MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d533a5d8a45fb3fcb5d02a46478cd5d56c64f80506d91bae938eb3f6cdc68456. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: d533a5d8a45fb3fcb5d02a46478cd5d56c64f80506d91bae938eb3f6cdc68456
SHA3-384 hash: 5ff747d650dee77e6010a657e024f1d478b6f99d9064b86c2c702916b7fd535796270cc7485c22d4b8dfaa3e07365de3
SHA1 hash: 53bae50dc1deb7d66071543d58353e4c949fdbd1
MD5 hash: 4209141935070d53983ef8c923b14c7c
humanhash: dakota-seven-november-maine
File name:agetty
Download: download sample
Signature Mirai
File size:108'048 bytes
First seen:2025-07-18 03:33:20 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:Uwz3CdNA6qPsLXHgA1IFtcTMYM5pOtLgngGcvPK:UwrItqPsDHDq2TMY8LnPc6
TLSH T1F9B35D22FA66092BC0D4657A61F34330F1F3539B54788A1B7EA30E8DBF646043567BE6
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
19
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated
Status:
terminated
Behavior Graph:
%3 guuid=fce6dcff-1800-0000-af5b-6af055140000 pid=5205 /usr/bin/sudo guuid=3ea66d01-1900-0000-af5b-6af056140000 pid=5206 /tmp/sample.bin guuid=fce6dcff-1800-0000-af5b-6af055140000 pid=5205->guuid=3ea66d01-1900-0000-af5b-6af056140000 pid=5206 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
56 / 100
Signature
Connects to many ports of the same IP (likely port scanning)
Multi AV Scanner detection for submitted file
Terminates several processes with shell command 'killall'
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1739331 Sample: agetty.elf Startdate: 18/07/2025 Architecture: LINUX Score: 56 45 138.221.100.62, 23 WORLDBANKUS Switzerland 2->45 47 64.232.31.210 WINDSTREAMUS United States 2->47 49 98 other IPs or domains 2->49 51 Multi AV Scanner detection for submitted file 2->51 53 Connects to many ports of the same IP (likely port scanning) 2->53 10 agetty.elf 2->10         started        12 dash rm 2->12         started        14 dash rm 2->14         started        signatures3 process4 process5 16 agetty.elf 10->16         started        process6 18 agetty.elf 16->18         started        20 agetty.elf 16->20         started        process7 22 agetty.elf sh 18->22         started        24 agetty.elf sh 18->24         started        26 agetty.elf sh 18->26         started        28 127 other processes 18->28 process8 30 sh killall 22->30         started        33 sh killall 24->33         started        35 sh killall 26->35         started        37 sh killall 28->37         started        39 sh killall 28->39         started        41 sh killall 28->41         started        43 124 other processes 28->43 signatures9 55 Terminates several processes with shell command 'killall' 30->55
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-07-18 03:34:14 UTC
File Type:
ELF32 Big (Exe)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf d533a5d8a45fb3fcb5d02a46478cd5d56c64f80506d91bae938eb3f6cdc68456

(this sample)

  
Delivery method
Distributed via web download

Comments