MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ada24dcf9234ce1518803f62c6af0c883c7b89b8a13b9575c73bf920f91c46c1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 5 File information Comments

SHA256 hash: ada24dcf9234ce1518803f62c6af0c883c7b89b8a13b9575c73bf920f91c46c1
SHA3-384 hash: 8072b520c12f1f821324afd38a156c49280451e61108052f437b95f31c81b48c050e394ce9f01af6aa7415aed2f225fe
SHA1 hash: 5edbf6034b28b54037dd0efdf5b3028ba66f17e3
MD5 hash: a2c1b3452018bd239c246ea34eb38f3b
humanhash: virginia-cola-aspen-five
File name:plasma.x86_64
Download: download sample
Signature Mirai
File size:1'071'736 bytes
First seen:2026-01-13 15:57:44 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:j4rprIhhNg5qXIGT+j+dXHcIEH3pmUclIH7hgYhTjsgZgDwOnH04PDoayOFJHHLV:j4rpmhNg50/T+j3eoTjsNlU4P9JnL
TLSH T102357C2EB2B2B5BCE00BC03457DFC6A25531B07526213D7B36C5DA312E66DE16369B32
telfhash t196d16a744bf938b0a6dbc615f352f0b9597218e266e936b00a277d48efc0f400d76827
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=0cb0d06b-1a00-0000-bd90-200bf20a0000 pid=2802 /usr/bin/sudo guuid=e477e56e-1a00-0000-bd90-200bf60a0000 pid=2806 /tmp/sample.bin guuid=0cb0d06b-1a00-0000-bd90-200bf20a0000 pid=2802->guuid=e477e56e-1a00-0000-bd90-200bf60a0000 pid=2806 execve guuid=ce6a176f-1a00-0000-bd90-200bf80a0000 pid=2808 /tmp/sample.bin guuid=e477e56e-1a00-0000-bd90-200bf60a0000 pid=2806->guuid=ce6a176f-1a00-0000-bd90-200bf80a0000 pid=2808 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809 /tmp/sample.bin net send-data write-config guuid=ce6a176f-1a00-0000-bd90-200bf80a0000 pid=2808->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809 clone 3df62266-e530-5690-95b0-1e0d3658d806 15.204.230.147:1337 guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->3df62266-e530-5690-95b0-1e0d3658d806 send: 31B guuid=c2f43d6f-1a00-0000-bd90-200bfa0a0000 pid=2810 /usr/bin/dash guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=c2f43d6f-1a00-0000-bd90-200bfa0a0000 pid=2810 execve guuid=3f93ae6f-1a00-0000-bd90-200bfd0a0000 pid=2813 /usr/bin/dash guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=3f93ae6f-1a00-0000-bd90-200bfd0a0000 pid=2813 execve guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2838 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2838 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2839 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2839 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2840 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2840 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2841 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2841 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2842 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2842 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2843 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2843 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2844 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2844 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2845 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2845 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2846 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2846 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2847 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2847 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2848 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2848 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2849 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2849 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2850 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2850 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2851 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2851 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2852 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2852 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2853 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2853 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2854 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2854 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2855 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2855 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2856 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2856 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2857 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2857 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2858 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2858 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2859 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2859 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2860 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2860 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2861 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2861 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2862 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2862 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2863 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2863 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2864 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2864 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2865 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2865 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2866 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2866 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2867 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2867 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2868 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2868 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2869 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2869 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2870 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2870 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2871 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2871 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2872 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2872 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2873 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2873 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2874 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2874 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2875 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2875 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2876 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2876 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2877 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2877 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2878 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2878 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2879 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2879 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2880 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2880 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2881 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2881 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2882 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2882 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2883 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2883 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2884 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2884 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2885 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2885 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2886 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2886 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2887 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2887 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2888 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2888 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2889 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2889 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2890 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2890 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2891 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2891 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2892 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2892 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2893 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2893 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2894 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2894 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2895 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2895 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2896 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2896 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2897 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2897 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2898 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2898 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2899 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2899 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2900 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2900 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2901 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2901 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2902 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2902 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2903 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2903 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2904 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2904 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2905 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2905 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2906 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2906 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2907 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2907 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2908 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2908 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2909 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2909 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2910 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2910 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2912 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2912 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2913 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2913 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2914 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2914 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2915 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2915 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2916 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2916 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2917 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2917 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2918 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2918 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2919 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2919 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2920 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2920 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2921 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2921 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2922 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2922 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2923 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2923 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2924 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2924 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2925 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2925 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2926 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2926 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2927 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2927 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2928 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2928 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2929 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2929 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2930 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2930 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2931 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2931 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2932 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2932 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2933 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2933 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2934 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2934 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2935 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2935 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2937 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2937 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2938 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2938 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2939 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2939 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2940 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2940 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2941 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2941 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2942 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2942 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2943 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2943 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2944 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2944 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2945 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2945 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2946 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2946 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2947 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2947 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2948 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2948 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2949 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2949 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2950 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2950 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2951 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2951 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2952 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2952 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2953 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2953 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2954 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2954 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2955 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2955 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2956 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2956 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2957 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2957 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2959 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2959 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2960 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2960 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2961 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2961 clone guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2962 /tmp/sample.bin guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2809->guuid=7113216f-1a00-0000-bd90-200bf90a0000 pid=2962 clone guuid=3ac9766f-1a00-0000-bd90-200bfb0a0000 pid=2811 /usr/bin/chmod guuid=c2f43d6f-1a00-0000-bd90-200bfa0a0000 pid=2810->guuid=3ac9766f-1a00-0000-bd90-200bfb0a0000 pid=2811 execve guuid=f122d86f-1a00-0000-bd90-200bff0a0000 pid=2815 /usr/sbin/xtables-nft-multi guuid=3f93ae6f-1a00-0000-bd90-200bfd0a0000 pid=2813->guuid=f122d86f-1a00-0000-bd90-200bff0a0000 pid=2815 execve guuid=990a1d7a-1a00-0000-bd90-200b150b0000 pid=2837 /usr/sbin/xtables-nft-multi guuid=3f93ae6f-1a00-0000-bd90-200bfd0a0000 pid=2813->guuid=990a1d7a-1a00-0000-bd90-200b150b0000 pid=2837 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj
Score:
52 / 100
Signature
Deletes all firewall rules
Executes the "iptables" command to insert, remove and/or manipulate rules
Sample tries to persist itself using cron
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1849951 Sample: plasma.x86_64.elf Startdate: 13/01/2026 Architecture: LINUX Score: 52 36 15.204.230.147, 1337, 49204, 49206 HP-INTERNET-ASUS United States 2->36 38 54.247.62.1, 443, 57230 AMAZON-02US United States 2->38 40 daisy.ubuntu.com 2->40 9 plasma.x86_64.elf 2->9         started        11 dash rm 2->11         started        13 dash rm 2->13         started        15 python3.8 dpkg 2->15         started        process3 process4 17 plasma.x86_64.elf 9->17         started        process5 19 plasma.x86_64.elf 17->19         started        file6 34 /etc/cron.d/sys_upd, ASCII 19->34 dropped 42 Sample tries to persist itself using cron 19->42 23 plasma.x86_64.elf sh 19->23         started        25 plasma.x86_64.elf sh 19->25         started        signatures7 process8 process9 27 sh iptables 23->27         started        30 sh iptables 23->30         started        32 sh chmod 25->32         started        signatures10 44 Executes the "iptables" command to insert, remove and/or manipulate rules 27->44 46 Deletes all firewall rules 30->46
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
System Network Configuration Discovery
Changes its process name
Creates/modifies Cron job
Flushes firewall rules
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202503_elf_Mirai
Author:abuse.ch
Description:Detects Mirai 'TSource' ELF files
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:malwareelf55503
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf ada24dcf9234ce1518803f62c6af0c883c7b89b8a13b9575c73bf920f91c46c1

(this sample)

  
Delivery method
Distributed via web download

Comments