MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cbb4d1aecc65903e67da787d93724125bf17babef31faa7bddea632c74da9b4e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA 5 File information Comments

SHA256 hash: cbb4d1aecc65903e67da787d93724125bf17babef31faa7bddea632c74da9b4e
SHA3-384 hash: 01017e3d75847beef2389b80241d79e9b3b97d508526c60fa28620d795ba2c3e66acca40283206d2d651c80619ca2e2a
SHA1 hash: 6f87cabf7cb22e9d228e69a31821efcbcafe3493
MD5 hash: b0c4b2c3b70640383bf2d58170449562
humanhash: april-eleven-monkey-alaska
File name:sys64.i486
Download: download sample
Signature Mirai
File size:91'372 bytes
First seen:2026-01-26 05:44:40 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:eG2qHqrZXotWs1vS1XW/dQeeC73Q5RbprMb9goSoa12kUY31MlefSWJiLpz4b2r:eG2q+ZYttxS1WFreu3QTlrS3uqlhjN0C
TLSH T174935B89F743E1B0EC05013155AFA7769B385E236534EA5AFB853F36AC23B11990B72C
telfhash t11f4139fa0ebe1cdcbbe59400d25e5f92a90de63f555475e00673992133abf40507ac35
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
gafgyt masquerade obfuscated rust
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
11
Number of processes launched:
2
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Process Renaming
Botnet C2s
TCP botnet C2(s):
type:Mirai 45.9.2.141:8033
UDP botnet C2(s):
not identified
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2026-01-25T22:22:00Z UTC
Last seen:
2026-01-26T04:34:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=5b4cdcb2-1800-0000-6c8e-d538380a0000 pid=2616 /usr/bin/sudo guuid=22666db4-1800-0000-6c8e-d5383f0a0000 pid=2623 /tmp/sample.bin guuid=5b4cdcb2-1800-0000-6c8e-d538380a0000 pid=2616->guuid=22666db4-1800-0000-6c8e-d5383f0a0000 pid=2623 execve guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625 /tmp/sample.bin dns net send-data write-file zombie guuid=22666db4-1800-0000-6c8e-d5383f0a0000 pid=2623->guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8cfbd4df-b5e2-5a19-bbaa-8077b09b55fd 223.5.5.5:53 guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->8cfbd4df-b5e2-5a19-bbaa-8077b09b55fd send: 39B bcea957d-6a39-5f2c-a5d4-a9196ec2f4e0 29t305j3uk4962rn.aliyunddos1008.com:80 guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->bcea957d-6a39-5f2c-a5d4-a9196ec2f4e0 send: 322B 1cb86108-37e5-58a7-89b9-353958c965a1 45.9.2.141:8033 guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->1cb86108-37e5-58a7-89b9-353958c965a1 send: 7B 66a460ca-d373-5bf3-9826-4746b0522c79 223.26.52.213:8033 guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->66a460ca-d373-5bf3-9826-4746b0522c79 con 54206152-f87f-522b-8766-11da8e91a2cc 204.76.203.49:8033 guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->54206152-f87f-522b-8766-11da8e91a2cc con guuid=a3d8c0b4-1800-0000-6c8e-d538420a0000 pid=2626 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=a3d8c0b4-1800-0000-6c8e-d538420a0000 pid=2626 clone guuid=c778c0ba-1800-0000-6c8e-d538580a0000 pid=2648 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=c778c0ba-1800-0000-6c8e-d538580a0000 pid=2648 clone guuid=2c4ec0c0-1800-0000-6c8e-d5386e0a0000 pid=2670 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=2c4ec0c0-1800-0000-6c8e-d5386e0a0000 pid=2670 clone guuid=e117bfc6-1800-0000-6c8e-d538830a0000 pid=2691 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=e117bfc6-1800-0000-6c8e-d538830a0000 pid=2691 clone guuid=7ccfc5cc-1800-0000-6c8e-d538970a0000 pid=2711 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=7ccfc5cc-1800-0000-6c8e-d538970a0000 pid=2711 clone guuid=3446c6d2-1800-0000-6c8e-d538a80a0000 pid=2728 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=3446c6d2-1800-0000-6c8e-d538a80a0000 pid=2728 clone guuid=6044cbd8-1800-0000-6c8e-d538b80a0000 pid=2744 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=6044cbd8-1800-0000-6c8e-d538b80a0000 pid=2744 clone guuid=7da3d0de-1800-0000-6c8e-d538c40a0000 pid=2756 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=7da3d0de-1800-0000-6c8e-d538c40a0000 pid=2756 clone guuid=e069d4e4-1800-0000-6c8e-d538cf0a0000 pid=2767 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=e069d4e4-1800-0000-6c8e-d538cf0a0000 pid=2767 clone guuid=e03adfea-1800-0000-6c8e-d538d70a0000 pid=2775 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=e03adfea-1800-0000-6c8e-d538d70a0000 pid=2775 clone guuid=c89debf0-1800-0000-6c8e-d538df0a0000 pid=2783 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=c89debf0-1800-0000-6c8e-d538df0a0000 pid=2783 clone guuid=7fd6f0f6-1800-0000-6c8e-d538e70a0000 pid=2791 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=7fd6f0f6-1800-0000-6c8e-d538e70a0000 pid=2791 clone guuid=f0cef0fc-1800-0000-6c8e-d538f40a0000 pid=2804 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=f0cef0fc-1800-0000-6c8e-d538f40a0000 pid=2804 clone guuid=f7def202-1900-0000-6c8e-d538fc0a0000 pid=2812 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=f7def202-1900-0000-6c8e-d538fc0a0000 pid=2812 clone guuid=9219f308-1900-0000-6c8e-d538050b0000 pid=2821 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=9219f308-1900-0000-6c8e-d538050b0000 pid=2821 clone guuid=126cf40e-1900-0000-6c8e-d538110b0000 pid=2833 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=126cf40e-1900-0000-6c8e-d538110b0000 pid=2833 clone guuid=7e6cf914-1900-0000-6c8e-d5381d0b0000 pid=2845 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=7e6cf914-1900-0000-6c8e-d5381d0b0000 pid=2845 clone guuid=3848f91a-1900-0000-6c8e-d5382a0b0000 pid=2858 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=3848f91a-1900-0000-6c8e-d5382a0b0000 pid=2858 clone guuid=9a8efa20-1900-0000-6c8e-d538370b0000 pid=2871 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=9a8efa20-1900-0000-6c8e-d538370b0000 pid=2871 clone guuid=43fbfd26-1900-0000-6c8e-d538490b0000 pid=2889 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=43fbfd26-1900-0000-6c8e-d538490b0000 pid=2889 clone guuid=98e4fc2c-1900-0000-6c8e-d5385c0b0000 pid=2908 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=98e4fc2c-1900-0000-6c8e-d5385c0b0000 pid=2908 clone guuid=4b25fd32-1900-0000-6c8e-d538690b0000 pid=2921 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=4b25fd32-1900-0000-6c8e-d538690b0000 pid=2921 clone guuid=306f0039-1900-0000-6c8e-d538770b0000 pid=2935 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=306f0039-1900-0000-6c8e-d538770b0000 pid=2935 clone guuid=1743083f-1900-0000-6c8e-d5387f0b0000 pid=2943 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=1743083f-1900-0000-6c8e-d5387f0b0000 pid=2943 clone guuid=da720d45-1900-0000-6c8e-d5388a0b0000 pid=2954 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=da720d45-1900-0000-6c8e-d5388a0b0000 pid=2954 clone guuid=e9510e4b-1900-0000-6c8e-d538960b0000 pid=2966 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=e9510e4b-1900-0000-6c8e-d538960b0000 pid=2966 clone guuid=05e40f51-1900-0000-6c8e-d5389e0b0000 pid=2974 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=05e40f51-1900-0000-6c8e-d5389e0b0000 pid=2974 clone guuid=92591357-1900-0000-6c8e-d538a70b0000 pid=2983 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=92591357-1900-0000-6c8e-d538a70b0000 pid=2983 clone guuid=a8e7145d-1900-0000-6c8e-d538af0b0000 pid=2991 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=a8e7145d-1900-0000-6c8e-d538af0b0000 pid=2991 clone guuid=de962163-1900-0000-6c8e-d538b90b0000 pid=3001 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=de962163-1900-0000-6c8e-d538b90b0000 pid=3001 clone guuid=422d2a69-1900-0000-6c8e-d538c40b0000 pid=3012 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=422d2a69-1900-0000-6c8e-d538c40b0000 pid=3012 clone guuid=df73326f-1900-0000-6c8e-d538ce0b0000 pid=3022 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=df73326f-1900-0000-6c8e-d538ce0b0000 pid=3022 clone guuid=4e7a3b75-1900-0000-6c8e-d538d70b0000 pid=3031 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=4e7a3b75-1900-0000-6c8e-d538d70b0000 pid=3031 clone guuid=eaca3a7b-1900-0000-6c8e-d538e40b0000 pid=3044 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=eaca3a7b-1900-0000-6c8e-d538e40b0000 pid=3044 clone guuid=ccbe3b81-1900-0000-6c8e-d538f10b0000 pid=3057 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=ccbe3b81-1900-0000-6c8e-d538f10b0000 pid=3057 clone guuid=bd9d3e87-1900-0000-6c8e-d538ff0b0000 pid=3071 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=bd9d3e87-1900-0000-6c8e-d538ff0b0000 pid=3071 clone guuid=d51b438d-1900-0000-6c8e-d538100c0000 pid=3088 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=d51b438d-1900-0000-6c8e-d538100c0000 pid=3088 clone guuid=e15f4893-1900-0000-6c8e-d538210c0000 pid=3105 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=e15f4893-1900-0000-6c8e-d538210c0000 pid=3105 clone guuid=1dd34799-1900-0000-6c8e-d538310c0000 pid=3121 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=1dd34799-1900-0000-6c8e-d538310c0000 pid=3121 clone guuid=9a61499f-1900-0000-6c8e-d538410c0000 pid=3137 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=9a61499f-1900-0000-6c8e-d538410c0000 pid=3137 clone guuid=76f74ea5-1900-0000-6c8e-d5384f0c0000 pid=3151 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=76f74ea5-1900-0000-6c8e-d5384f0c0000 pid=3151 clone guuid=b0de56ab-1900-0000-6c8e-d5385e0c0000 pid=3166 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=b0de56ab-1900-0000-6c8e-d5385e0c0000 pid=3166 clone guuid=e57a58b1-1900-0000-6c8e-d5386f0c0000 pid=3183 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=e57a58b1-1900-0000-6c8e-d5386f0c0000 pid=3183 clone guuid=644759b7-1900-0000-6c8e-d5387a0c0000 pid=3194 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=644759b7-1900-0000-6c8e-d5387a0c0000 pid=3194 clone guuid=a9155dbd-1900-0000-6c8e-d538870c0000 pid=3207 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=a9155dbd-1900-0000-6c8e-d538870c0000 pid=3207 clone guuid=e02463c3-1900-0000-6c8e-d538920c0000 pid=3218 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=e02463c3-1900-0000-6c8e-d538920c0000 pid=3218 clone guuid=1a7261c9-1900-0000-6c8e-d5389c0c0000 pid=3228 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=1a7261c9-1900-0000-6c8e-d5389c0c0000 pid=3228 clone guuid=46ad5fcf-1900-0000-6c8e-d538aa0c0000 pid=3242 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=46ad5fcf-1900-0000-6c8e-d538aa0c0000 pid=3242 clone guuid=bcee61d5-1900-0000-6c8e-d538b80c0000 pid=3256 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=bcee61d5-1900-0000-6c8e-d538b80c0000 pid=3256 clone guuid=2b3465db-1900-0000-6c8e-d538be0c0000 pid=3262 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=2b3465db-1900-0000-6c8e-d538be0c0000 pid=3262 clone guuid=247172e1-1900-0000-6c8e-d538bf0c0000 pid=3263 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=247172e1-1900-0000-6c8e-d538bf0c0000 pid=3263 clone guuid=fdf679e7-1900-0000-6c8e-d538ca0c0000 pid=3274 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=fdf679e7-1900-0000-6c8e-d538ca0c0000 pid=3274 clone guuid=f1fa7ded-1900-0000-6c8e-d538d60c0000 pid=3286 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=f1fa7ded-1900-0000-6c8e-d538d60c0000 pid=3286 clone guuid=1d5391f3-1900-0000-6c8e-d538d80c0000 pid=3288 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=1d5391f3-1900-0000-6c8e-d538d80c0000 pid=3288 clone guuid=a2f991f9-1900-0000-6c8e-d538e40c0000 pid=3300 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=a2f991f9-1900-0000-6c8e-d538e40c0000 pid=3300 clone guuid=06fa99ff-1900-0000-6c8e-d538ee0c0000 pid=3310 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=06fa99ff-1900-0000-6c8e-d538ee0c0000 pid=3310 clone guuid=f9f09c05-1a00-0000-6c8e-d538f90c0000 pid=3321 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=f9f09c05-1a00-0000-6c8e-d538f90c0000 pid=3321 clone guuid=34d39f0b-1a00-0000-6c8e-d538070d0000 pid=3335 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=34d39f0b-1a00-0000-6c8e-d538070d0000 pid=3335 clone guuid=f0829e11-1a00-0000-6c8e-d538150d0000 pid=3349 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=f0829e11-1a00-0000-6c8e-d538150d0000 pid=3349 clone guuid=c5ffa217-1a00-0000-6c8e-d5381f0d0000 pid=3359 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=c5ffa217-1a00-0000-6c8e-d5381f0d0000 pid=3359 clone guuid=7a0ca21d-1a00-0000-6c8e-d538290d0000 pid=3369 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=7a0ca21d-1a00-0000-6c8e-d538290d0000 pid=3369 clone guuid=10a3a323-1a00-0000-6c8e-d538350d0000 pid=3381 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=10a3a323-1a00-0000-6c8e-d538350d0000 pid=3381 clone guuid=ec85ab29-1a00-0000-6c8e-d5383c0d0000 pid=3388 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=ec85ab29-1a00-0000-6c8e-d5383c0d0000 pid=3388 clone guuid=ae1ab12f-1a00-0000-6c8e-d5383e0d0000 pid=3390 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=ae1ab12f-1a00-0000-6c8e-d5383e0d0000 pid=3390 clone guuid=5e48b735-1a00-0000-6c8e-d5384b0d0000 pid=3403 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=5e48b735-1a00-0000-6c8e-d5384b0d0000 pid=3403 clone guuid=6c80ba3b-1a00-0000-6c8e-d538520d0000 pid=3410 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=6c80ba3b-1a00-0000-6c8e-d538520d0000 pid=3410 clone guuid=0456bf41-1a00-0000-6c8e-d5385b0d0000 pid=3419 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=0456bf41-1a00-0000-6c8e-d5385b0d0000 pid=3419 clone guuid=efc2c247-1a00-0000-6c8e-d538660d0000 pid=3430 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=efc2c247-1a00-0000-6c8e-d538660d0000 pid=3430 clone guuid=40c6cd4d-1a00-0000-6c8e-d538700d0000 pid=3440 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=40c6cd4d-1a00-0000-6c8e-d538700d0000 pid=3440 clone guuid=a600d353-1a00-0000-6c8e-d5387e0d0000 pid=3454 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=a600d353-1a00-0000-6c8e-d5387e0d0000 pid=3454 clone guuid=b6bad959-1a00-0000-6c8e-d538890d0000 pid=3465 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=b6bad959-1a00-0000-6c8e-d538890d0000 pid=3465 clone guuid=65cdde5f-1a00-0000-6c8e-d538980d0000 pid=3480 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=65cdde5f-1a00-0000-6c8e-d538980d0000 pid=3480 clone guuid=946feb65-1a00-0000-6c8e-d538a60d0000 pid=3494 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=946feb65-1a00-0000-6c8e-d538a60d0000 pid=3494 clone guuid=033ef76b-1a00-0000-6c8e-d538b30d0000 pid=3507 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=033ef76b-1a00-0000-6c8e-d538b30d0000 pid=3507 clone guuid=f967fc71-1a00-0000-6c8e-d538be0d0000 pid=3518 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=f967fc71-1a00-0000-6c8e-d538be0d0000 pid=3518 clone guuid=822f0978-1a00-0000-6c8e-d538cb0d0000 pid=3531 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=822f0978-1a00-0000-6c8e-d538cb0d0000 pid=3531 clone guuid=1262077e-1a00-0000-6c8e-d538d90d0000 pid=3545 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=1262077e-1a00-0000-6c8e-d538d90d0000 pid=3545 clone guuid=88140984-1a00-0000-6c8e-d538e90d0000 pid=3561 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=88140984-1a00-0000-6c8e-d538e90d0000 pid=3561 clone guuid=2b6f098a-1a00-0000-6c8e-d538ef0d0000 pid=3567 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=2b6f098a-1a00-0000-6c8e-d538ef0d0000 pid=3567 clone guuid=bfde0a90-1a00-0000-6c8e-d538fb0d0000 pid=3579 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=bfde0a90-1a00-0000-6c8e-d538fb0d0000 pid=3579 clone guuid=73d70996-1a00-0000-6c8e-d538040e0000 pid=3588 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=73d70996-1a00-0000-6c8e-d538040e0000 pid=3588 clone guuid=24760c9c-1a00-0000-6c8e-d538110e0000 pid=3601 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=24760c9c-1a00-0000-6c8e-d538110e0000 pid=3601 clone guuid=f37b17a2-1a00-0000-6c8e-d538180e0000 pid=3608 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=f37b17a2-1a00-0000-6c8e-d538180e0000 pid=3608 clone guuid=13301da8-1a00-0000-6c8e-d538280e0000 pid=3624 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=13301da8-1a00-0000-6c8e-d538280e0000 pid=3624 clone guuid=07611fae-1a00-0000-6c8e-d5383c0e0000 pid=3644 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=07611fae-1a00-0000-6c8e-d5383c0e0000 pid=3644 clone guuid=731620b4-1a00-0000-6c8e-d5384a0e0000 pid=3658 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=731620b4-1a00-0000-6c8e-d5384a0e0000 pid=3658 clone guuid=069f2cba-1a00-0000-6c8e-d538570e0000 pid=3671 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=069f2cba-1a00-0000-6c8e-d538570e0000 pid=3671 clone guuid=d4fe36c0-1a00-0000-6c8e-d538630e0000 pid=3683 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=d4fe36c0-1a00-0000-6c8e-d538630e0000 pid=3683 clone guuid=35bf3dc6-1a00-0000-6c8e-d5386b0e0000 pid=3691 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=35bf3dc6-1a00-0000-6c8e-d5386b0e0000 pid=3691 clone guuid=5e7b40cc-1a00-0000-6c8e-d5387a0e0000 pid=3706 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=5e7b40cc-1a00-0000-6c8e-d5387a0e0000 pid=3706 clone guuid=64d048d2-1a00-0000-6c8e-d5388b0e0000 pid=3723 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=64d048d2-1a00-0000-6c8e-d5388b0e0000 pid=3723 clone guuid=2e9552d8-1a00-0000-6c8e-d538970e0000 pid=3735 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=2e9552d8-1a00-0000-6c8e-d538970e0000 pid=3735 clone guuid=5ab854de-1a00-0000-6c8e-d538a60e0000 pid=3750 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=5ab854de-1a00-0000-6c8e-d538a60e0000 pid=3750 clone guuid=c7bd5ae4-1a00-0000-6c8e-d538a90e0000 pid=3753 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=c7bd5ae4-1a00-0000-6c8e-d538a90e0000 pid=3753 clone guuid=f8005dea-1a00-0000-6c8e-d538b00e0000 pid=3760 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=f8005dea-1a00-0000-6c8e-d538b00e0000 pid=3760 clone guuid=dde25cf0-1a00-0000-6c8e-d538bd0e0000 pid=3773 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=dde25cf0-1a00-0000-6c8e-d538bd0e0000 pid=3773 clone guuid=5b3366f6-1a00-0000-6c8e-d538cf0e0000 pid=3791 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=5b3366f6-1a00-0000-6c8e-d538cf0e0000 pid=3791 clone guuid=f9786afc-1a00-0000-6c8e-d538e90e0000 pid=3817 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=f9786afc-1a00-0000-6c8e-d538e90e0000 pid=3817 clone guuid=abf46e02-1b00-0000-6c8e-d538000f0000 pid=3840 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=abf46e02-1b00-0000-6c8e-d538000f0000 pid=3840 clone guuid=96666e08-1b00-0000-6c8e-d538100f0000 pid=3856 /tmp/sample.bin guuid=19c1a6b4-1800-0000-6c8e-d538410a0000 pid=2625->guuid=96666e08-1b00-0000-6c8e-d538100f0000 pid=3856 clone
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj
Score:
60 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample reads /proc/mounts (often used for finding a writable filesystem)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1857416 Sample: sys64.i486.elf Startdate: 26/01/2026 Architecture: LINUX Score: 60 25 trx.mytokenpocket.vip 2->25 27 204.76.203.49, 56822, 8033 UNASSIGNED Reserved 2->27 29 7 other IPs or domains 2->29 31 Malicious sample detected (through community Yara rule) 2->31 33 Multi AV Scanner detection for submitted file 2->33 8 sys64.i486.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 sys64.i486.elf 8->14         started        signatures6 35 Sample reads /proc/mounts (often used for finding a writable filesystem) 14->35 17 sys64.i486.elf 14->17         started        19 sys64.i486.elf 14->19         started        21 sys64.i486.elf 14->21         started        23 97 other processes 14->23 process7
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Changes its process name
Unexpected DNS network traffic destination
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Mirai_3a56423b
Author:Elastic Security
Rule name:SUSP_XORed_Mozilla_Oct19
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf cbb4d1aecc65903e67da787d93724125bf17babef31faa7bddea632c74da9b4e

(this sample)

  
Delivery method
Distributed via web download

Comments