MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c19a9ccea95a758dccbd692cbd469e9a2d373fe6e63cbf4009d8c76fd073e288. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: c19a9ccea95a758dccbd692cbd469e9a2d373fe6e63cbf4009d8c76fd073e288
SHA3-384 hash: 8d92d1af4c6df22faa1e8c0092d0706a74812d1f3d84950e8dd18a89ed03e113cc0594332c559aa422bddbe1f6df9610
SHA1 hash: a9547efe5e9a7e2b9a0b6d08bef7e0a6358b187d
MD5 hash: 48d6f7d6f94e437cd8b6c98870ef8c87
humanhash: alanine-snake-undress-pizza
File name:putita.ppc
Download: download sample
Signature Mirai
File size:198'016 bytes
First seen:2026-07-16 00:29:46 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 3072:t/njlJBseKbpY0EUoGIy4yS010AEvQH/JGaRp1DrojG9uJ:t/njtse6Y0EUtI/F5AEvQH/JGOvQIuJ
TLSH T119147E01BF181953D1931DB45B3F0766D379D88318B8F109190BBB961733EB7AA87B8A
Magika elf
Reporter abuse_ch
Tags:elf mirai upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 fc6a37d766e2c13eb68da8efa734978ae6dead2a8ec536b99793c422b1caa836
File size (compressed) :60'588 bytes
File size (de-compressed) :198'016 bytes
Format:linux/ppc32
Packed file: fc6a37d766e2c13eb68da8efa734978ae6dead2a8ec536b99793c422b1caa836

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
gcc masquerade mirai
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2026-07-16T08:55:00Z UTC
Last seen:
2026-07-17T19:40:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a5ebcf5f-1900-0000-f5d5-e2ac0b0e0000 pid=3595 /usr/bin/sudo guuid=26c68861-1900-0000-f5d5-e2ac110e0000 pid=3601 /tmp/sample.bin guuid=a5ebcf5f-1900-0000-f5d5-e2ac0b0e0000 pid=3595->guuid=26c68861-1900-0000-f5d5-e2ac110e0000 pid=3601 execve
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-07-16 00:31:10 UTC
File Type:
ELF32 Big (SO)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
Rule name:ELF_Mirai
Author:NDA0E
Description:Detects multiple Mirai variants
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf c19a9ccea95a758dccbd692cbd469e9a2d373fe6e63cbf4009d8c76fd073e288

(this sample)

  
Delivery method
Distributed via web download

Comments