MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b5f0994117bf18e836aa1a1281171e823e36ce2480c107291a6b51255b6b324a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 13


Intelligence 13 IOCs YARA 11 File information Comments

SHA256 hash: b5f0994117bf18e836aa1a1281171e823e36ce2480c107291a6b51255b6b324a
SHA3-384 hash: 0bb6458bc075268a263dba41e801ddf3ebcee606ad339954e5d48da45fc6dfc35d9ff835bc16ec4b4def6591ffe786d6
SHA1 hash: 6a0fe09926a2db3cde7097ac799fbc46da9848c5
MD5 hash: 5c024a2738fedb3c3900fffe3302c11a
humanhash: sierra-north-mississippi-fourteen
File name:x86_64.kok
Download: download sample
Signature Mirai
File size:194'352 bytes
First seen:2026-01-09 07:22:19 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:rugGCYxLmP68MWRw38F/gOJKtKI1c0Vk6zwFgHrsRV:rBGC0LaCWu38FjMPdkuVAf
TLSH T111146B06F68190FFE89AC33852EEA632D9B2782D1235769D67C5FF153C48E20363E645
telfhash t1e94178741dd1341852e7c352b21fe67dae72081196ed36e8af27e5e9ed437c40ca6822
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Deleting a recently created file
Removes directories from a subdirectory of a temporary directory
Sets a written file as executable
Creates directories in a temporary directory
Creating a file in the %temp% directory
Creates directories in a subdirectory of a temporary directory
Opens a port
Creating a file in the %temp% subdirectories
Launching a process
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
base64 masquerade mirai
Result
Gathering data
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2026-01-09T04:29:00Z UTC
Last seen:
2026-01-09T04:29:00Z UTC
Hits:
~10
Detections:
HEUR:Backdoor.Linux.Mirai.b HEUR:Backdoor.Linux.Gafgyt.ij HEUR:Backdoor.Linux.Gafgyt.gu
Status:
terminated
Behavior Graph:
%3 guuid=612f2631-1900-0000-6bb3-0b8835130000 pid=4917 /usr/bin/sudo guuid=655a3b33-1900-0000-6bb3-0b883e130000 pid=4926 /tmp/sample.bin guuid=612f2631-1900-0000-6bb3-0b8835130000 pid=4917->guuid=655a3b33-1900-0000-6bb3-0b883e130000 pid=4926 execve guuid=cf905a33-1900-0000-6bb3-0b883f130000 pid=4927 /usr/bin/dash guuid=655a3b33-1900-0000-6bb3-0b883e130000 pid=4926->guuid=cf905a33-1900-0000-6bb3-0b883f130000 pid=4927 execve guuid=5fb9cd33-1900-0000-6bb3-0b8843130000 pid=4931 /usr/bin/dash guuid=655a3b33-1900-0000-6bb3-0b883e130000 pid=4926->guuid=5fb9cd33-1900-0000-6bb3-0b8843130000 pid=4931 execve guuid=85b43a34-1900-0000-6bb3-0b8847130000 pid=4935 /usr/bin/dash guuid=655a3b33-1900-0000-6bb3-0b883e130000 pid=4926->guuid=85b43a34-1900-0000-6bb3-0b8847130000 pid=4935 execve guuid=43f2b034-1900-0000-6bb3-0b884a130000 pid=4938 /usr/bin/dash guuid=655a3b33-1900-0000-6bb3-0b883e130000 pid=4926->guuid=43f2b034-1900-0000-6bb3-0b884a130000 pid=4938 execve guuid=9df61a35-1900-0000-6bb3-0b884e130000 pid=4942 /usr/bin/dash guuid=655a3b33-1900-0000-6bb3-0b883e130000 pid=4926->guuid=9df61a35-1900-0000-6bb3-0b884e130000 pid=4942 execve guuid=1a186d35-1900-0000-6bb3-0b8851130000 pid=4945 /usr/bin/dash guuid=655a3b33-1900-0000-6bb3-0b883e130000 pid=4926->guuid=1a186d35-1900-0000-6bb3-0b8851130000 pid=4945 execve guuid=2c718333-1900-0000-6bb3-0b8841130000 pid=4929 /usr/bin/which.debianutils guuid=cf905a33-1900-0000-6bb3-0b883f130000 pid=4927->guuid=2c718333-1900-0000-6bb3-0b8841130000 pid=4929 execve guuid=9b53fd33-1900-0000-6bb3-0b8845130000 pid=4933 /usr/bin/which.debianutils guuid=5fb9cd33-1900-0000-6bb3-0b8843130000 pid=4931->guuid=9b53fd33-1900-0000-6bb3-0b8845130000 pid=4933 execve guuid=43966734-1900-0000-6bb3-0b8849130000 pid=4937 /usr/bin/which.debianutils guuid=85b43a34-1900-0000-6bb3-0b8847130000 pid=4935->guuid=43966734-1900-0000-6bb3-0b8849130000 pid=4937 execve guuid=9dfad734-1900-0000-6bb3-0b884c130000 pid=4940 /usr/bin/which.debianutils guuid=43f2b034-1900-0000-6bb3-0b884a130000 pid=4938->guuid=9dfad734-1900-0000-6bb3-0b884c130000 pid=4940 execve guuid=c1553e35-1900-0000-6bb3-0b8850130000 pid=4944 /usr/bin/which.debianutils guuid=9df61a35-1900-0000-6bb3-0b884e130000 pid=4942->guuid=c1553e35-1900-0000-6bb3-0b8850130000 pid=4944 execve guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947 /usr/bin/apt-get delete-file write-file guuid=1a186d35-1900-0000-6bb3-0b8851130000 pid=4945->guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947 execve guuid=cd0df636-1900-0000-6bb3-0b885b130000 pid=4955 /usr/bin/dpkg guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947->guuid=cd0df636-1900-0000-6bb3-0b885b130000 pid=4955 execve guuid=5cddb937-1900-0000-6bb3-0b885f130000 pid=4959 /usr/lib/apt/methods/mirror guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947->guuid=5cddb937-1900-0000-6bb3-0b885f130000 pid=4959 execve guuid=b3f42139-1900-0000-6bb3-0b8866130000 pid=4966 /usr/lib/apt/methods/mirror guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947->guuid=b3f42139-1900-0000-6bb3-0b8866130000 pid=4966 execve guuid=0cf51b3a-1900-0000-6bb3-0b886b130000 pid=4971 /usr/lib/apt/methods/file guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947->guuid=0cf51b3a-1900-0000-6bb3-0b886b130000 pid=4971 execve guuid=0a4dae3b-1900-0000-6bb3-0b8873130000 pid=4979 /usr/lib/apt/methods/file delete-file guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947->guuid=0a4dae3b-1900-0000-6bb3-0b8873130000 pid=4979 execve guuid=e9b71f3d-1900-0000-6bb3-0b8879130000 pid=4985 /usr/lib/apt/methods/http guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947->guuid=e9b71f3d-1900-0000-6bb3-0b8879130000 pid=4985 execve guuid=dd43c83f-1900-0000-6bb3-0b8885130000 pid=4997 /usr/lib/apt/methods/http dns net send-data write-file guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947->guuid=dd43c83f-1900-0000-6bb3-0b8885130000 pid=4997 execve guuid=b393ab57-1900-0000-6bb3-0b88d8130000 pid=5080 /usr/lib/apt/methods/gpgv guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947->guuid=b393ab57-1900-0000-6bb3-0b88d8130000 pid=5080 execve guuid=264ef658-1900-0000-6bb3-0b88de130000 pid=5086 /usr/lib/apt/methods/gpgv guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947->guuid=264ef658-1900-0000-6bb3-0b88de130000 pid=5086 execve guuid=b959e9e6-1e00-0000-6bb3-0b8808150000 pid=5384 /usr/lib/apt/methods/store guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947->guuid=b959e9e6-1e00-0000-6bb3-0b8808150000 pid=5384 execve guuid=b06abbe8-1e00-0000-6bb3-0b8809150000 pid=5385 /usr/lib/apt/methods/store write-file guuid=a1fd9335-1900-0000-6bb3-0b8853130000 pid=4947->guuid=b06abbe8-1e00-0000-6bb3-0b8809150000 pid=5385 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=dd43c83f-1900-0000-6bb3-0b8885130000 pid=4997->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=dd43c83f-1900-0000-6bb3-0b8885130000 pid=4997->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf send: 5772B guuid=546e6b5a-1900-0000-6bb3-0b88e4130000 pid=5092 /usr/lib/apt/methods/gpgv delete-file write-file guuid=264ef658-1900-0000-6bb3-0b88de130000 pid=5086->guuid=546e6b5a-1900-0000-6bb3-0b88e4130000 pid=5092 clone guuid=efda5274-1900-0000-6bb3-0b8827140000 pid=5159 /usr/lib/apt/methods/gpgv delete-file write-file guuid=264ef658-1900-0000-6bb3-0b88de130000 pid=5086->guuid=efda5274-1900-0000-6bb3-0b8827140000 pid=5159 clone guuid=c26aee81-1900-0000-6bb3-0b884b140000 pid=5195 /usr/lib/apt/methods/gpgv delete-file write-file guuid=264ef658-1900-0000-6bb3-0b88de130000 pid=5086->guuid=c26aee81-1900-0000-6bb3-0b884b140000 pid=5195 clone guuid=ba88c98c-1900-0000-6bb3-0b8876140000 pid=5238 /usr/lib/apt/methods/gpgv delete-file write-file guuid=264ef658-1900-0000-6bb3-0b88de130000 pid=5086->guuid=ba88c98c-1900-0000-6bb3-0b8876140000 pid=5238 clone guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104 /usr/bin/apt-key write-file guuid=546e6b5a-1900-0000-6bb3-0b88e4130000 pid=5092->guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104 execve guuid=65eb0c5d-1900-0000-6bb3-0b88f1130000 pid=5105 /usr/bin/dash guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=65eb0c5d-1900-0000-6bb3-0b88f1130000 pid=5105 clone guuid=6773255d-1900-0000-6bb3-0b88f2130000 pid=5106 /usr/bin/apt-config guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=6773255d-1900-0000-6bb3-0b88f2130000 pid=5106 execve guuid=e633a463-1900-0000-6bb3-0b88fd130000 pid=5117 /usr/bin/apt-config guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=e633a463-1900-0000-6bb3-0b88fd130000 pid=5117 execve guuid=e0648865-1900-0000-6bb3-0b8805140000 pid=5125 /usr/bin/apt-config guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=e0648865-1900-0000-6bb3-0b8805140000 pid=5125 execve guuid=889b0167-1900-0000-6bb3-0b880c140000 pid=5132 /usr/bin/apt-config guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=889b0167-1900-0000-6bb3-0b880c140000 pid=5132 execve guuid=43fc5b68-1900-0000-6bb3-0b8812140000 pid=5138 /usr/bin/dash guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=43fc5b68-1900-0000-6bb3-0b8812140000 pid=5138 clone guuid=725d8468-1900-0000-6bb3-0b8813140000 pid=5139 /usr/bin/apt-config guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=725d8468-1900-0000-6bb3-0b8813140000 pid=5139 execve guuid=4422dc6d-1900-0000-6bb3-0b881b140000 pid=5147 /usr/bin/mktemp guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=4422dc6d-1900-0000-6bb3-0b881b140000 pid=5147 execve guuid=8fa3396e-1900-0000-6bb3-0b881c140000 pid=5148 /usr/bin/chmod guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=8fa3396e-1900-0000-6bb3-0b881c140000 pid=5148 execve guuid=6287676e-1900-0000-6bb3-0b881d140000 pid=5149 /usr/bin/dash guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=6287676e-1900-0000-6bb3-0b881d140000 pid=5149 clone guuid=93d4776e-1900-0000-6bb3-0b881e140000 pid=5150 /usr/bin/dash guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=93d4776e-1900-0000-6bb3-0b881e140000 pid=5150 clone guuid=fe45dd6e-1900-0000-6bb3-0b8821140000 pid=5153 /usr/bin/dash guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=fe45dd6e-1900-0000-6bb3-0b8821140000 pid=5153 clone guuid=2e963b6f-1900-0000-6bb3-0b8824140000 pid=5156 /usr/bin/dash guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=2e963b6f-1900-0000-6bb3-0b8824140000 pid=5156 clone guuid=c569496f-1900-0000-6bb3-0b8825140000 pid=5157 /usr/bin/gpgv guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=c569496f-1900-0000-6bb3-0b8825140000 pid=5157 execve guuid=802e6971-1900-0000-6bb3-0b8826140000 pid=5158 /usr/bin/rm delete-file guuid=56e8945c-1900-0000-6bb3-0b88f0130000 pid=5104->guuid=802e6971-1900-0000-6bb3-0b8826140000 pid=5158 execve guuid=9ad7a65e-1900-0000-6bb3-0b88f4130000 pid=5108 /usr/bin/dpkg guuid=6773255d-1900-0000-6bb3-0b88f2130000 pid=5106->guuid=9ad7a65e-1900-0000-6bb3-0b88f4130000 pid=5108 execve guuid=d7f5f164-1900-0000-6bb3-0b8801140000 pid=5121 /usr/bin/dpkg guuid=e633a463-1900-0000-6bb3-0b88fd130000 pid=5117->guuid=d7f5f164-1900-0000-6bb3-0b8801140000 pid=5121 execve guuid=a21e6a66-1900-0000-6bb3-0b8809140000 pid=5129 /usr/bin/dpkg guuid=e0648865-1900-0000-6bb3-0b8805140000 pid=5125->guuid=a21e6a66-1900-0000-6bb3-0b8809140000 pid=5129 execve guuid=cc89e067-1900-0000-6bb3-0b8810140000 pid=5136 /usr/bin/dpkg guuid=889b0167-1900-0000-6bb3-0b880c140000 pid=5132->guuid=cc89e067-1900-0000-6bb3-0b8810140000 pid=5136 execve guuid=97607469-1900-0000-6bb3-0b8817140000 pid=5143 /usr/bin/dpkg guuid=725d8468-1900-0000-6bb3-0b8813140000 pid=5139->guuid=97607469-1900-0000-6bb3-0b8817140000 pid=5143 execve guuid=a5e8836e-1900-0000-6bb3-0b881f140000 pid=5151 /usr/bin/dash guuid=93d4776e-1900-0000-6bb3-0b881e140000 pid=5150->guuid=a5e8836e-1900-0000-6bb3-0b881f140000 pid=5151 clone guuid=4ddf886e-1900-0000-6bb3-0b8820140000 pid=5152 /usr/bin/sed guuid=93d4776e-1900-0000-6bb3-0b881e140000 pid=5150->guuid=4ddf886e-1900-0000-6bb3-0b8820140000 pid=5152 execve guuid=ab44e56e-1900-0000-6bb3-0b8822140000 pid=5154 /usr/bin/dash guuid=fe45dd6e-1900-0000-6bb3-0b8821140000 pid=5153->guuid=ab44e56e-1900-0000-6bb3-0b8822140000 pid=5154 clone guuid=c97feb6e-1900-0000-6bb3-0b8823140000 pid=5155 /usr/bin/sed guuid=fe45dd6e-1900-0000-6bb3-0b8821140000 pid=5153->guuid=c97feb6e-1900-0000-6bb3-0b8823140000 pid=5155 execve guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160 /usr/bin/apt-key write-file guuid=efda5274-1900-0000-6bb3-0b8827140000 pid=5159->guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160 execve guuid=c4244475-1900-0000-6bb3-0b8829140000 pid=5161 /usr/bin/dash guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=c4244475-1900-0000-6bb3-0b8829140000 pid=5161 clone guuid=73da5375-1900-0000-6bb3-0b882a140000 pid=5162 /usr/bin/apt-config guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=73da5375-1900-0000-6bb3-0b882a140000 pid=5162 execve guuid=e6825377-1900-0000-6bb3-0b882c140000 pid=5164 /usr/bin/apt-config guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=e6825377-1900-0000-6bb3-0b882c140000 pid=5164 execve guuid=86a3de78-1900-0000-6bb3-0b882e140000 pid=5166 /usr/bin/apt-config guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=86a3de78-1900-0000-6bb3-0b882e140000 pid=5166 execve guuid=a510587b-1900-0000-6bb3-0b8830140000 pid=5168 /usr/bin/apt-config guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=a510587b-1900-0000-6bb3-0b8830140000 pid=5168 execve guuid=5ab3e27c-1900-0000-6bb3-0b8833140000 pid=5171 /usr/bin/dash guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=5ab3e27c-1900-0000-6bb3-0b8833140000 pid=5171 clone guuid=5c0a047d-1900-0000-6bb3-0b8834140000 pid=5172 /usr/bin/apt-config guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=5c0a047d-1900-0000-6bb3-0b8834140000 pid=5172 execve guuid=5a868f7e-1900-0000-6bb3-0b8839140000 pid=5177 /usr/bin/mktemp guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=5a868f7e-1900-0000-6bb3-0b8839140000 pid=5177 execve guuid=1ca7c97e-1900-0000-6bb3-0b883b140000 pid=5179 /usr/bin/chmod guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=1ca7c97e-1900-0000-6bb3-0b883b140000 pid=5179 execve guuid=d416ee7e-1900-0000-6bb3-0b883c140000 pid=5180 /usr/bin/dash guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=d416ee7e-1900-0000-6bb3-0b883c140000 pid=5180 clone guuid=1add0b7f-1900-0000-6bb3-0b883d140000 pid=5181 /usr/bin/dash guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=1add0b7f-1900-0000-6bb3-0b883d140000 pid=5181 clone guuid=60046c7f-1900-0000-6bb3-0b8842140000 pid=5186 /usr/bin/dash guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=60046c7f-1900-0000-6bb3-0b8842140000 pid=5186 clone guuid=9ed9cd7f-1900-0000-6bb3-0b8846140000 pid=5190 /usr/bin/dash guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=9ed9cd7f-1900-0000-6bb3-0b8846140000 pid=5190 clone guuid=089edc7f-1900-0000-6bb3-0b8847140000 pid=5191 /usr/bin/gpgv guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=089edc7f-1900-0000-6bb3-0b8847140000 pid=5191 execve guuid=f4933481-1900-0000-6bb3-0b884a140000 pid=5194 /usr/bin/rm delete-file guuid=71021075-1900-0000-6bb3-0b8828140000 pid=5160->guuid=f4933481-1900-0000-6bb3-0b884a140000 pid=5194 execve guuid=7beaab76-1900-0000-6bb3-0b882b140000 pid=5163 /usr/bin/dpkg guuid=73da5375-1900-0000-6bb3-0b882a140000 pid=5162->guuid=7beaab76-1900-0000-6bb3-0b882b140000 pid=5163 execve guuid=de665278-1900-0000-6bb3-0b882d140000 pid=5165 /usr/bin/dpkg guuid=e6825377-1900-0000-6bb3-0b882c140000 pid=5164->guuid=de665278-1900-0000-6bb3-0b882d140000 pid=5165 execve guuid=90a9df7a-1900-0000-6bb3-0b882f140000 pid=5167 /usr/bin/dpkg guuid=86a3de78-1900-0000-6bb3-0b882e140000 pid=5166->guuid=90a9df7a-1900-0000-6bb3-0b882f140000 pid=5167 execve guuid=90ba527c-1900-0000-6bb3-0b8831140000 pid=5169 /usr/bin/dpkg guuid=a510587b-1900-0000-6bb3-0b8830140000 pid=5168->guuid=90ba527c-1900-0000-6bb3-0b8831140000 pid=5169 execve guuid=3569ef7d-1900-0000-6bb3-0b8837140000 pid=5175 /usr/bin/dpkg guuid=5c0a047d-1900-0000-6bb3-0b8834140000 pid=5172->guuid=3569ef7d-1900-0000-6bb3-0b8837140000 pid=5175 execve guuid=f4a9167f-1900-0000-6bb3-0b883f140000 pid=5183 /usr/bin/dash guuid=1add0b7f-1900-0000-6bb3-0b883d140000 pid=5181->guuid=f4a9167f-1900-0000-6bb3-0b883f140000 pid=5183 clone guuid=8b3b1f7f-1900-0000-6bb3-0b8840140000 pid=5184 /usr/bin/sed guuid=1add0b7f-1900-0000-6bb3-0b883d140000 pid=5181->guuid=8b3b1f7f-1900-0000-6bb3-0b8840140000 pid=5184 execve guuid=87b2757f-1900-0000-6bb3-0b8843140000 pid=5187 /usr/bin/dash guuid=60046c7f-1900-0000-6bb3-0b8842140000 pid=5186->guuid=87b2757f-1900-0000-6bb3-0b8843140000 pid=5187 clone guuid=506f7b7f-1900-0000-6bb3-0b8844140000 pid=5188 /usr/bin/sed guuid=60046c7f-1900-0000-6bb3-0b8842140000 pid=5186->guuid=506f7b7f-1900-0000-6bb3-0b8844140000 pid=5188 execve guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196 /usr/bin/apt-key write-file guuid=c26aee81-1900-0000-6bb3-0b884b140000 pid=5195->guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196 execve guuid=1a61c882-1900-0000-6bb3-0b884d140000 pid=5197 /usr/bin/dash guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=1a61c882-1900-0000-6bb3-0b884d140000 pid=5197 clone guuid=e679d582-1900-0000-6bb3-0b884e140000 pid=5198 /usr/bin/apt-config guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=e679d582-1900-0000-6bb3-0b884e140000 pid=5198 execve guuid=138a4384-1900-0000-6bb3-0b8852140000 pid=5202 /usr/bin/apt-config guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=138a4384-1900-0000-6bb3-0b8852140000 pid=5202 execve guuid=a6b48e85-1900-0000-6bb3-0b8858140000 pid=5208 /usr/bin/apt-config guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=a6b48e85-1900-0000-6bb3-0b8858140000 pid=5208 execve guuid=f9b1e286-1900-0000-6bb3-0b885e140000 pid=5214 /usr/bin/apt-config guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=f9b1e286-1900-0000-6bb3-0b885e140000 pid=5214 execve guuid=ce6b0988-1900-0000-6bb3-0b8862140000 pid=5218 /usr/bin/dash guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=ce6b0988-1900-0000-6bb3-0b8862140000 pid=5218 clone guuid=25112e88-1900-0000-6bb3-0b8863140000 pid=5219 /usr/bin/apt-config guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=25112e88-1900-0000-6bb3-0b8863140000 pid=5219 execve guuid=03fd5789-1900-0000-6bb3-0b8865140000 pid=5221 /usr/bin/mktemp guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=03fd5789-1900-0000-6bb3-0b8865140000 pid=5221 execve guuid=6a5d8f89-1900-0000-6bb3-0b8866140000 pid=5222 /usr/bin/chmod guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=6a5d8f89-1900-0000-6bb3-0b8866140000 pid=5222 execve guuid=9da1bf89-1900-0000-6bb3-0b8867140000 pid=5223 /usr/bin/dash guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=9da1bf89-1900-0000-6bb3-0b8867140000 pid=5223 clone guuid=1818d389-1900-0000-6bb3-0b8868140000 pid=5224 /usr/bin/dash guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=1818d389-1900-0000-6bb3-0b8868140000 pid=5224 clone guuid=f8c23b8a-1900-0000-6bb3-0b886b140000 pid=5227 /usr/bin/dash guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=f8c23b8a-1900-0000-6bb3-0b886b140000 pid=5227 clone guuid=e6db9f8a-1900-0000-6bb3-0b886e140000 pid=5230 /usr/bin/dash guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=e6db9f8a-1900-0000-6bb3-0b886e140000 pid=5230 clone guuid=8f1eb18a-1900-0000-6bb3-0b886f140000 pid=5231 /usr/bin/gpgv guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=8f1eb18a-1900-0000-6bb3-0b886f140000 pid=5231 execve guuid=604e028c-1900-0000-6bb3-0b8872140000 pid=5234 /usr/bin/rm delete-file guuid=3af49682-1900-0000-6bb3-0b884c140000 pid=5196->guuid=604e028c-1900-0000-6bb3-0b8872140000 pid=5234 execve guuid=37b2e683-1900-0000-6bb3-0b8850140000 pid=5200 /usr/bin/dpkg guuid=e679d582-1900-0000-6bb3-0b884e140000 pid=5198->guuid=37b2e683-1900-0000-6bb3-0b8850140000 pid=5200 execve guuid=5e7c2885-1900-0000-6bb3-0b8856140000 pid=5206 /usr/bin/dpkg guuid=138a4384-1900-0000-6bb3-0b8852140000 pid=5202->guuid=5e7c2885-1900-0000-6bb3-0b8856140000 pid=5206 execve guuid=7ae08286-1900-0000-6bb3-0b885c140000 pid=5212 /usr/bin/dpkg guuid=a6b48e85-1900-0000-6bb3-0b8858140000 pid=5208->guuid=7ae08286-1900-0000-6bb3-0b885c140000 pid=5212 execve guuid=ce31af87-1900-0000-6bb3-0b8861140000 pid=5217 /usr/bin/dpkg guuid=f9b1e286-1900-0000-6bb3-0b885e140000 pid=5214->guuid=ce31af87-1900-0000-6bb3-0b8861140000 pid=5217 execve guuid=8e0dff88-1900-0000-6bb3-0b8864140000 pid=5220 /usr/bin/dpkg guuid=25112e88-1900-0000-6bb3-0b8863140000 pid=5219->guuid=8e0dff88-1900-0000-6bb3-0b8864140000 pid=5220 execve guuid=e527dc89-1900-0000-6bb3-0b8869140000 pid=5225 /usr/bin/dash guuid=1818d389-1900-0000-6bb3-0b8868140000 pid=5224->guuid=e527dc89-1900-0000-6bb3-0b8869140000 pid=5225 clone guuid=3337e289-1900-0000-6bb3-0b886a140000 pid=5226 /usr/bin/sed guuid=1818d389-1900-0000-6bb3-0b8868140000 pid=5224->guuid=3337e289-1900-0000-6bb3-0b886a140000 pid=5226 execve guuid=8eb9458a-1900-0000-6bb3-0b886c140000 pid=5228 /usr/bin/dash guuid=f8c23b8a-1900-0000-6bb3-0b886b140000 pid=5227->guuid=8eb9458a-1900-0000-6bb3-0b886c140000 pid=5228 clone guuid=99404b8a-1900-0000-6bb3-0b886d140000 pid=5229 /usr/bin/sed guuid=f8c23b8a-1900-0000-6bb3-0b886b140000 pid=5227->guuid=99404b8a-1900-0000-6bb3-0b886d140000 pid=5229 execve guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241 /usr/bin/apt-key write-file guuid=ba88c98c-1900-0000-6bb3-0b8876140000 pid=5238->guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241 execve guuid=51b1928d-1900-0000-6bb3-0b887b140000 pid=5243 /usr/bin/dash guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=51b1928d-1900-0000-6bb3-0b887b140000 pid=5243 clone guuid=b7dba18d-1900-0000-6bb3-0b887c140000 pid=5244 /usr/bin/apt-config guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=b7dba18d-1900-0000-6bb3-0b887c140000 pid=5244 execve guuid=e7ed228f-1900-0000-6bb3-0b8884140000 pid=5252 /usr/bin/apt-config guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=e7ed228f-1900-0000-6bb3-0b8884140000 pid=5252 execve guuid=16cb7290-1900-0000-6bb3-0b888a140000 pid=5258 /usr/bin/apt-config guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=16cb7290-1900-0000-6bb3-0b888a140000 pid=5258 execve guuid=0cbcb192-1900-0000-6bb3-0b8895140000 pid=5269 /usr/bin/apt-config guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=0cbcb192-1900-0000-6bb3-0b8895140000 pid=5269 execve guuid=02f5dd97-1900-0000-6bb3-0b8897140000 pid=5271 /usr/bin/dash guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=02f5dd97-1900-0000-6bb3-0b8897140000 pid=5271 clone guuid=6e310598-1900-0000-6bb3-0b8898140000 pid=5272 /usr/bin/apt-config guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=6e310598-1900-0000-6bb3-0b8898140000 pid=5272 execve guuid=fb82ca99-1900-0000-6bb3-0b88a3140000 pid=5283 /usr/bin/mktemp guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=fb82ca99-1900-0000-6bb3-0b88a3140000 pid=5283 execve guuid=2e87169a-1900-0000-6bb3-0b88a6140000 pid=5286 /usr/bin/chmod guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=2e87169a-1900-0000-6bb3-0b88a6140000 pid=5286 execve guuid=7f9c5d9a-1900-0000-6bb3-0b88a9140000 pid=5289 /usr/bin/dash guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=7f9c5d9a-1900-0000-6bb3-0b88a9140000 pid=5289 clone guuid=42ee739a-1900-0000-6bb3-0b88aa140000 pid=5290 /usr/bin/dash guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=42ee739a-1900-0000-6bb3-0b88aa140000 pid=5290 clone guuid=7578da9a-1900-0000-6bb3-0b88af140000 pid=5295 /usr/bin/dash guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=7578da9a-1900-0000-6bb3-0b88af140000 pid=5295 clone guuid=d9766e9b-1900-0000-6bb3-0b88b6140000 pid=5302 /usr/bin/dash guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=d9766e9b-1900-0000-6bb3-0b88b6140000 pid=5302 clone guuid=8cc37f9b-1900-0000-6bb3-0b88b7140000 pid=5303 /usr/bin/gpgv guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=8cc37f9b-1900-0000-6bb3-0b88b7140000 pid=5303 execve guuid=25e81b9d-1900-0000-6bb3-0b88c2140000 pid=5314 /usr/bin/rm delete-file guuid=9b3e5e8d-1900-0000-6bb3-0b8879140000 pid=5241->guuid=25e81b9d-1900-0000-6bb3-0b88c2140000 pid=5314 execve guuid=c964c38e-1900-0000-6bb3-0b8881140000 pid=5249 /usr/bin/dpkg guuid=b7dba18d-1900-0000-6bb3-0b887c140000 pid=5244->guuid=c964c38e-1900-0000-6bb3-0b8881140000 pid=5249 execve guuid=87051090-1900-0000-6bb3-0b8888140000 pid=5256 /usr/bin/dpkg guuid=e7ed228f-1900-0000-6bb3-0b8884140000 pid=5252->guuid=87051090-1900-0000-6bb3-0b8888140000 pid=5256 execve guuid=4e853792-1900-0000-6bb3-0b8891140000 pid=5265 /usr/bin/dpkg guuid=16cb7290-1900-0000-6bb3-0b888a140000 pid=5258->guuid=4e853792-1900-0000-6bb3-0b8891140000 pid=5265 execve guuid=83728d93-1900-0000-6bb3-0b8896140000 pid=5270 /usr/bin/dpkg guuid=0cbcb192-1900-0000-6bb3-0b8895140000 pid=5269->guuid=83728d93-1900-0000-6bb3-0b8896140000 pid=5270 execve guuid=f0db0c99-1900-0000-6bb3-0b889a140000 pid=5274 /usr/bin/dpkg guuid=6e310598-1900-0000-6bb3-0b8898140000 pid=5272->guuid=f0db0c99-1900-0000-6bb3-0b889a140000 pid=5274 execve guuid=90137e9a-1900-0000-6bb3-0b88ac140000 pid=5292 /usr/bin/dash guuid=42ee739a-1900-0000-6bb3-0b88aa140000 pid=5290->guuid=90137e9a-1900-0000-6bb3-0b88ac140000 pid=5292 clone guuid=d627839a-1900-0000-6bb3-0b88ad140000 pid=5293 /usr/bin/sed guuid=42ee739a-1900-0000-6bb3-0b88aa140000 pid=5290->guuid=d627839a-1900-0000-6bb3-0b88ad140000 pid=5293 execve guuid=5498e19a-1900-0000-6bb3-0b88b0140000 pid=5296 /usr/bin/dash guuid=7578da9a-1900-0000-6bb3-0b88af140000 pid=5295->guuid=5498e19a-1900-0000-6bb3-0b88b0140000 pid=5296 clone guuid=26a2e69a-1900-0000-6bb3-0b88b1140000 pid=5297 /usr/bin/sed guuid=7578da9a-1900-0000-6bb3-0b88af140000 pid=5295->guuid=26a2e69a-1900-0000-6bb3-0b88b1140000 pid=5297 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
64 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample contains AV-related strings
Sample pipes script to sh (AV evasion)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1847116 Sample: x86_64.kok.elf Startdate: 09/01/2026 Architecture: LINUX Score: 64 128 _http._tcp.ch.archive.ubuntu.com 2->128 130 169.254.169.254 USDOSUS Reserved 2->130 132 5 other IPs or domains 2->132 134 Malicious sample detected (through community Yara rule) 2->134 136 Multi AV Scanner detection for submitted file 2->136 138 Sample pipes script to sh (AV evasion) 2->138 140 Sample contains AV-related strings 2->140 13 x86_64.kok.elf 2->13         started        15 dash rm 2->15         started        17 dash rm 2->17         started        19 python3.8 dpkg 2->19         started        signatures3 process4 process5 21 x86_64.kok.elf sh 13->21         started        23 x86_64.kok.elf sh 13->23         started        25 x86_64.kok.elf sh 13->25         started        27 3 other processes 13->27 process6 29 sh apt-get 21->29         started        31 sh which 23->31         started        33 sh which 25->33         started        35 sh which 27->35         started        37 sh which 27->37         started        39 sh which 27->39         started        process7 41 apt-get 29->41         started        43 apt-get gpgv 29->43         started        45 apt-get dpkg 29->45         started        47 7 other processes 29->47 process8 49 apt-get sh 41->49         started        51 apt-get sh 41->51         started        53 apt-get sh 41->53         started        63 3 other processes 41->63 55 gpgv 43->55         started        57 gpgv 43->57         started        59 gpgv 43->59         started        61 gpgv 43->61         started        process9 65 sh update-motd-updates-available 49->65         started        67 sh appstreamcli 51->67         started        69 sh test 51->69         started        80 4 other processes 53->80 71 gpgv apt-key 55->71         started        74 gpgv apt-key 57->74         started        76 gpgv apt-key 59->76         started        78 gpgv apt-key 61->78         started        82 3 other processes 63->82 file10 84 update-motd-updates-available apt-check 65->84         started        90 10 other processes 65->90 92 30 other processes 67->92 120 /tmp/apt-key-gpghome.MRaHob04WG/gpg.1.sh, POSIX 71->120 dropped 86 apt-key gpgconf 71->86         started        94 35 other processes 71->94 122 /tmp/apt-key-gpghome.5QBau3GRD2/gpg.1.sh, POSIX 74->122 dropped 96 36 other processes 74->96 124 /tmp/apt-key-gpghome.0UJbQGDwW5/gpg.1.sh, POSIX 76->124 dropped 98 36 other processes 76->98 126 /tmp/apt-key-gpghome.uk5VRhz7QF/gpg.1.sh, POSIX 78->126 dropped 100 36 other processes 78->100 88 cnf-update-db dpkg 82->88         started        process11 process12 104 166 other processes 84->104 102 gpgconf gpg-connect-agent 86->102         started        106 2 other processes 86->106 108 6 other processes 90->108 110 30 other processes 92->110 112 14 other processes 94->112 114 17 other processes 96->114 116 17 other processes 98->116 118 17 other processes 100->118
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2026-01-09 07:22:36 UTC
File Type:
ELF64 Little (Exe)
AV detection:
9 of 36 (25.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Writes file to tmp directory
Changes its process name
Modifies Bash startup script
Creates/modifies Cron job
Creates/modifies environment variables
Deletes log files
Enumerates running processes
Looks up external IP address via web service
Modifies init.d
Modifies rc script
Write file to user bin folder
Executes dropped EXE
Verdict:
Malicious
Tags:
trojan gafgyt Unix.Trojan.Mirai-7640640-0
YARA:
Linux_Trojan_Gafgyt_9e9530a7 Linux_Trojan_Gafgyt_807911a2 Linux_Trojan_Gafgyt_d4227dbf Linux_Trojan_Gafgyt_d996d335 Linux_Trojan_Gafgyt_620087b9 Linux_Trojan_Gafgyt_33b4111a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202503_elf_Mirai
Author:abuse.ch
Description:Detects Mirai 'TSource' ELF files
Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf b5f0994117bf18e836aa1a1281171e823e36ce2480c107291a6b51255b6b324a

(this sample)

  
Delivery method
Distributed via web download

Comments