/bin/pgrep guuid=de4b8ac6-1c00-0000-3845-a46cd2100000 pid=4306->guuid=7539bec6-1c00-0000-3845-a46cd3100000 pid=4307 execve guuid=f5c60ecb-1c00-0000-3845-a46cd8100000 pid=4312 /usr/bin/pgrep guuid=645fdcca-1c00-0000-3845-a46cd7100000 pid=4311->guuid=f5c60ecb-1c00-0000-3845-a46cd8100000 pid=4312 execve guuid=1b2149d0-1c00-0000-3845-a46cec100000 pid=4332 /usr/bin/pgrep guuid=952822d0-1c00-0000-3845-a46ceb100000 pid=4331->guuid=1b2149d0-1c00-0000-3845-a46cec100000 pid=4332 execve guuid=f6d6c6d2-1c00-0000-3845-a46cfc100000 pid=4348 /usr/bin/pgrep guuid=46dea2d2-1c00-0000-3845-a46cfb100000 pid=4347->guuid=f6d6c6d2-1c00-0000-3845-a46cfc100000 pid=4348 execve guuid=390844d5-1c00-0000-3845-a46c08110000 pid=4360 /usr/bin/pgrep guuid=4d491ed5-1c00-0000-3845-a46c07110000 pid=4359->guuid=390844d5-1c00-0000-3845-a46c08110000 pid=4360 execve guuid=bfb9d7d8-1c00-0000-3845-a46c1e110000 pid=4382 /usr/bin/pgrep guuid=ae6fa9d8-1c00-0000-3845-a46c1b110000 pid=4379->guuid=bfb9d7d8-1c00-0000-3845-a46c1e110000 pid=4382 execve guuid=386f3fdc-1c00-0000-3845-a46c2e110000 pid=4398 /usr/bin/pgrep guuid=4d0f11dc-1c00-0000-3845-a46c2c110000 pid=4396->guuid=386f3fdc-1c00-0000-3845-a46c2e110000 pid=4398 execve guuid=4c0404df-1c00-0000-3845-a46c40110000 pid=4416 /usr/bin/pgrep guuid=88b6c6de-1c00-0000-3845-a46c3c110000 pid=4412->guuid=4c0404df-1c00-0000-3845-a46c40110000 pid=4416 execve guuid=8465ace3-1c00-0000-3845-a46c51110000 pid=4433 /usr/bin/pgrep guuid=877978e3-1c00-0000-3845-a46c50110000 pid=4432->guuid=8465ace3-1c00-0000-3845-a46c51110000 pid=4433 execve guuid=2659aae6-1c00-0000-3845-a46c63110000 pid=4451 /usr/bin/pgrep guuid=cce47ee6-1c00-0000-3845-a46c61110000 pid=4449->guuid=2659aae6-1c00-0000-3845-a46c63110000 pid=4451 execve guuid=1ce27fe9-1c00-0000-3845-a46c72110000 pid=4466 /usr/bin/pgrep guuid=ab4e52e9-1c00-0000-3845-a46c70110000 pid=4464->guuid=1ce27fe9-1c00-0000-3845-a46c72110000 pid=4466 execve guuid=a581f5ec-1c00-0000-3845-a46c81110000 pid=4481 /usr/bin/pgrep guuid=712ab4ec-1c00-0000-3845-a46c80110000 pid=4480->guuid=a581f5ec-1c00-0000-3845-a46c81110000 pid=4481 execve guuid=6b2087ef-1c00-0000-3845-a46c8e110000 pid=4494 /usr/bin/pgrep guuid=7d065def-1c00-0000-3845-a46c8a110000 pid=4490->guuid=6b2087ef-1c00-0000-3845-a46c8e110000 pid=4494 execve guuid=c2e5aaf3-1c00-0000-3845-a46ca0110000 pid=4512 /usr/bin/pgrep guuid=c6336ff3-1c00-0000-3845-a46c9f110000 pid=4511->guuid=c2e5aaf3-1c00-0000-3845-a46ca0110000 pid=4512 execve guuid=6d5437f7-1c00-0000-3845-a46caf110000 pid=4527 /usr/bin/pgrep guuid=70cafef6-1c00-0000-3845-a46cad110000 pid=4525->guuid=6d5437f7-1c00-0000-3845-a46caf110000 pid=4527 execve guuid=d3109efb-1c00-0000-3845-a46cbc110000 pid=4540 /usr/bin/pgrep guuid=687365fb-1c00-0000-3845-a46cbb110000 pid=4539->guuid=d3109efb-1c00-0000-3845-a46cbc110000 pid=4540 execve guuid=a5c822ff-1c00-0000-3845-a46cc7110000 pid=4551 /usr/bin/pgrep guuid=4332fcfe-1c00-0000-3845-a46cc6110000 pid=4550->guuid=a5c822ff-1c00-0000-3845-a46cc7110000 pid=4551 execve guuid=85900603-1d00-0000-3845-a46cd0110000 pid=4560 /usr/bin/pgrep guuid=3b0dc602-1d00-0000-3845-a46ccf110000 pid=4559->guuid=85900603-1d00-0000-3845-a46cd0110000 pid=4560 execve guuid=f3637f05-1d00-0000-3845-a46cd9110000 pid=4569 /usr/bin/pgrep guuid=8df25405-1d00-0000-3845-a46cd8110000 pid=4568->guuid=f3637f05-1d00-0000-3845-a46cd9110000 pid=4569 execve guuid=88a8890a-1d00-0000-3845-a46ce7110000 pid=4583 /usr/bin/pgrep guuid=d09d580a-1d00-0000-3845-a46ce5110000 pid=4581->guuid=88a8890a-1d00-0000-3845-a46ce7110000 pid=4583 execve guuid=e9be1e10-1d00-0000-3845-a46cff110000 pid=4607 /usr/bin/pgrep guuid=0f15e60f-1d00-0000-3845-a46cfb110000 pid=4603->guuid=e9be1e10-1d00-0000-3845-a46cff110000 pid=4607 execve guuid=f97bee12-1d00-0000-3845-a46c0e120000 pid=4622 /usr/bin/pgrep guuid=af01bd12-1d00-0000-3845-a46c0a120000 pid=4618->guuid=f97bee12-1d00-0000-3845-a46c0e120000 pid=4622 execve guuid=4a318c15-1d00-0000-3845-a46c1b120000 pid=4635 /usr/bin/pgrep guuid=ed8c6715-1d00-0000-3845-a46c17120000 pid=4631->guuid=4a318c15-1d00-0000-3845-a46c1b120000 pid=4635 execve guuid=6b659d18-1d00-0000-3845-a46c2a120000 pid=4650 /usr/bin/pgrep guuid=2dfb5e18-1d00-0000-3845-a46c29120000 pid=4649->guuid=6b659d18-1d00-0000-3845-a46c2a120000 pid=4650 execve guuid=34e55d1b-1d00-0000-3845-a46c38120000 pid=4664 /usr/bin/pgrep guuid=9e05341b-1d00-0000-3845-a46c37120000 pid=4663->guuid=34e55d1b-1d00-0000-3845-a46c38120000 pid=4664 execve guuid=8064cc1e-1d00-0000-3845-a46c4b120000 pid=4683 /usr/bin/pgrep guuid=a760a81e-1d00-0000-3845-a46c49120000 pid=4681->guuid=8064cc1e-1d00-0000-3845-a46c4b120000 pid=4683 execve guuid=03edf521-1d00-0000-3845-a46c56120000 pid=4694 /usr/bin/pgrep guuid=1931c721-1d00-0000-3845-a46c54120000 pid=4692->guuid=03edf521-1d00-0000-3845-a46c56120000 pid=4694 execve guuid=14d6cb24-1d00-0000-3845-a46c60120000 pid=4704 /usr/bin/pgrep guuid=3e22a024-1d00-0000-3845-a46c5f120000 pid=4703->guuid=14d6cb24-1d00-0000-3845-a46c60120000 pid=4704 execve guuid=01699a27-1d00-0000-3845-a46c68120000 pid=4712 /usr/bin/pgrep guuid=efb86127-1d00-0000-3845-a46c66120000 pid=4710->guuid=01699a27-1d00-0000-3845-a46c68120000 pid=4712 execve guuid=7ebb262b-1d00-0000-3845-a46c7a120000 pid=4730 /usr/bin/pgrep guuid=242fe62a-1d00-0000-3845-a46c79120000 pid=4729->guuid=7ebb262b-1d00-0000-3845-a46c7a120000 pid=4730 execve guuid=8098842e-1d00-0000-3845-a46c8a120000 pid=4746 /usr/bin/pgrep guuid=40505a2e-1d00-0000-3845-a46c88120000 pid=4744->guuid=8098842e-1d00-0000-3845-a46c8a120000 pid=4746 execve guuid=8ed83631-1d00-0000-3845-a46c97120000 pid=4759 /usr/bin/pgrep guuid=ca1e0e31-1d00-0000-3845-a46c94120000 pid=4756->guuid=8ed83631-1d00-0000-3845-a46c97120000 pid=4759 execve guuid=d538de35-1d00-0000-3845-a46cac120000 pid=4780 /usr/bin/rm guuid=a6b69735-1d00-0000-3845-a46caa120000 pid=4778->guuid=d538de35-1d00-0000-3845-a46cac120000 pid=4780 execve guuid=5f217236-1d00-0000-3845-a46cb1120000 pid=4785 /usr/bin/rm guuid=bc914336-1d00-0000-3845-a46caf120000 pid=4783->guuid=5f217236-1d00-0000-3845-a46cb1120000 pid=4785 execve guuid=ae25ec36-1d00-0000-3845-a46cb6120000 pid=4790 /usr/bin/rm guuid=79b7c136-1d00-0000-3845-a46cb2120000 pid=4786->guuid=ae25ec36-1d00-0000-3845-a46cb6120000 pid=4790 execve guuid=128d9f37-1d00-0000-3845-a46cb8120000 pid=4792 /usr/bin/rm guuid=61cc5e37-1d00-0000-3845-a46cb7120000 pid=4791->guuid=128d9f37-1d00-0000-3845-a46cb8120000 pid=4792 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
spre.troj.evad.mine
Score:
84 / 100
Signature
Drops files in suspicious directories
Executes the "crontab" command typically for achieving persistence
Found strings related to Crypto-Mining
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Sample tries to set files in /etc globally writable
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1844406 Sample: i486.elf Startdate: 04/01/2026 Architecture: LINUX Score: 84 65 45.153.34.74, 12344, 41054 SKYLINKNL Germany 2->65 67 Malicious sample detected (through community Yara rule) 2->67 69 Multi AV Scanner detection for submitted file 2->69 9 i486.elf 2->9         started        signatures3 process4 signatures5 73 Found strings related to Crypto-Mining 9->73 12 i486.elf 9->12         started        14 i486.elf sh 9->14         started        16 i486.elf sh 9->16         started        18 3 other processes 9->18 process6 file7 22 i486.elf sh 12->22         started        24 i486.elf sh 12->24         started        26 i486.elf sh 12->26         started        38 41 other processes 12->38 28 sh crontab 14->28         started        32 sh 14->32         started        34 sh cp 16->34         started        36 sh chmod 16->36         started        59 /etc/rc.local, ASCII 18->59 dropped 71 Sample tries to persist itself using System V runlevels 18->71 40 2 other processes 18->40 signatures8 process9 file10 42 sh pkill 22->42         started        45 sh pkill 24->45         started        47 sh pkill 26->47         started        61 /var/spool/cron/crontabs/tmp.8VI3Hy, ASCII 28->61 dropped 79 Sample tries to persist itself using cron 28->79 81 Executes the "crontab" command typically for achieving persistence 28->81 49 sh crontab 32->49         started        63 /usr/bin/systemd-update, ELF 34->63 dropped 83 Drops files in suspicious directories 34->83 51 sh crontab 38->51         started        53 sh pkill 38->53         started        55 sh pkill 38->55         started        57 39 other processes 38->57 85 Sample tries to set files in /etc globally writable 40->85 signatures11 process12 signatures13 75 Sample tries to kill multiple processes (SIGKILL) 42->75 77 Executes the "crontab" command typically for achieving persistence 49->77
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-01-04 06:14:05 UTC
File Type:
ELF32 Little (Exe)
AV detection:
14 of 38 (36.84%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
Modifies rc script
Modifies systemd
Write file to user bin folder
File and Directory Permissions Modification
Modifies hosts file
Verdict:
Unknown
Tags:
trojan mirai
YARA:
Linux_Trojan_Mirai_3a56423b
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_Mirai
Author:NDA0E
Description:Detects multiple Mirai variants
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Mirai_3a56423b
Author:Elastic Security
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf a25c180db1c0bf0c233bb7cb936b6a6202e6b5e3ab792d3bfb198e4aeab94dfb

(this sample)

  
Delivery method
Distributed via web download

Comments