MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a29c5b31347714fd1e7470ade9d5fffc183ff86029969dcf313729fe7292f310. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 4 File information Comments

SHA256 hash: a29c5b31347714fd1e7470ade9d5fffc183ff86029969dcf313729fe7292f310
SHA3-384 hash: 5b9e4c4eb4794fdf8412f955d31428ffda8f283ca5f9de0a180329fec4ebe2cbbc86ee614dbb036564b6fa471f4fd8be
SHA1 hash: c6a633bc3411ab15b0e3014482f04e35cbc1f78f
MD5 hash: 2477fae010693c81b980320ad2b40300
humanhash: zebra-mexico-gee-spring
File name:i486
Download: download sample
Signature Mirai
File size:61'984 bytes
First seen:2026-08-23 03:01:30 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:GYEsXD9bV0eCTfoaHr4LTk7B01XTnouy8Lzkk/:JEG30dwQS1XroutUk/
TLSH T1E35302DF51845B60D205423D28DF3DADE818830FFA8966D9E9CD6C31E69F3516A10BE3
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf UPX
File size (compressed) :61'984 bytes
File size (de-compressed) :124'140 bytes
Format:linux/i386
Unpacked file: cef3bbc2c3ffc6f7b8b5a89d0494d219d5a08304f3f7436d702b139fa9859c50

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Connection attempt
Deleting a recently created file
Sets a written file as executable
Sets a file as executable
Runs as daemon
Deletes a file
Locks files
Kills processes
Creating a file
Collects information on the CPU
Creating a process from a recently created file
Kills critical processes
Substitutes an application name
Deleting of the original file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
mirai packed packer upx
Status:
terminated
Behavior Graph:
%3 guuid=1b22a9fb-1c00-0000-9b0d-aa2ea9080000 pid=2217 /usr/bin/sudo guuid=b1b7b3fd-1c00-0000-9b0d-aa2eb0080000 pid=2224 /tmp/sample.bin guuid=1b22a9fb-1c00-0000-9b0d-aa2ea9080000 pid=2217->guuid=b1b7b3fd-1c00-0000-9b0d-aa2eb0080000 pid=2224 execve guuid=f99ecc00-1d00-0000-9b0d-aa2eb2080000 pid=2226 /tmp/sample.bin guuid=b1b7b3fd-1c00-0000-9b0d-aa2eb0080000 pid=2224->guuid=f99ecc00-1d00-0000-9b0d-aa2eb2080000 pid=2226 clone guuid=22eaec00-1d00-0000-9b0d-aa2eb3080000 pid=2227 memfd:1313570585 write-file zombie guuid=f99ecc00-1d00-0000-9b0d-aa2eb2080000 pid=2226->guuid=22eaec00-1d00-0000-9b0d-aa2eb3080000 pid=2227 execve guuid=22eaec00-1d00-0000-9b0d-aa2eb3080000 pid=2228 /tmp/sample.bin guuid=22eaec00-1d00-0000-9b0d-aa2eb3080000 pid=2227->guuid=22eaec00-1d00-0000-9b0d-aa2eb3080000 pid=2228 clone guuid=51e82901-1d00-0000-9b0d-aa2eb5080000 pid=2229 /tmp/sample.bin guuid=22eaec00-1d00-0000-9b0d-aa2eb3080000 pid=2227->guuid=51e82901-1d00-0000-9b0d-aa2eb5080000 pid=2229 clone guuid=a3114e01-1d00-0000-9b0d-aa2eb6080000 pid=2230 /usr/sbin/xtables-nft-multi guuid=22eaec00-1d00-0000-9b0d-aa2eb3080000 pid=2227->guuid=a3114e01-1d00-0000-9b0d-aa2eb6080000 pid=2230 execve guuid=78ef2911-1d00-0000-9b0d-aa2ed2080000 pid=2258 /usr/sbin/xtables-nft-multi guuid=22eaec00-1d00-0000-9b0d-aa2eb3080000 pid=2227->guuid=78ef2911-1d00-0000-9b0d-aa2ed2080000 pid=2258 execve guuid=56177a11-1d00-0000-9b0d-aa2ed3080000 pid=2259 /tmp/sample.bin write-file zombie guuid=22eaec00-1d00-0000-9b0d-aa2eb3080000 pid=2227->guuid=56177a11-1d00-0000-9b0d-aa2ed3080000 pid=2259 clone guuid=1d48ff14-1d00-0000-9b0d-aa2eda080000 pid=2266 memfd:1313570585 guuid=22eaec00-1d00-0000-9b0d-aa2eb3080000 pid=2227->guuid=1d48ff14-1d00-0000-9b0d-aa2eda080000 pid=2266 clone guuid=bd6a0715-1d00-0000-9b0d-aa2edb080000 pid=2267 memfd:1313570585 delete-file net send-data write-file zombie guuid=1d48ff14-1d00-0000-9b0d-aa2eda080000 pid=2266->guuid=bd6a0715-1d00-0000-9b0d-aa2edb080000 pid=2267 clone 43107d06-e1b8-559a-8721-01616c7cb4c1 83.168.69.141:9482 guuid=bd6a0715-1d00-0000-9b0d-aa2edb080000 pid=2267->43107d06-e1b8-559a-8721-01616c7cb4c1 send: 19B guuid=bd6a0715-1d00-0000-9b0d-aa2edb080000 pid=2268 memfd:1313570585 zombie guuid=bd6a0715-1d00-0000-9b0d-aa2edb080000 pid=2267->guuid=bd6a0715-1d00-0000-9b0d-aa2edb080000 pid=2268 clone guuid=59611d15-1d00-0000-9b0d-aa2edd080000 pid=2269 memfd:1313570585 guuid=bd6a0715-1d00-0000-9b0d-aa2edb080000 pid=2267->guuid=59611d15-1d00-0000-9b0d-aa2edd080000 pid=2269 clone guuid=73183815-1d00-0000-9b0d-aa2ede080000 pid=2270 /usr/sbin/xtables-nft-multi guuid=bd6a0715-1d00-0000-9b0d-aa2edb080000 pid=2267->guuid=73183815-1d00-0000-9b0d-aa2ede080000 pid=2270 execve guuid=cf687617-1d00-0000-9b0d-aa2ee1080000 pid=2273 /usr/sbin/xtables-nft-multi guuid=bd6a0715-1d00-0000-9b0d-aa2edb080000 pid=2267->guuid=cf687617-1d00-0000-9b0d-aa2ee1080000 pid=2273 execve guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275 memfd:1313570585 delete-file write-config write-file zombie guuid=bd6a0715-1d00-0000-9b0d-aa2edb080000 pid=2267->guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275 clone guuid=cc8f1d24-1d00-0000-9b0d-aa2ef8080000 pid=2296 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=cc8f1d24-1d00-0000-9b0d-aa2ef8080000 pid=2296 execve guuid=dfa28a24-1d00-0000-9b0d-aa2efa080000 pid=2298 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=dfa28a24-1d00-0000-9b0d-aa2efa080000 pid=2298 execve guuid=87481f25-1d00-0000-9b0d-aa2efc080000 pid=2300 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=87481f25-1d00-0000-9b0d-aa2efc080000 pid=2300 execve guuid=dee17d25-1d00-0000-9b0d-aa2efd080000 pid=2301 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=dee17d25-1d00-0000-9b0d-aa2efd080000 pid=2301 execve guuid=1cf5dd25-1d00-0000-9b0d-aa2eff080000 pid=2303 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=1cf5dd25-1d00-0000-9b0d-aa2eff080000 pid=2303 execve guuid=da847230-1d00-0000-9b0d-aa2e15090000 pid=2325 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=da847230-1d00-0000-9b0d-aa2e15090000 pid=2325 execve guuid=09dc4031-1d00-0000-9b0d-aa2e17090000 pid=2327 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=09dc4031-1d00-0000-9b0d-aa2e17090000 pid=2327 execve guuid=62cfab31-1d00-0000-9b0d-aa2e19090000 pid=2329 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=62cfab31-1d00-0000-9b0d-aa2e19090000 pid=2329 execve guuid=f04d0832-1d00-0000-9b0d-aa2e1b090000 pid=2331 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=f04d0832-1d00-0000-9b0d-aa2e1b090000 pid=2331 execve guuid=83196932-1d00-0000-9b0d-aa2e1d090000 pid=2333 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=83196932-1d00-0000-9b0d-aa2e1d090000 pid=2333 execve guuid=78c9c432-1d00-0000-9b0d-aa2e1e090000 pid=2334 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=78c9c432-1d00-0000-9b0d-aa2e1e090000 pid=2334 execve guuid=7bb31f33-1d00-0000-9b0d-aa2e20090000 pid=2336 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=7bb31f33-1d00-0000-9b0d-aa2e20090000 pid=2336 execve guuid=b9967e33-1d00-0000-9b0d-aa2e21090000 pid=2337 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=b9967e33-1d00-0000-9b0d-aa2e21090000 pid=2337 execve guuid=6690df33-1d00-0000-9b0d-aa2e23090000 pid=2339 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=6690df33-1d00-0000-9b0d-aa2e23090000 pid=2339 execve guuid=c8f33b34-1d00-0000-9b0d-aa2e24090000 pid=2340 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=c8f33b34-1d00-0000-9b0d-aa2e24090000 pid=2340 execve guuid=192b9f34-1d00-0000-9b0d-aa2e26090000 pid=2342 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=192b9f34-1d00-0000-9b0d-aa2e26090000 pid=2342 execve guuid=e27df934-1d00-0000-9b0d-aa2e28090000 pid=2344 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=e27df934-1d00-0000-9b0d-aa2e28090000 pid=2344 execve guuid=636a5d35-1d00-0000-9b0d-aa2e29090000 pid=2345 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=636a5d35-1d00-0000-9b0d-aa2e29090000 pid=2345 execve guuid=0619bc35-1d00-0000-9b0d-aa2e2b090000 pid=2347 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=0619bc35-1d00-0000-9b0d-aa2e2b090000 pid=2347 execve guuid=77103b36-1d00-0000-9b0d-aa2e2c090000 pid=2348 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=77103b36-1d00-0000-9b0d-aa2e2c090000 pid=2348 execve guuid=f9ebb236-1d00-0000-9b0d-aa2e2e090000 pid=2350 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=f9ebb236-1d00-0000-9b0d-aa2e2e090000 pid=2350 execve guuid=24172137-1d00-0000-9b0d-aa2e30090000 pid=2352 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=24172137-1d00-0000-9b0d-aa2e30090000 pid=2352 execve guuid=461da837-1d00-0000-9b0d-aa2e32090000 pid=2354 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=461da837-1d00-0000-9b0d-aa2e32090000 pid=2354 execve guuid=e8743b38-1d00-0000-9b0d-aa2e33090000 pid=2355 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=e8743b38-1d00-0000-9b0d-aa2e33090000 pid=2355 execve guuid=a356b238-1d00-0000-9b0d-aa2e34090000 pid=2356 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=a356b238-1d00-0000-9b0d-aa2e34090000 pid=2356 execve guuid=ddf94f39-1d00-0000-9b0d-aa2e37090000 pid=2359 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=ddf94f39-1d00-0000-9b0d-aa2e37090000 pid=2359 execve guuid=5a939768-1d00-0000-9b0d-aa2e8d090000 pid=2445 /usr/bin/systemctl guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=5a939768-1d00-0000-9b0d-aa2e8d090000 pid=2445 execve guuid=ee7037c2-1d00-0000-9b0d-aa2e170a0000 pid=2583 /usr/bin/systemctl guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=ee7037c2-1d00-0000-9b0d-aa2e170a0000 pid=2583 execve guuid=049bdf18-1e00-0000-9b0d-aa2e9c0a0000 pid=2716 memfd:1313570585 write-file guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=049bdf18-1e00-0000-9b0d-aa2e9c0a0000 pid=2716 clone guuid=23926569-1e00-0000-9b0d-aa2ee70a0000 pid=2791 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=23926569-1e00-0000-9b0d-aa2ee70a0000 pid=2791 execve guuid=d2c8e169-1e00-0000-9b0d-aa2ee90a0000 pid=2793 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=d2c8e169-1e00-0000-9b0d-aa2ee90a0000 pid=2793 execve guuid=29ff566b-1e00-0000-9b0d-aa2eec0a0000 pid=2796 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=29ff566b-1e00-0000-9b0d-aa2eec0a0000 pid=2796 execve guuid=4ebe2a6c-1e00-0000-9b0d-aa2eee0a0000 pid=2798 /usr/sbin/xtables-nft-multi guuid=9b420c18-1d00-0000-9b0d-aa2ee3080000 pid=2275->guuid=4ebe2a6c-1e00-0000-9b0d-aa2eee0a0000 pid=2798 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
spre.evad.mine
Score:
80 / 100
Signature
Deletes system log files
Found strings related to Crypto-Mining
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample is packed with UPX
Sample tries to kill multiple processes (SIGKILL)
Spawns processes using file descriptor names (likely to hide the executable path or fileless malware)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1962325 Sample: i486.elf Startdate: 23/08/2026 Architecture: LINUX Score: 80 60 169.254.169.254, 80 USDOS-USDepartmentofStateUS ZZ 2->60 62 83.168.69.141, 57572, 57574, 57576 SKYPASS-ASPL Poland 2->62 64 Malicious sample detected (through community Yara rule) 2->64 66 Multi AV Scanner detection for submitted file 2->66 68 Sample is packed with UPX 2->68 11 i486.elf 2->11         started        14 systemd snapd-env-generator 2->14         started        16 systemd snapd-env-generator 2->16         started        18 python3.8 dpkg 2->18         started        signatures3 process4 signatures5 78 Found strings related to Crypto-Mining 11->78 20 i486.elf 11->20         started        process6 process7 22 i486.elf 3 20->22         started        file8 58 /memfd:508712556 (deleted), ELF 22->58 dropped 70 Spawns processes using file descriptor names (likely to hide the executable path or fileless malware) 22->70 26 i486.elf 22->26         started        29 3 22->29         started        31 i486.elf iptables 22->31         started        33 2 other processes 22->33 signatures9 process10 signatures11 72 Sample tries to kill multiple processes (SIGKILL) 26->72 74 Deletes system log files 26->74 35 i486.elf 26->35         started        38 i486.elf iptables 26->38         started        40 i486.elf iptables 26->40         started        45 41 other processes 26->45 42 3 29->42         started        process12 file13 56 /run/.watchdog.pid, ASCII 35->56 dropped 76 Sample deletes itself 42->76 47 3 42->47         started        50 3 42->50         started        52 3 iptables 42->52         started        54 3 iptables 42->54         started        signatures14 process15 signatures16 80 Sample tries to kill multiple processes (SIGKILL) 47->80
Threat name:
Linux.Trojan.Malgent
Status:
Malicious
First seen:
2026-08-23 03:10:49 UTC
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm discovery linux upx
Behaviour
Reads runtime system information
Changes its process name
Checks CPU configuration
UPX packed file
Checks hardware identifiers (DMI)
Enumerates running processes
Deletes itself
Runs EXE from memory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf a29c5b31347714fd1e7470ade9d5fffc183ff86029969dcf313729fe7292f310

(this sample)

  
Delivery method
Distributed via web download

Comments