MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ac17a0c00de0a53dbe5fb9bb19af2c789685a20a56ccaea840b8df1d191d4012. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA 3 File information Comments

SHA256 hash: ac17a0c00de0a53dbe5fb9bb19af2c789685a20a56ccaea840b8df1d191d4012
SHA3-384 hash: 23c10a2029b08c364db0668242367ee6d114e784009aabc0a8d02ea07e61ace49ca396912969f7c93f36ec3aac8b3736
SHA1 hash: d6f93cda7ad30e6eac7363624c94eac10c1c27bb
MD5 hash: 1e16b7bad5a907a345dc45cc7983f577
humanhash: pennsylvania-alabama-coffee-juliet
File name:i686
Download: download sample
Signature Mirai
File size:38'896 bytes
First seen:2025-08-24 01:20:42 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:dTPqiDDYb7z8qvXyPlXHDPNWS4rV8DW7ohqbRcCN:NqiD0b3RyNHDVWS4u3hiP
TLSH T143036BC5E623C4F1DCA502B01037EB647F71D43A6A35EA4BCB59A636AC43B40A71B39D
telfhash t1ac21cdf5beab09fcf691bc5ccb1f27f32708da6b169028b584e539413af210090a2830
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Receives data from a server
Runs as daemon
Mounts file systems
Sends data to a server
Connection attempt
Substitutes an application name
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
38
Number of processes launched:
2
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=a8c6f137-1b00-0000-b8bf-fddd240a0000 pid=2596 /usr/bin/sudo guuid=e1dd6e3a-1b00-0000-b8bf-fddd2c0a0000 pid=2604 /tmp/sample.bin guuid=a8c6f137-1b00-0000-b8bf-fddd240a0000 pid=2596->guuid=e1dd6e3a-1b00-0000-b8bf-fddd2c0a0000 pid=2604 execve guuid=14c1f27a-1b00-0000-b8bf-fdddd50a0000 pid=2773 /tmp/sample.bin net send-data zombie guuid=e1dd6e3a-1b00-0000-b8bf-fddd2c0a0000 pid=2604->guuid=14c1f27a-1b00-0000-b8bf-fdddd50a0000 pid=2773 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=14c1f27a-1b00-0000-b8bf-fdddd50a0000 pid=2773->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 2b659683-be59-5022-8f04-927e151f5c7e 217.60.248.199:1025 guuid=14c1f27a-1b00-0000-b8bf-fdddd50a0000 pid=2773->2b659683-be59-5022-8f04-927e151f5c7e send: 14B guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778 /tmp/sample.bin guuid=14c1f27a-1b00-0000-b8bf-fdddd50a0000 pid=2773->guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778 clone guuid=ce173ba7-1b00-0000-b8bf-fddd440b0000 pid=2884 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=ce173ba7-1b00-0000-b8bf-fddd440b0000 pid=2884 clone guuid=685e1ef7-1b00-0000-b8bf-fdddf00b0000 pid=3056 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=685e1ef7-1b00-0000-b8bf-fdddf00b0000 pid=3056 clone guuid=3db164b4-1c00-0000-b8bf-fddd4b0d0000 pid=3403 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=3db164b4-1c00-0000-b8bf-fddd4b0d0000 pid=3403 clone guuid=406171b4-1c00-0000-b8bf-fddd4c0d0000 pid=3404 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=406171b4-1c00-0000-b8bf-fddd4c0d0000 pid=3404 clone guuid=e56595b7-1c00-0000-b8bf-fddd560d0000 pid=3414 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=e56595b7-1c00-0000-b8bf-fddd560d0000 pid=3414 clone guuid=284ec3b7-1c00-0000-b8bf-fddd580d0000 pid=3416 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=284ec3b7-1c00-0000-b8bf-fddd580d0000 pid=3416 clone guuid=7d39b4b8-1c00-0000-b8bf-fddd5b0d0000 pid=3419 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=7d39b4b8-1c00-0000-b8bf-fddd5b0d0000 pid=3419 clone guuid=a08d06b9-1c00-0000-b8bf-fddd5e0d0000 pid=3422 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=a08d06b9-1c00-0000-b8bf-fddd5e0d0000 pid=3422 clone guuid=37bd99ba-1c00-0000-b8bf-fddd640d0000 pid=3428 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=37bd99ba-1c00-0000-b8bf-fddd640d0000 pid=3428 clone guuid=ee613dbc-1c00-0000-b8bf-fddd6a0d0000 pid=3434 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=ee613dbc-1c00-0000-b8bf-fddd6a0d0000 pid=3434 clone guuid=b88955be-1c00-0000-b8bf-fddd710d0000 pid=3441 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=b88955be-1c00-0000-b8bf-fddd710d0000 pid=3441 clone guuid=65c0e6be-1c00-0000-b8bf-fddd750d0000 pid=3445 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=65c0e6be-1c00-0000-b8bf-fddd750d0000 pid=3445 clone guuid=926ad1d4-1c00-0000-b8bf-fdddc10d0000 pid=3521 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=926ad1d4-1c00-0000-b8bf-fdddc10d0000 pid=3521 clone guuid=436bf1d5-1c00-0000-b8bf-fdddc50d0000 pid=3525 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=436bf1d5-1c00-0000-b8bf-fdddc50d0000 pid=3525 clone guuid=a455ecd7-1c00-0000-b8bf-fdddcf0d0000 pid=3535 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=a455ecd7-1c00-0000-b8bf-fdddcf0d0000 pid=3535 clone guuid=36ff00db-1c00-0000-b8bf-fdddd90d0000 pid=3545 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=36ff00db-1c00-0000-b8bf-fdddd90d0000 pid=3545 clone guuid=d08020de-1c00-0000-b8bf-fddde10d0000 pid=3553 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=d08020de-1c00-0000-b8bf-fddde10d0000 pid=3553 clone guuid=783e85e0-1c00-0000-b8bf-fddde70d0000 pid=3559 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=783e85e0-1c00-0000-b8bf-fddde70d0000 pid=3559 clone guuid=89ea19e3-1c00-0000-b8bf-fdddf20d0000 pid=3570 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=89ea19e3-1c00-0000-b8bf-fdddf20d0000 pid=3570 clone guuid=6c41f7e4-1c00-0000-b8bf-fdddfb0d0000 pid=3579 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=6c41f7e4-1c00-0000-b8bf-fdddfb0d0000 pid=3579 clone guuid=8f0942e9-1c00-0000-b8bf-fddd050e0000 pid=3589 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=8f0942e9-1c00-0000-b8bf-fddd050e0000 pid=3589 clone guuid=e076e5ea-1c00-0000-b8bf-fddd0b0e0000 pid=3595 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=e076e5ea-1c00-0000-b8bf-fddd0b0e0000 pid=3595 clone guuid=0c5710ec-1c00-0000-b8bf-fddd110e0000 pid=3601 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=0c5710ec-1c00-0000-b8bf-fddd110e0000 pid=3601 clone guuid=c1ad55ee-1c00-0000-b8bf-fddd1a0e0000 pid=3610 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=c1ad55ee-1c00-0000-b8bf-fddd1a0e0000 pid=3610 clone guuid=e75866f0-1c00-0000-b8bf-fddd230e0000 pid=3619 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=e75866f0-1c00-0000-b8bf-fddd230e0000 pid=3619 clone guuid=d8beeef2-1c00-0000-b8bf-fddd2c0e0000 pid=3628 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=d8beeef2-1c00-0000-b8bf-fddd2c0e0000 pid=3628 clone guuid=07af4ff5-1c00-0000-b8bf-fddd350e0000 pid=3637 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=07af4ff5-1c00-0000-b8bf-fddd350e0000 pid=3637 clone guuid=2e4ab8f8-1c00-0000-b8bf-fddd440e0000 pid=3652 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=2e4ab8f8-1c00-0000-b8bf-fddd440e0000 pid=3652 clone guuid=5976a004-1d00-0000-b8bf-fddd5d0e0000 pid=3677 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=5976a004-1d00-0000-b8bf-fddd5d0e0000 pid=3677 clone guuid=a1293207-1d00-0000-b8bf-fddd630e0000 pid=3683 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=a1293207-1d00-0000-b8bf-fddd630e0000 pid=3683 clone guuid=1087100a-1d00-0000-b8bf-fddd6a0e0000 pid=3690 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=1087100a-1d00-0000-b8bf-fddd6a0e0000 pid=3690 clone guuid=97309b0e-1d00-0000-b8bf-fddd6c0e0000 pid=3692 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=97309b0e-1d00-0000-b8bf-fddd6c0e0000 pid=3692 clone guuid=4e20ae0e-1d00-0000-b8bf-fddd6e0e0000 pid=3694 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=4e20ae0e-1d00-0000-b8bf-fddd6e0e0000 pid=3694 clone guuid=4c1f300f-1d00-0000-b8bf-fddd710e0000 pid=3697 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=4c1f300f-1d00-0000-b8bf-fddd710e0000 pid=3697 clone guuid=7eeb156e-1d00-0000-b8bf-fddd780e0000 pid=3704 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=7eeb156e-1d00-0000-b8bf-fddd780e0000 pid=3704 clone guuid=6ecab072-1d00-0000-b8bf-fddd790e0000 pid=3705 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=6ecab072-1d00-0000-b8bf-fddd790e0000 pid=3705 clone guuid=c1a0fc73-1d00-0000-b8bf-fddd7c0e0000 pid=3708 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=c1a0fc73-1d00-0000-b8bf-fddd7c0e0000 pid=3708 clone guuid=67c30f74-1d00-0000-b8bf-fddd7d0e0000 pid=3709 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=67c30f74-1d00-0000-b8bf-fddd7d0e0000 pid=3709 clone guuid=14f14874-1d00-0000-b8bf-fddd7f0e0000 pid=3711 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=14f14874-1d00-0000-b8bf-fddd7f0e0000 pid=3711 clone guuid=1f256a74-1d00-0000-b8bf-fddd810e0000 pid=3713 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=1f256a74-1d00-0000-b8bf-fddd810e0000 pid=3713 clone guuid=feee9774-1d00-0000-b8bf-fddd830e0000 pid=3715 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=feee9774-1d00-0000-b8bf-fddd830e0000 pid=3715 clone guuid=b487bc74-1d00-0000-b8bf-fddd850e0000 pid=3717 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=b487bc74-1d00-0000-b8bf-fddd850e0000 pid=3717 clone guuid=6d260475-1d00-0000-b8bf-fddd870e0000 pid=3719 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=6d260475-1d00-0000-b8bf-fddd870e0000 pid=3719 clone guuid=e5662675-1d00-0000-b8bf-fddd890e0000 pid=3721 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=e5662675-1d00-0000-b8bf-fddd890e0000 pid=3721 clone guuid=074a4675-1d00-0000-b8bf-fddd8b0e0000 pid=3723 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=074a4675-1d00-0000-b8bf-fddd8b0e0000 pid=3723 clone guuid=d4666875-1d00-0000-b8bf-fddd8d0e0000 pid=3725 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=d4666875-1d00-0000-b8bf-fddd8d0e0000 pid=3725 clone guuid=163bc975-1d00-0000-b8bf-fddd8f0e0000 pid=3727 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=163bc975-1d00-0000-b8bf-fddd8f0e0000 pid=3727 clone guuid=5a56ee75-1d00-0000-b8bf-fddd910e0000 pid=3729 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=5a56ee75-1d00-0000-b8bf-fddd910e0000 pid=3729 clone guuid=583b2e76-1d00-0000-b8bf-fddd930e0000 pid=3731 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=583b2e76-1d00-0000-b8bf-fddd930e0000 pid=3731 clone guuid=1fefc130-2900-0000-b8bf-fddd980e0000 pid=3736 /tmp/sample.bin net send-data guuid=a90c267c-1b00-0000-b8bf-fdddda0a0000 pid=2778->guuid=1fefc130-2900-0000-b8bf-fddd980e0000 pid=3736 clone d7e75a5d-65d1-5941-aac4-e4015a0a0899 31.56.39.76:6969 guuid=ce173ba7-1b00-0000-b8bf-fddd440b0000 pid=2884->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 34B guuid=685e1ef7-1b00-0000-b8bf-fdddf00b0000 pid=3056->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 40B guuid=3db164b4-1c00-0000-b8bf-fddd4b0d0000 pid=3403->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 33B guuid=406171b4-1c00-0000-b8bf-fddd4c0d0000 pid=3404->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 40B guuid=e56595b7-1c00-0000-b8bf-fddd560d0000 pid=3414->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 40B guuid=284ec3b7-1c00-0000-b8bf-fddd580d0000 pid=3416->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 40B guuid=7d39b4b8-1c00-0000-b8bf-fddd5b0d0000 pid=3419->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 35B guuid=a08d06b9-1c00-0000-b8bf-fddd5e0d0000 pid=3422->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 32B guuid=37bd99ba-1c00-0000-b8bf-fddd640d0000 pid=3428->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 38B guuid=ee613dbc-1c00-0000-b8bf-fddd6a0d0000 pid=3434->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 33B guuid=b88955be-1c00-0000-b8bf-fddd710d0000 pid=3441->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 38B guuid=65c0e6be-1c00-0000-b8bf-fddd750d0000 pid=3445->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=926ad1d4-1c00-0000-b8bf-fdddc10d0000 pid=3521->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 36B guuid=436bf1d5-1c00-0000-b8bf-fdddc50d0000 pid=3525->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 46B guuid=a455ecd7-1c00-0000-b8bf-fdddcf0d0000 pid=3535->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=36ff00db-1c00-0000-b8bf-fdddd90d0000 pid=3545->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=d08020de-1c00-0000-b8bf-fddde10d0000 pid=3553->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 38B guuid=783e85e0-1c00-0000-b8bf-fddde70d0000 pid=3559->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=89ea19e3-1c00-0000-b8bf-fdddf20d0000 pid=3570->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=6c41f7e4-1c00-0000-b8bf-fdddfb0d0000 pid=3579->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=8f0942e9-1c00-0000-b8bf-fddd050e0000 pid=3589->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=e076e5ea-1c00-0000-b8bf-fddd0b0e0000 pid=3595->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 38B guuid=0c5710ec-1c00-0000-b8bf-fddd110e0000 pid=3601->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=c1ad55ee-1c00-0000-b8bf-fddd1a0e0000 pid=3610->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=e75866f0-1c00-0000-b8bf-fddd230e0000 pid=3619->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=d8beeef2-1c00-0000-b8bf-fddd2c0e0000 pid=3628->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=07af4ff5-1c00-0000-b8bf-fddd350e0000 pid=3637->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=2e4ab8f8-1c00-0000-b8bf-fddd440e0000 pid=3652->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 38B guuid=5976a004-1d00-0000-b8bf-fddd5d0e0000 pid=3677->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 38B guuid=a1293207-1d00-0000-b8bf-fddd630e0000 pid=3683->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=1087100a-1d00-0000-b8bf-fddd6a0e0000 pid=3690->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 40B guuid=97309b0e-1d00-0000-b8bf-fddd6c0e0000 pid=3692->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 32B guuid=4e20ae0e-1d00-0000-b8bf-fddd6e0e0000 pid=3694->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 38B guuid=4c1f300f-1d00-0000-b8bf-fddd710e0000 pid=3697->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 38B guuid=7eeb156e-1d00-0000-b8bf-fddd780e0000 pid=3704->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 36B guuid=6ecab072-1d00-0000-b8bf-fddd790e0000 pid=3705->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 42B guuid=c1a0fc73-1d00-0000-b8bf-fddd7c0e0000 pid=3708->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 40B guuid=67c30f74-1d00-0000-b8bf-fddd7d0e0000 pid=3709->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 42B guuid=14f14874-1d00-0000-b8bf-fddd7f0e0000 pid=3711->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 46B guuid=1f256a74-1d00-0000-b8bf-fddd810e0000 pid=3713->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 42B guuid=feee9774-1d00-0000-b8bf-fddd830e0000 pid=3715->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 46B guuid=b487bc74-1d00-0000-b8bf-fddd850e0000 pid=3717->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 42B guuid=6d260475-1d00-0000-b8bf-fddd870e0000 pid=3719->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 46B guuid=e5662675-1d00-0000-b8bf-fddd890e0000 pid=3721->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 42B guuid=074a4675-1d00-0000-b8bf-fddd8b0e0000 pid=3723->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 42B guuid=d4666875-1d00-0000-b8bf-fddd8d0e0000 pid=3725->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 42B guuid=163bc975-1d00-0000-b8bf-fddd8f0e0000 pid=3727->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=5a56ee75-1d00-0000-b8bf-fddd910e0000 pid=3729->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=583b2e76-1d00-0000-b8bf-fddd930e0000 pid=3731->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=1fefc130-2900-0000-b8bf-fddd980e0000 pid=3736->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B
Result
Threat name:
n/a
Detection:
malicious
Classification:
spre.troj
Score:
64 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1763793 Sample: i686.elf Startdate: 24/08/2025 Architecture: LINUX Score: 64 25 31.56.39.76, 37760, 37762, 37764 RASANAIR Iran (ISLAMIC Republic Of) 2->25 27 31.58.51.213, 1025, 51538 RASANAIR Iran (ISLAMIC Republic Of) 2->27 29 Malicious sample detected (through community Yara rule) 2->29 31 Multi AV Scanner detection for submitted file 2->31 9 i686.elf 2->9         started        signatures3 process4 signatures5 33 Sample reads /proc/mounts (often used for finding a writable filesystem) 9->33 12 i686.elf 9->12         started        process6 process7 14 i686.elf 12->14         started        signatures8 35 Sample tries to kill multiple processes (SIGKILL) 14->35 17 i686.elf 14->17         started        19 i686.elf 14->19         started        21 i686.elf 14->21         started        23 6 other processes 14->23 process9
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-08-24 01:22:43 UTC
File Type:
ELF32 Little (Exe)
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
credential_access discovery linux
Behaviour
Reads runtime system information
Changes its process name
Reads process memory
Enumerates running processes
Verdict:
Malicious
Tags:
trojan mirai Unix.Trojan.Mirai-9970440-0
YARA:
Linux_Trojan_Mirai_cc93863b
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Mirai_cc93863b
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf ac17a0c00de0a53dbe5fb9bb19af2c789685a20a56ccaea840b8df1d191d4012

(this sample)

  
Delivery method
Distributed via web download

Comments