MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa8957d62054a2ec5f3f8306f37230e79830aca7dfc26859dcd1c5496079ab23. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: aa8957d62054a2ec5f3f8306f37230e79830aca7dfc26859dcd1c5496079ab23
SHA3-384 hash: 8687e6daf74f9c7381ec5f91a84beb51a98f20c64c373f167820f905f864326543b2e40bde9210e1539bac4611edbbc3
SHA1 hash: 2c1f5f2f8ad00dc61fc1e909c8102ecbc9f3b428
MD5 hash: 8a2cdc37f59f7979b79d52b399461833
humanhash: neptune-princess-mobile-bacon
File name:m68k
Download: download sample
Signature Mirai
File size:92'116 bytes
First seen:2025-11-14 18:30:47 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:TO6T+MTF9Kt4xj2mrbO8iJynaUZ2CQKmLMg5G744keh3TneVGyQ:K6aMTTAGj2mrbWynaUXm44Ah3TneVGyQ
TLSH T12F934BE2FC02EE7EF84FD77B44570D19B630A3A125931E3573A3BA17A8351994863E81
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
148
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2025-11-14T16:18:00Z UTC
Last seen:
2025-11-16T01:59:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=691fc709-1700-0000-a53c-5eba010e0000 pid=3585 /usr/bin/sudo guuid=a306060c-1700-0000-a53c-5eba080e0000 pid=3592 /tmp/sample.bin guuid=691fc709-1700-0000-a53c-5eba010e0000 pid=3585->guuid=a306060c-1700-0000-a53c-5eba080e0000 pid=3592 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1814390 Sample: m68k.elf Startdate: 14/11/2025 Architecture: LINUX Score: 48 12 109.202.202.202, 80 INIT7CH Switzerland 2->12 14 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->14 16 3 other IPs or domains 2->16 18 Multi AV Scanner detection for submitted file 2->18 6 dash rm 2->6         started        8 dash rm 2->8         started        10 m68k.elf 2->10         started        signatures3 process4
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-11-14 18:31:22 UTC
File Type:
ELF32 Big (Exe)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai linux
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-6981989-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf aa8957d62054a2ec5f3f8306f37230e79830aca7dfc26859dcd1c5496079ab23

(this sample)

  
Delivery method
Distributed via web download

Comments