MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b70debdd7bc241ec9435cf354332a59ab5a98ea60458c7c062fdee18373562bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 12


Intelligence 12 IOCs YARA 10 File information Comments

SHA256 hash: b70debdd7bc241ec9435cf354332a59ab5a98ea60458c7c062fdee18373562bc
SHA3-384 hash: a5cacbbda12a3580f65a84ce6eb9f577923f3ed4aa95e0dc2c946f5f68528e94d82514183be4ea57686c31c9baf79838
SHA1 hash: 108d67182e599964331d9fe8d3343ef253c954de
MD5 hash: 19156986339517098f6315c4b6fba5e2
humanhash: neptune-beryllium-kansas-quebec
File name:GodAge3ATOx64
Download: download sample
Signature Mirai
File size:41'984 bytes
First seen:2025-08-04 05:44:17 UTC
Last seen:2025-08-08 05:53:11 UTC
File type: elf
MIME type:application/x-executable
ssdeep 768:lVu2eCac5mcXmviroq2gNcTVXt0cz9T57aJI7yIk:62Fac5mcXproqPuTJt3hT57t2I
TLSH T1A6131A17B94184FCC099C234577AB53ED92B71BE0239B3EA37D4FB266AC9E611E1D804
telfhash t19601a2f27d2a0c55b1e7f016b79ae1514c380d1120d036f6e6b179ea9b19f415771c3b
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
3
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
4
Number of processes launched:
6
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=17dd5b97-1a00-0000-e603-4501c4090000 pid=2500 /usr/bin/sudo guuid=ee2e3b99-1a00-0000-e603-4501c7090000 pid=2503 /tmp/sample.bin net guuid=17dd5b97-1a00-0000-e603-4501c4090000 pid=2500->guuid=ee2e3b99-1a00-0000-e603-4501c7090000 pid=2503 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ee2e3b99-1a00-0000-e603-4501c7090000 pid=2503->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=52126099-1a00-0000-e603-4501c8090000 pid=2504 /tmp/sample.bin zombie guuid=ee2e3b99-1a00-0000-e603-4501c7090000 pid=2503->guuid=52126099-1a00-0000-e603-4501c8090000 pid=2504 clone guuid=23246399-1a00-0000-e603-4501c9090000 pid=2505 /tmp/sample.bin guuid=ee2e3b99-1a00-0000-e603-4501c7090000 pid=2503->guuid=23246399-1a00-0000-e603-4501c9090000 pid=2505 clone guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506 /tmp/sample.bin net send-data zombie guuid=ee2e3b99-1a00-0000-e603-4501c7090000 pid=2503->guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506 clone guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con c7912158-024c-52f0-b966-e0a025bb059a 83.150.218.182:34700 guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506->c7912158-024c-52f0-b966-e0a025bb059a send: 7B guuid=666c7099-1a00-0000-e603-4501cb090000 pid=2507 /tmp/sample.bin guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506->guuid=666c7099-1a00-0000-e603-4501cb090000 pid=2507 clone guuid=53a17399-1a00-0000-e603-4501cc090000 pid=2508 /tmp/sample.bin guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506->guuid=53a17399-1a00-0000-e603-4501cc090000 pid=2508 clone guuid=69a4b00e-1f00-0000-e603-45013f130000 pid=4927 /tmp/sample.bin send-data guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506->guuid=69a4b00e-1f00-0000-e603-45013f130000 pid=4927 clone guuid=e4459f1b-1f00-0000-e603-450169130000 pid=4969 /tmp/sample.bin send-data guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506->guuid=e4459f1b-1f00-0000-e603-450169130000 pid=4969 clone guuid=370cf31d-1f00-0000-e603-450171130000 pid=4977 /tmp/sample.bin net guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506->guuid=370cf31d-1f00-0000-e603-450171130000 pid=4977 clone guuid=61897023-1f00-0000-e603-450186130000 pid=4998 /tmp/sample.bin send-data guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506->guuid=61897023-1f00-0000-e603-450186130000 pid=4998 clone guuid=9cd13bd4-2300-0000-e603-450193140000 pid=5267 /tmp/sample.bin net send-data guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506->guuid=9cd13bd4-2300-0000-e603-450193140000 pid=5267 clone guuid=9b2c90db-2300-0000-e603-450195140000 pid=5269 /tmp/sample.bin net send-data guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506->guuid=9b2c90db-2300-0000-e603-450195140000 pid=5269 clone guuid=b23494e3-2300-0000-e603-450197140000 pid=5271 /tmp/sample.bin net send-data guuid=7aad6699-1a00-0000-e603-4501ca090000 pid=2506->guuid=b23494e3-2300-0000-e603-450197140000 pid=5271 clone 283f8ca1-bc60-5ad1-8d9d-ac0253926cbd 116.103.229.97:8080 guuid=69a4b00e-1f00-0000-e603-45013f130000 pid=4927->283f8ca1-bc60-5ad1-8d9d-ac0253926cbd send: 4359208B guuid=a1dcb70e-1f00-0000-e603-450140130000 pid=4928 /tmp/sample.bin guuid=69a4b00e-1f00-0000-e603-45013f130000 pid=4927->guuid=a1dcb70e-1f00-0000-e603-450140130000 pid=4928 clone guuid=e4459f1b-1f00-0000-e603-450169130000 pid=4969->283f8ca1-bc60-5ad1-8d9d-ac0253926cbd send: 4359208B guuid=77dba31b-1f00-0000-e603-45016a130000 pid=4970 /tmp/sample.bin guuid=e4459f1b-1f00-0000-e603-450169130000 pid=4969->guuid=77dba31b-1f00-0000-e603-45016a130000 pid=4970 clone guuid=370cf31d-1f00-0000-e603-450171130000 pid=4977->283f8ca1-bc60-5ad1-8d9d-ac0253926cbd con guuid=d33bfa1d-1f00-0000-e603-450172130000 pid=4978 /tmp/sample.bin guuid=370cf31d-1f00-0000-e603-450171130000 pid=4977->guuid=d33bfa1d-1f00-0000-e603-450172130000 pid=4978 clone guuid=61897023-1f00-0000-e603-450186130000 pid=4998->283f8ca1-bc60-5ad1-8d9d-ac0253926cbd send: 4359208B guuid=466c8f23-1f00-0000-e603-450187130000 pid=4999 /tmp/sample.bin guuid=61897023-1f00-0000-e603-450186130000 pid=4998->guuid=466c8f23-1f00-0000-e603-450187130000 pid=4999 clone ed44887e-d7f0-53a5-ae30-214ce33dd05f 76.158.120.110:53 guuid=9cd13bd4-2300-0000-e603-450193140000 pid=5267->ed44887e-d7f0-53a5-ae30-214ce33dd05f send: 2097664B guuid=4f3bb2d4-2300-0000-e603-450194140000 pid=5268 /tmp/sample.bin guuid=9cd13bd4-2300-0000-e603-450193140000 pid=5267->guuid=4f3bb2d4-2300-0000-e603-450194140000 pid=5268 clone guuid=9b2c90db-2300-0000-e603-450195140000 pid=5269->ed44887e-d7f0-53a5-ae30-214ce33dd05f send: 2097664B guuid=868416dc-2300-0000-e603-450196140000 pid=5270 /tmp/sample.bin guuid=9b2c90db-2300-0000-e603-450195140000 pid=5269->guuid=868416dc-2300-0000-e603-450196140000 pid=5270 clone guuid=b23494e3-2300-0000-e603-450197140000 pid=5271->ed44887e-d7f0-53a5-ae30-214ce33dd05f send: 2097664B guuid=431200e4-2300-0000-e603-450198140000 pid=5272 /tmp/sample.bin guuid=b23494e3-2300-0000-e603-450197140000 pid=5271->guuid=431200e4-2300-0000-e603-450198140000 pid=5272 clone
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Verdict:
Malicious
Threat:
HEUR:Backdoor.Linux.Mirai
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-08-04 05:45:27 UTC
File Type:
ELF64 Little (Exe)
AV detection:
26 of 38 (68.42%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari linux
Malware Config
C2 Extraction:
newageofkifirempire.camdvr.org
Verdict:
Malicious
Tags:
trojan gafgyt mirai Unix.Dropper.Mirai-7135890-0
YARA:
Linux_Trojan_Gafgyt_9e9530a7 Linux_Trojan_Gafgyt_807911a2 Linux_Trojan_Gafgyt_d4227dbf Linux_Trojan_Gafgyt_620087b9 Linux_Trojan_Gafgyt_33b4111a Linux_Trojan_Mirai_520deeb8 Linux_Trojan_Mirai_6a77af0f Linux_Trojan_Mirai_01e4a728 Linux_Trojan_Mirai_e0cf29e2
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_01e4a728
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_520deeb8
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_6a77af0f
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_e0cf29e2
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf b70debdd7bc241ec9435cf354332a59ab5a98ea60458c7c062fdee18373562bc

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh

Comments