MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d9076dc040c207e5ae168b3c38357f04db9aa5c553ee54f415a7c983df4ffeff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 4


Intelligence 4 IOCs YARA 3 File information Comments

SHA256 hash: d9076dc040c207e5ae168b3c38357f04db9aa5c553ee54f415a7c983df4ffeff
SHA3-384 hash: 506994676f8e3a23d62f1af244a0131d0db9733876c172c790c706b53c1dbb407a6448328f3183bcd4af6c6b126cb429
SHA1 hash: 6cb36ef1ba4d2746c48117fa4822b46b2e2246ba
MD5 hash: 3caddc6ad3a0587562f1aa0b6d942d03
humanhash: beer-lima-eighteen-jersey
File name:putita.m68k
Download: download sample
Signature Mirai
File size:134'392 bytes
First seen:2026-08-25 14:02:17 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 3072:mmVdc92GUspp9XIpdlrEy5NHnyQWTya+9IZgi12vVhfLLjBXoQ:3cExspU6ycTf+Wi3vVhfX14Q
TLSH T10ED37C91B10C3E6EE2C72D3EC20A17175C1D9F49AC02495140E9BA475AFB9E72F3A5CB
telfhash t165d001f2a70fa282034ecbcd83d6330d851dd046012bef17fe80003e818841c252608f
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
gcc masquerade
Status:
terminated
Behavior Graph:
%3 guuid=61134c3b-1b00-0000-a3ba-8886f3080000 pid=2291 /usr/bin/sudo guuid=505f1c3d-1b00-0000-a3ba-8886f8080000 pid=2296 /tmp/sample.bin guuid=61134c3b-1b00-0000-a3ba-8886f3080000 pid=2291->guuid=505f1c3d-1b00-0000-a3ba-8886f8080000 pid=2296 execve
Gathering data
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
Rule name:ELF_Mirai
Author:NDA0E
Description:Detects multiple Mirai variants
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf d9076dc040c207e5ae168b3c38357f04db9aa5c553ee54f415a7c983df4ffeff

(this sample)

  
Delivery method
Distributed via web download

Comments