MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3ad009ffdbaacb38af7317b12aa955a371c8140f4b5748315da3990206dc9ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: b3ad009ffdbaacb38af7317b12aa955a371c8140f4b5748315da3990206dc9ba
SHA3-384 hash: c4b8676d3f48237ec95cbdc9d989f267e08f49cc916b1f5ffd247041a0c8a57e9e4a0ad5cfa0ed8edb6197dda9d10fd9
SHA1 hash: 46a6b5548c00e329f9a3ce9c70bb952f0a9c6320
MD5 hash: de4543a66883832b8dfedf5413fce429
humanhash: tango-equal-helium-hamper
File name:miori.m68k
Download: download sample
Signature Mirai
File size:37'008 bytes
First seen:2025-01-07 13:26:41 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:8lGY2AuWck/QCSlDbec12v4WPU1uOR8avLT3sJKQWGqTVQ0jx:8l3AW5vkveS2v4WPUUOR8avHsJKQPqTZ
TLSH T1C6F228E6B401ED7CFC4FE77AC11B0909F132764495931A362363BDA7AC361984E2BE46
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
141
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
android anti-debug masquerade mirai
Result
Threat name:
n/a
Detection:
malicious
Classification:
spre
Score:
52 / 100
Signature
Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1585331 Sample: miori.m68k.elf Startdate: 07/01/2025 Architecture: LINUX Score: 52 25 81.16.202.185 ZT-HU Hungary 2->25 27 204.244.177.86 WESTEL-1CA Canada 2->27 29 98 other IPs or domains 2->29 33 Multi AV Scanner detection for submitted file 2->33 8 miori.m68k.elf 2->8         started        10 gnome-session-binary sh gsd-print-notifications 2->10         started        12 xfce4-session rm 2->12         started        signatures3 process4 process5 14 miori.m68k.elf 8->14         started        16 gsd-print-notifications 10->16         started        process6 18 miori.m68k.elf 14->18         started        21 miori.m68k.elf 14->21         started        23 gsd-print-notifications gsd-printer 16->23         started        signatures7 31 Sample tries to kill multiple processes (SIGKILL) 18->31
Threat name:
Linux.Trojan.Mirai
Status:
Malicious
First seen:
2025-01-07 09:06:12 UTC
File Type:
ELF32 Big (Exe)
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-6981989-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf b3ad009ffdbaacb38af7317b12aa955a371c8140f4b5748315da3990206dc9ba

(this sample)

  
Delivery method
Distributed via web download

Comments