MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bf27d70029fd5b3938b0da2e1d054ad50b2bb7d39ccf0a67b075c23c11ea8361. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: bf27d70029fd5b3938b0da2e1d054ad50b2bb7d39ccf0a67b075c23c11ea8361
SHA3-384 hash: a17561f9db170b1cf9ee1e9ca559acc609df20027260dc3695b1102a3aba26286402d481760f02aad2e076600b8e808c
SHA1 hash: 87c9ec5986c28c9a76c930ce85e2873646f1e89b
MD5 hash: d044bb7160daffe9782e62741d243801
humanhash: wolfram-xray-lion-carpet
File name:ppc
Download: download sample
Signature Mirai
File size:38'572 bytes
First seen:2025-10-12 22:37:52 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:GRgA68jSOyvC578Omo81TpKaBqOydbpuU1/4HSqn7L:KSv881h364HSqX
TLSH T1A7032C42765C4F67D5A22AB4253F53E083FEE9A020F4F588264FCB968635E374187E8D
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
108
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Runs as daemon
Connection attempt
Substitutes an application name
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2025-10-12T20:54:00Z UTC
Last seen:
2025-10-12T22:31:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=eb8a2fac-1a00-0000-da0e-94d3730b0000 pid=2931 /usr/bin/sudo guuid=a0b7d4ad-1a00-0000-da0e-94d3780b0000 pid=2936 /tmp/sample.bin guuid=eb8a2fac-1a00-0000-da0e-94d3730b0000 pid=2931->guuid=a0b7d4ad-1a00-0000-da0e-94d3780b0000 pid=2936 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1793670 Sample: ppc.elf Startdate: 13/10/2025 Architecture: LINUX Score: 48 11 188.241.62.243, 2310, 42066 HVC-ASUS Spain 2->11 13 Multi AV Scanner detection for submitted file 2->13 7 ppc.elf 2->7         started        signatures3 process4 process5 9 ppc.elf 7->9         started       
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-10-12 22:39:24 UTC
File Type:
ELF32 Big (Exe)
AV detection:
24 of 38 (63.16%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:kaizen linux
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-9876194-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf bf27d70029fd5b3938b0da2e1d054ad50b2bb7d39ccf0a67b075c23c11ea8361

(this sample)

  
Delivery method
Distributed via web download

Comments