MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c14d198279d75d641372771beb25c299662461a09163bcf7e454f8313211125b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: c14d198279d75d641372771beb25c299662461a09163bcf7e454f8313211125b
SHA3-384 hash: be3735e63cc591626a6b082ced06958d5d024a8d80b7a73b6aebedb67ed76e39aab54c958bc6aeb088a939771bb7fb2d
SHA1 hash: ba14a63a989bc7faae64434e87fdef36da73b4ed
MD5 hash: a2554f491e340ea0f309eb3b8fc5d08a
humanhash: magnesium-neptune-edward-beer
File name:87sbhas6as.m68k
Download: download sample
Signature Mirai
File size:37'985 bytes
First seen:2025-12-31 00:21:10 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:vIQJ3fiZ0t+FqD806l8lGAq2GfxTW3AGDQ:gMfiuIqw5l8saGfxTOA
TLSH T111032B8AB4029E3CF94FF77F54124918F5613356D1D31B2A53A7FE53A8332682E52E82
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=5dec8b63-1900-0000-b5b3-2997ad070000 pid=1965 /usr/bin/sudo guuid=4f9fc766-1900-0000-b5b3-2997b0070000 pid=1968 /tmp/sample.bin guuid=5dec8b63-1900-0000-b5b3-2997ad070000 pid=1965->guuid=4f9fc766-1900-0000-b5b3-2997b0070000 pid=1968 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1842416 Sample: 87sbhas6as.m68k.elf Startdate: 31/12/2025 Architecture: LINUX Score: 48 20 130.12.180.134, 33966, 34028 DATAHOPDatahop-SixDegreesGB Canada 2->20 22 34.254.182.186, 443, 44532 AMAZON-02US United States 2->22 24 Multi AV Scanner detection for submitted file 2->24 8 87sbhas6as.m68k.elf 2->8         started        10 dash rm 2->10         started        12 dash cat 2->12         started        14 8 other processes 2->14 signatures3 process4 process5 16 87sbhas6as.m68k.elf 8->16         started        process6 18 87sbhas6as.m68k.elf 16->18         started       
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-31 00:22:22 UTC
File Type:
ELF32 Big (Exe)
AV detection:
8 of 36 (22.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Verdict:
Malicious
Tags:
Unix.Trojan.Mirai-6981989-0
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf c14d198279d75d641372771beb25c299662461a09163bcf7e454f8313211125b

(this sample)

  
Delivery method
Distributed via web download

Comments