MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 caecf172cfe7405e4feca3d24ec1007ffde4df46934db85ecaa85ca39281a8ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: caecf172cfe7405e4feca3d24ec1007ffde4df46934db85ecaa85ca39281a8ea
SHA3-384 hash: 0ad04da1cef21583e577e8339d0b76a6570a59c56968d4f17a9eb0f2fbaba950bb3d9d7895531f09ac48d4b306b00d4d
SHA1 hash: b300fa3ee49f96146113d0af2b0a15372f2eb5a7
MD5 hash: 4c65f4f18aca7418cc6ab42aa35212ce
humanhash: moon-carpet-red-social
File name:ppc
Download: download sample
Signature Mirai
File size:63'104 bytes
First seen:2025-11-01 10:30:55 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 768:bLQaw7umFBnpoyu7wfQ99vDoSeONP6O3QRdsjF4mtuWkuqh/2IOi:XQT7FBiPcfCvDteAPx3Qhmc3uqh/2Hi
TLSH T175532C42B31C0957D5B3AEB0253F27E093BBE55021F4BA88251E9B999371E325186FCE
Magika elf
Reporter abuse_ch
Tags:elf mirai upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 661b156b5561fa89f3e09ff671a92de8020d6d786593f11e56c5d3af6ea35032
File size (compressed) :31'928 bytes
File size (de-compressed) :63'104 bytes
Format:linux/ppc32
Packed file: 661b156b5561fa89f3e09ff671a92de8020d6d786593f11e56c5d3af6ea35032

Intelligence


File Origin
# of uploads :
1
# of downloads :
147
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Receives data from a server
Opens a port
Sends data to a server
DNS request
Connection attempt
Substitutes an application name
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2025-11-01T08:40:00Z UTC
Last seen:
2025-11-01T13:14:00Z UTC
Hits:
~10
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
68 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sends malformed DNS queries
Yara detected Mirai
Behaviour
Behavior Graph:
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-11-01 10:34:39 UTC
File Type:
ELF32 Big (Exe)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf caecf172cfe7405e4feca3d24ec1007ffde4df46934db85ecaa85ca39281a8ea

(this sample)

  
Delivery method
Distributed via web download

Comments