MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b56eed1db7691e327f4904251b3c0c1d518ae9dd2f67edbe320476fd43484091. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 11


Intelligence 11 IOCs YARA 15 File information Comments

SHA256 hash: b56eed1db7691e327f4904251b3c0c1d518ae9dd2f67edbe320476fd43484091
SHA3-384 hash: 04943db7f53ac7fe3a9ceed841bca7406dd5fb74ec1a6aa81d6065284081cd9d651727f44d5b5bbf2fb449eb3fded1c3
SHA1 hash: 2685d68f1cf44e28156f532851586b78b054a1cd
MD5 hash: 76534797de869346354b2b0039505ddb
humanhash: tango-carolina-white-island
File name:sys64.x86_64
Download: download sample
Signature Mirai
File size:165'128 bytes
First seen:2026-01-26 06:41:33 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:51wf76PYX8N1M4BNlcS+ADtFHu7aOXrVy+7EdFdtH8ur0b:kT6gS3txHemR0b
TLSH T1E5F3381374C080FDC8D6C1749FBEE126DA32F02E2134B65F2B946E262E4EE311E5E695
telfhash t1ea61cb703d993a9861d7f326f30ed9a9b97209500de1b4e19d7738e6cf077844e62093
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
gafgyt mirai obfuscated
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
11
Number of processes launched:
2
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Process Renaming
Botnet C2s
TCP botnet C2(s):
type:Mirai 45.9.2.141:8033
UDP botnet C2(s):
not identified
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=be642d86-1500-0000-b1a0-f006c20b0000 pid=3010 /usr/bin/sudo guuid=77108488-1500-0000-b1a0-f006c80b0000 pid=3016 /tmp/sample.bin guuid=be642d86-1500-0000-b1a0-f006c20b0000 pid=3010->guuid=77108488-1500-0000-b1a0-f006c80b0000 pid=3016 execve guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017 /tmp/sample.bin dns net send-data write-file zombie guuid=77108488-1500-0000-b1a0-f006c80b0000 pid=3016->guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8cfbd4df-b5e2-5a19-bbaa-8077b09b55fd 223.5.5.5:53 guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->8cfbd4df-b5e2-5a19-bbaa-8077b09b55fd send: 39B bcea957d-6a39-5f2c-a5d4-a9196ec2f4e0 29t305j3uk4962rn.aliyunddos1008.com:80 guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->bcea957d-6a39-5f2c-a5d4-a9196ec2f4e0 send: 322B 1cb86108-37e5-58a7-89b9-353958c965a1 45.9.2.141:8033 guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->1cb86108-37e5-58a7-89b9-353958c965a1 send: 7B 66a460ca-d373-5bf3-9826-4746b0522c79 223.26.52.213:8033 guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->66a460ca-d373-5bf3-9826-4746b0522c79 con 54206152-f87f-522b-8766-11da8e91a2cc 204.76.203.49:8033 guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->54206152-f87f-522b-8766-11da8e91a2cc con guuid=a56abc88-1500-0000-b1a0-f006ca0b0000 pid=3018 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=a56abc88-1500-0000-b1a0-f006ca0b0000 pid=3018 clone guuid=aa11b98e-1500-0000-b1a0-f006d90b0000 pid=3033 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=aa11b98e-1500-0000-b1a0-f006d90b0000 pid=3033 clone guuid=268ac594-1500-0000-b1a0-f006e50b0000 pid=3045 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=268ac594-1500-0000-b1a0-f006e50b0000 pid=3045 clone guuid=214fd29a-1500-0000-b1a0-f006f20b0000 pid=3058 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=214fd29a-1500-0000-b1a0-f006f20b0000 pid=3058 clone guuid=d760d6a0-1500-0000-b1a0-f006010c0000 pid=3073 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=d760d6a0-1500-0000-b1a0-f006010c0000 pid=3073 clone guuid=3e78d7a6-1500-0000-b1a0-f006130c0000 pid=3091 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=3e78d7a6-1500-0000-b1a0-f006130c0000 pid=3091 clone guuid=1429ddac-1500-0000-b1a0-f0061e0c0000 pid=3102 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=1429ddac-1500-0000-b1a0-f0061e0c0000 pid=3102 clone guuid=fce3e1b2-1500-0000-b1a0-f0062b0c0000 pid=3115 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=fce3e1b2-1500-0000-b1a0-f0062b0c0000 pid=3115 clone guuid=a367ebb8-1500-0000-b1a0-f006370c0000 pid=3127 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=a367ebb8-1500-0000-b1a0-f006370c0000 pid=3127 clone guuid=29c8f0be-1500-0000-b1a0-f006430c0000 pid=3139 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=29c8f0be-1500-0000-b1a0-f006430c0000 pid=3139 clone guuid=28baf6c4-1500-0000-b1a0-f0064c0c0000 pid=3148 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=28baf6c4-1500-0000-b1a0-f0064c0c0000 pid=3148 clone guuid=de0705cb-1500-0000-b1a0-f006530c0000 pid=3155 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=de0705cb-1500-0000-b1a0-f006530c0000 pid=3155 clone guuid=6a2d0ed1-1500-0000-b1a0-f0065b0c0000 pid=3163 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=6a2d0ed1-1500-0000-b1a0-f0065b0c0000 pid=3163 clone guuid=ea5f13d7-1500-0000-b1a0-f006650c0000 pid=3173 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=ea5f13d7-1500-0000-b1a0-f006650c0000 pid=3173 clone guuid=d7b819dd-1500-0000-b1a0-f0066a0c0000 pid=3178 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=d7b819dd-1500-0000-b1a0-f0066a0c0000 pid=3178 clone guuid=621820e3-1500-0000-b1a0-f0066b0c0000 pid=3179 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=621820e3-1500-0000-b1a0-f0066b0c0000 pid=3179 clone guuid=d79d22e9-1500-0000-b1a0-f0066c0c0000 pid=3180 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=d79d22e9-1500-0000-b1a0-f0066c0c0000 pid=3180 clone guuid=ebb328ef-1500-0000-b1a0-f006760c0000 pid=3190 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=ebb328ef-1500-0000-b1a0-f006760c0000 pid=3190 clone guuid=c66130f5-1500-0000-b1a0-f0067f0c0000 pid=3199 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=c66130f5-1500-0000-b1a0-f0067f0c0000 pid=3199 clone guuid=889f39fb-1500-0000-b1a0-f006880c0000 pid=3208 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=889f39fb-1500-0000-b1a0-f006880c0000 pid=3208 clone guuid=9dc64101-1600-0000-b1a0-f006920c0000 pid=3218 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=9dc64101-1600-0000-b1a0-f006920c0000 pid=3218 clone guuid=85634807-1600-0000-b1a0-f006950c0000 pid=3221 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=85634807-1600-0000-b1a0-f006950c0000 pid=3221 clone guuid=bdd44b0d-1600-0000-b1a0-f006960c0000 pid=3222 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=bdd44b0d-1600-0000-b1a0-f006960c0000 pid=3222 clone guuid=e0274e13-1600-0000-b1a0-f006980c0000 pid=3224 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=e0274e13-1600-0000-b1a0-f006980c0000 pid=3224 clone guuid=b4a14e19-1600-0000-b1a0-f006a30c0000 pid=3235 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=b4a14e19-1600-0000-b1a0-f006a30c0000 pid=3235 clone guuid=b9f6511f-1600-0000-b1a0-f006ae0c0000 pid=3246 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=b9f6511f-1600-0000-b1a0-f006ae0c0000 pid=3246 clone guuid=31195725-1600-0000-b1a0-f006b00c0000 pid=3248 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=31195725-1600-0000-b1a0-f006b00c0000 pid=3248 clone guuid=2493612b-1600-0000-b1a0-f006b80c0000 pid=3256 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=2493612b-1600-0000-b1a0-f006b80c0000 pid=3256 clone guuid=c7e56431-1600-0000-b1a0-f006c20c0000 pid=3266 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=c7e56431-1600-0000-b1a0-f006c20c0000 pid=3266 clone guuid=6ecb7337-1600-0000-b1a0-f006c70c0000 pid=3271 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=6ecb7337-1600-0000-b1a0-f006c70c0000 pid=3271 clone guuid=22f3803d-1600-0000-b1a0-f006d10c0000 pid=3281 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=22f3803d-1600-0000-b1a0-f006d10c0000 pid=3281 clone guuid=a8988343-1600-0000-b1a0-f006dd0c0000 pid=3293 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=a8988343-1600-0000-b1a0-f006dd0c0000 pid=3293 clone guuid=af758949-1600-0000-b1a0-f006e50c0000 pid=3301 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=af758949-1600-0000-b1a0-f006e50c0000 pid=3301 clone guuid=7bce944f-1600-0000-b1a0-f006f10c0000 pid=3313 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=7bce944f-1600-0000-b1a0-f006f10c0000 pid=3313 clone guuid=34449e55-1600-0000-b1a0-f006fa0c0000 pid=3322 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=34449e55-1600-0000-b1a0-f006fa0c0000 pid=3322 clone guuid=350dab55-1600-0000-b1a0-f006fb0c0000 pid=3323 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=350dab55-1600-0000-b1a0-f006fb0c0000 pid=3323 clone guuid=c4c5ab5b-1600-0000-b1a0-f0060f0d0000 pid=3343 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=c4c5ab5b-1600-0000-b1a0-f0060f0d0000 pid=3343 clone guuid=f5f5b261-1600-0000-b1a0-f006160d0000 pid=3350 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=f5f5b261-1600-0000-b1a0-f006160d0000 pid=3350 clone guuid=9ed0ba67-1600-0000-b1a0-f006180d0000 pid=3352 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=9ed0ba67-1600-0000-b1a0-f006180d0000 pid=3352 clone guuid=616fbb6d-1600-0000-b1a0-f006240d0000 pid=3364 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=616fbb6d-1600-0000-b1a0-f006240d0000 pid=3364 clone guuid=e0c2c073-1600-0000-b1a0-f0062d0d0000 pid=3373 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=e0c2c073-1600-0000-b1a0-f0062d0d0000 pid=3373 clone guuid=0b02cc79-1600-0000-b1a0-f006360d0000 pid=3382 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=0b02cc79-1600-0000-b1a0-f006360d0000 pid=3382 clone guuid=c458d67f-1600-0000-b1a0-f006400d0000 pid=3392 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=c458d67f-1600-0000-b1a0-f006400d0000 pid=3392 clone guuid=9856e485-1600-0000-b1a0-f006470d0000 pid=3399 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=9856e485-1600-0000-b1a0-f006470d0000 pid=3399 clone guuid=247ff08b-1600-0000-b1a0-f0064f0d0000 pid=3407 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=247ff08b-1600-0000-b1a0-f0064f0d0000 pid=3407 clone guuid=e032f791-1600-0000-b1a0-f0065d0d0000 pid=3421 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=e032f791-1600-0000-b1a0-f0065d0d0000 pid=3421 clone guuid=bea4f797-1600-0000-b1a0-f006730d0000 pid=3443 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=bea4f797-1600-0000-b1a0-f006730d0000 pid=3443 clone guuid=3864f99d-1600-0000-b1a0-f006860d0000 pid=3462 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=3864f99d-1600-0000-b1a0-f006860d0000 pid=3462 clone guuid=3a4900a4-1600-0000-b1a0-f006920d0000 pid=3474 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=3a4900a4-1600-0000-b1a0-f006920d0000 pid=3474 clone guuid=564106aa-1600-0000-b1a0-f0069c0d0000 pid=3484 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=564106aa-1600-0000-b1a0-f0069c0d0000 pid=3484 clone guuid=efec0eb0-1600-0000-b1a0-f006a80d0000 pid=3496 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=efec0eb0-1600-0000-b1a0-f006a80d0000 pid=3496 clone guuid=f2961db6-1600-0000-b1a0-f006b30d0000 pid=3507 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=f2961db6-1600-0000-b1a0-f006b30d0000 pid=3507 clone guuid=849727bc-1600-0000-b1a0-f006bf0d0000 pid=3519 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=849727bc-1600-0000-b1a0-f006bf0d0000 pid=3519 clone guuid=441830c2-1600-0000-b1a0-f006c90d0000 pid=3529 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=441830c2-1600-0000-b1a0-f006c90d0000 pid=3529 clone guuid=55b740c8-1600-0000-b1a0-f006cf0d0000 pid=3535 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=55b740c8-1600-0000-b1a0-f006cf0d0000 pid=3535 clone guuid=ad8941ce-1600-0000-b1a0-f006d90d0000 pid=3545 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=ad8941ce-1600-0000-b1a0-f006d90d0000 pid=3545 clone guuid=c10047d4-1600-0000-b1a0-f006e00d0000 pid=3552 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=c10047d4-1600-0000-b1a0-f006e00d0000 pid=3552 clone guuid=ab204dda-1600-0000-b1a0-f006e20d0000 pid=3554 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=ab204dda-1600-0000-b1a0-f006e20d0000 pid=3554 clone guuid=bb9b56e0-1600-0000-b1a0-f006ee0d0000 pid=3566 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=bb9b56e0-1600-0000-b1a0-f006ee0d0000 pid=3566 clone guuid=da125fe6-1600-0000-b1a0-f006f40d0000 pid=3572 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=da125fe6-1600-0000-b1a0-f006f40d0000 pid=3572 clone guuid=55526aec-1600-0000-b1a0-f006fc0d0000 pid=3580 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=55526aec-1600-0000-b1a0-f006fc0d0000 pid=3580 clone guuid=41ab7bf2-1600-0000-b1a0-f006070e0000 pid=3591 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=41ab7bf2-1600-0000-b1a0-f006070e0000 pid=3591 clone guuid=958482f8-1600-0000-b1a0-f006130e0000 pid=3603 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=958482f8-1600-0000-b1a0-f006130e0000 pid=3603 clone guuid=600295fe-1600-0000-b1a0-f0061e0e0000 pid=3614 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=600295fe-1600-0000-b1a0-f0061e0e0000 pid=3614 clone guuid=0e399604-1700-0000-b1a0-f006270e0000 pid=3623 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=0e399604-1700-0000-b1a0-f006270e0000 pid=3623 clone guuid=642a990a-1700-0000-b1a0-f006300e0000 pid=3632 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=642a990a-1700-0000-b1a0-f006300e0000 pid=3632 clone guuid=1d7f9910-1700-0000-b1a0-f0063e0e0000 pid=3646 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=1d7f9910-1700-0000-b1a0-f0063e0e0000 pid=3646 clone guuid=94309b16-1700-0000-b1a0-f006490e0000 pid=3657 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=94309b16-1700-0000-b1a0-f006490e0000 pid=3657 clone guuid=fa409d1c-1700-0000-b1a0-f0065e0e0000 pid=3678 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=fa409d1c-1700-0000-b1a0-f0065e0e0000 pid=3678 clone guuid=e445a622-1700-0000-b1a0-f006700e0000 pid=3696 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=e445a622-1700-0000-b1a0-f006700e0000 pid=3696 clone guuid=3a57a928-1700-0000-b1a0-f0067c0e0000 pid=3708 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=3a57a928-1700-0000-b1a0-f0067c0e0000 pid=3708 clone guuid=e7d2b02e-1700-0000-b1a0-f006880e0000 pid=3720 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=e7d2b02e-1700-0000-b1a0-f006880e0000 pid=3720 clone guuid=5157b634-1700-0000-b1a0-f006960e0000 pid=3734 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=5157b634-1700-0000-b1a0-f006960e0000 pid=3734 clone guuid=0e28bb3a-1700-0000-b1a0-f006a20e0000 pid=3746 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=0e28bb3a-1700-0000-b1a0-f006a20e0000 pid=3746 clone guuid=a51ec040-1700-0000-b1a0-f006b20e0000 pid=3762 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=a51ec040-1700-0000-b1a0-f006b20e0000 pid=3762 clone guuid=83b4c046-1700-0000-b1a0-f006c90e0000 pid=3785 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=83b4c046-1700-0000-b1a0-f006c90e0000 pid=3785 clone guuid=ce15be4c-1700-0000-b1a0-f006e40e0000 pid=3812 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=ce15be4c-1700-0000-b1a0-f006e40e0000 pid=3812 clone guuid=f834c052-1700-0000-b1a0-f006f40e0000 pid=3828 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=f834c052-1700-0000-b1a0-f006f40e0000 pid=3828 clone guuid=e0e8c758-1700-0000-b1a0-f006090f0000 pid=3849 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=e0e8c758-1700-0000-b1a0-f006090f0000 pid=3849 clone guuid=f632cc5e-1700-0000-b1a0-f0061e0f0000 pid=3870 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=f632cc5e-1700-0000-b1a0-f0061e0f0000 pid=3870 clone guuid=0034cf64-1700-0000-b1a0-f006300f0000 pid=3888 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=0034cf64-1700-0000-b1a0-f006300f0000 pid=3888 clone guuid=ac9dd86a-1700-0000-b1a0-f0063e0f0000 pid=3902 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=ac9dd86a-1700-0000-b1a0-f0063e0f0000 pid=3902 clone guuid=9846db70-1700-0000-b1a0-f0064d0f0000 pid=3917 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=9846db70-1700-0000-b1a0-f0064d0f0000 pid=3917 clone guuid=5d45de76-1700-0000-b1a0-f0065c0f0000 pid=3932 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=5d45de76-1700-0000-b1a0-f0065c0f0000 pid=3932 clone guuid=3f49e47c-1700-0000-b1a0-f0066c0f0000 pid=3948 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=3f49e47c-1700-0000-b1a0-f0066c0f0000 pid=3948 clone guuid=8b1be682-1700-0000-b1a0-f006830f0000 pid=3971 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=8b1be682-1700-0000-b1a0-f006830f0000 pid=3971 clone guuid=0386e688-1700-0000-b1a0-f0069e0f0000 pid=3998 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=0386e688-1700-0000-b1a0-f0069e0f0000 pid=3998 clone guuid=a252e98e-1700-0000-b1a0-f006b10f0000 pid=4017 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=a252e98e-1700-0000-b1a0-f006b10f0000 pid=4017 clone guuid=c226ef94-1700-0000-b1a0-f006c80f0000 pid=4040 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=c226ef94-1700-0000-b1a0-f006c80f0000 pid=4040 clone guuid=69e8fa9a-1700-0000-b1a0-f006cb0f0000 pid=4043 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=69e8fa9a-1700-0000-b1a0-f006cb0f0000 pid=4043 clone guuid=93abfca0-1700-0000-b1a0-f006d90f0000 pid=4057 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=93abfca0-1700-0000-b1a0-f006d90f0000 pid=4057 clone guuid=b69302a7-1700-0000-b1a0-f006eb0f0000 pid=4075 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=b69302a7-1700-0000-b1a0-f006eb0f0000 pid=4075 clone guuid=6c1b06ad-1700-0000-b1a0-f006f90f0000 pid=4089 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=6c1b06ad-1700-0000-b1a0-f006f90f0000 pid=4089 clone guuid=62a706b3-1700-0000-b1a0-f00607100000 pid=4103 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=62a706b3-1700-0000-b1a0-f00607100000 pid=4103 clone guuid=6eea0db9-1700-0000-b1a0-f00616100000 pid=4118 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=6eea0db9-1700-0000-b1a0-f00616100000 pid=4118 clone guuid=f3ef11bf-1700-0000-b1a0-f00629100000 pid=4137 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=f3ef11bf-1700-0000-b1a0-f00629100000 pid=4137 clone guuid=d6d012c5-1700-0000-b1a0-f00639100000 pid=4153 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=d6d012c5-1700-0000-b1a0-f00639100000 pid=4153 clone guuid=3fd315cb-1700-0000-b1a0-f0064b100000 pid=4171 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=3fd315cb-1700-0000-b1a0-f0064b100000 pid=4171 clone guuid=0a281ed1-1700-0000-b1a0-f0065b100000 pid=4187 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=0a281ed1-1700-0000-b1a0-f0065b100000 pid=4187 clone guuid=a6be1fd7-1700-0000-b1a0-f0066f100000 pid=4207 /tmp/sample.bin guuid=d81bae88-1500-0000-b1a0-f006c90b0000 pid=3017->guuid=a6be1fd7-1700-0000-b1a0-f0066f100000 pid=4207 clone
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj
Score:
60 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample reads /proc/mounts (often used for finding a writable filesystem)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1857441 Sample: sys64.x86_64.elf Startdate: 26/01/2026 Architecture: LINUX Score: 60 25 trx.mytokenpocket.vip 2->25 27 204.76.203.49, 56822, 8033 UNASSIGNED Reserved 2->27 29 7 other IPs or domains 2->29 31 Malicious sample detected (through community Yara rule) 2->31 33 Multi AV Scanner detection for submitted file 2->33 8 sys64.x86_64.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 sys64.x86_64.elf 8->14         started        signatures6 35 Sample reads /proc/mounts (often used for finding a writable filesystem) 14->35 17 sys64.x86_64.elf 14->17         started        19 sys64.x86_64.elf 14->19         started        21 sys64.x86_64.elf 14->21         started        23 97 other processes 14->23 process7
Threat name:
Linux.Trojan.Gafgyt
Status:
Suspicious
First seen:
2026-01-26 01:38:29 UTC
File Type:
ELF64 Little (Exe)
AV detection:
11 of 36 (30.56%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Changes its process name
Unexpected DNS network traffic destination
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_1cb033f3
Author:Elastic Security
Rule name:SUSP_XORed_Mozilla_Oct19
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf b56eed1db7691e327f4904251b3c0c1d518ae9dd2f67edbe320476fd43484091

(this sample)

  
Delivery method
Distributed via web download

Comments