MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cb4efe99fbc11befd19e6eb33c1c29b00301429ddfb6864a10130dc7ac3eb5e0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 9 File information Comments

SHA256 hash: cb4efe99fbc11befd19e6eb33c1c29b00301429ddfb6864a10130dc7ac3eb5e0
SHA3-384 hash: f0cbd01b9fef0022e65011825eb8842095275c0ae1618cce31c2e126798a3ae215b9c67218f31cf6d9a2b2f576be5a58
SHA1 hash: 94868c9ea3a3bf92a9ffa5fb3cd879bac60c140e
MD5 hash: 8770c0083d72b222a0fc4503dddd339b
humanhash: connecticut-comet-leopard-autumn
File name:flutter.mipsel
Download: download sample
Signature Mirai
File size:262'440 bytes
First seen:2026-08-19 01:51:46 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 6144:zTTzGgib+PZBB7ipRkADLpR84CTL3geUHvRYLKV4:XTz2b+PZnip+mU4CTSCLKu
TLSH T17E445C8A9E601FEBC46FCD30063E871719ED999BA2F16736C67CDC48358E24946E385C
telfhash t1fa4123355f7995229ed2c4509cee9322a51ed1190755ee27df24854c102e09ff21be8f
Magika elf
Reporter abuse_ch
Tags:elf mirai upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 b1f240b7153d4f3e5c6239c00ea341f46e00df99b4e3751d85b341f4a8106b91
File size (compressed) :134'764 bytes
File size (de-compressed) :262'440 bytes
Format:linux/mipsel
Packed file: b1f240b7153d4f3e5c6239c00ea341f46e00df99b4e3751d85b341f4a8106b91

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Kills processes
Opens a port
Receives data from a server
Sends data to a server
Connection attempt
Manages services
Runs as daemon
DNS request
Changes access rights for a written file
Creating a file
Substitutes an application name
Creates or modifies files in /cron to set up autorun
Creates or modifies files in /init.d to set up autorun
Performs a bruteforce attack in the network
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 dropper expand gcc lolbin mirai obfuscated
Status:
terminated
Behavior Graph:
%3 guuid=8c966f36-1900-0000-e837-6a003c030000 pid=828 /usr/bin/sudo guuid=91a00b39-1900-0000-e837-6a003d030000 pid=829 /tmp/sample.bin guuid=8c966f36-1900-0000-e837-6a003c030000 pid=828->guuid=91a00b39-1900-0000-e837-6a003d030000 pid=829 execve
Gathering data
Threat name:
Linux.Backdoor.Mirai
Status:
Malicious
First seen:
2026-08-19 01:55:41 UTC
File Type:
ELF32 Little (SO)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Changes its process name
Reads system network configuration
Write file to user bin folder
Creates/modifies Cron job
Enumerates active TCP sockets
Enumerates running processes
Modifies rc script
Modifies systemd
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:elf_arm_mips_ko_so
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:test_rule_vldslv
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
Rule name:woof_mirai_variant
Author:Nokia Deepfield ERT
Description:Detects Woof Mirai variant (ChaCha20 table, HTTP C2 with token/guid, .woof dropper)
Reference:Internal analysis of sample 6ef4ce02

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf cb4efe99fbc11befd19e6eb33c1c29b00301429ddfb6864a10130dc7ac3eb5e0

(this sample)

  
Delivery method
Distributed via web download

Comments