MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc2a1a46c9f2849eb08496416d5d040b43db95ec52ff5fc49a91ca629dccc756. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 19 File information Comments

SHA256 hash: dc2a1a46c9f2849eb08496416d5d040b43db95ec52ff5fc49a91ca629dccc756
SHA3-384 hash: 1a1a80c62336ac047ba1a4060324260a7241fe64cf85d9f459b6a41524af4f60970e858273f27ed5302171587b754f1e
SHA1 hash: 9007b83e14c252b3e75d2f95fbf53efbadc347cf
MD5 hash: 34d6522417db64211bcf226d81aebc2b
humanhash: minnesota-tennis-sweet-india
File name:x86_64
Download: download sample
Signature Mirai
File size:180'200 bytes
First seen:2026-08-20 02:07:38 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:uFEV5h/EZ9eX9jhYCMtUGI1Zw41GWLsGBQGA4/wzx0quPVMnoOK:15pEg9Rbq21lmoOK
TLSH T11E045B1775C188FDC8D5C1B44BAFE235EA32F0591138B60F27D8AE262E4DF61AB2D650
telfhash t1c961ad702d9938a911e76736738be9d8fc7205214ed675e69e2368d0ce877cc0ea3016
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 a0a2beb18f9334564860acef1a8d9754dfcd2e94cb90cd878308f12cb5bdf264
File size (compressed) :71'308 bytes
File size (de-compressed) :180'200 bytes
Format:linux/amd64
Packed file: a0a2beb18f9334564860acef1a8d9754dfcd2e94cb90cd878308f12cb5bdf264

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Kills processes
Deletes a file
Launching a process
Locks files
Runs as daemon
Sets a file as executable
Creating a file
Substitutes an application name
Kills critical processes
Deleting of the original file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm anti-vm bash dropper lolbin mirai
Status:
terminated
Behavior Graph:
%3 guuid=5549d91d-1900-0000-109e-d4a458080000 pid=2136 /usr/bin/sudo guuid=7466d320-1900-0000-109e-d4a45e080000 pid=2142 /tmp/sample.bin guuid=5549d91d-1900-0000-109e-d4a458080000 pid=2136->guuid=7466d320-1900-0000-109e-d4a45e080000 pid=2142 execve guuid=91ea6a22-1900-0000-109e-d4a45f080000 pid=2143 /tmp/sample.bin zombie guuid=7466d320-1900-0000-109e-d4a45e080000 pid=2142->guuid=91ea6a22-1900-0000-109e-d4a45f080000 pid=2143 clone guuid=bf75ad22-1900-0000-109e-d4a460080000 pid=2144 /tmp/sample.bin delete-file net send-data write-file zombie guuid=91ea6a22-1900-0000-109e-d4a45f080000 pid=2143->guuid=bf75ad22-1900-0000-109e-d4a460080000 pid=2144 clone 43107d06-e1b8-559a-8721-01616c7cb4c1 83.168.69.141:9482 guuid=bf75ad22-1900-0000-109e-d4a460080000 pid=2144->43107d06-e1b8-559a-8721-01616c7cb4c1 send: 303B guuid=9392fd22-1900-0000-109e-d4a461080000 pid=2145 /tmp/sample.bin guuid=bf75ad22-1900-0000-109e-d4a460080000 pid=2144->guuid=9392fd22-1900-0000-109e-d4a461080000 pid=2145 clone guuid=d0cb1f23-1900-0000-109e-d4a463080000 pid=2147 /tmp/sample.bin guuid=bf75ad22-1900-0000-109e-d4a460080000 pid=2144->guuid=d0cb1f23-1900-0000-109e-d4a463080000 pid=2147 clone guuid=86213e23-1900-0000-109e-d4a464080000 pid=2148 /usr/sbin/xtables-nft-multi guuid=bf75ad22-1900-0000-109e-d4a460080000 pid=2144->guuid=86213e23-1900-0000-109e-d4a464080000 pid=2148 execve guuid=e733332e-1900-0000-109e-d4a47b080000 pid=2171 /usr/sbin/xtables-nft-multi guuid=bf75ad22-1900-0000-109e-d4a460080000 pid=2144->guuid=e733332e-1900-0000-109e-d4a47b080000 pid=2171 execve guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173 /tmp/sample.bin delete-file write-config write-file guuid=bf75ad22-1900-0000-109e-d4a460080000 pid=2144->guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173 clone guuid=383a0b23-1900-0000-109e-d4a462080000 pid=2146 /tmp/sample.bin guuid=9392fd22-1900-0000-109e-d4a461080000 pid=2145->guuid=383a0b23-1900-0000-109e-d4a462080000 pid=2146 clone guuid=e8a73033-1900-0000-109e-d4a485080000 pid=2181 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=e8a73033-1900-0000-109e-d4a485080000 pid=2181 execve guuid=f0718e33-1900-0000-109e-d4a486080000 pid=2182 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=f0718e33-1900-0000-109e-d4a486080000 pid=2182 execve guuid=d67f0734-1900-0000-109e-d4a489080000 pid=2185 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=d67f0734-1900-0000-109e-d4a489080000 pid=2185 execve guuid=65467934-1900-0000-109e-d4a48b080000 pid=2187 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=65467934-1900-0000-109e-d4a48b080000 pid=2187 execve guuid=b5722b35-1900-0000-109e-d4a48d080000 pid=2189 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=b5722b35-1900-0000-109e-d4a48d080000 pid=2189 execve guuid=0df9033d-1900-0000-109e-d4a49d080000 pid=2205 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=0df9033d-1900-0000-109e-d4a49d080000 pid=2205 execve guuid=1dc5713d-1900-0000-109e-d4a49f080000 pid=2207 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=1dc5713d-1900-0000-109e-d4a49f080000 pid=2207 execve guuid=753f133e-1900-0000-109e-d4a4a0080000 pid=2208 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=753f133e-1900-0000-109e-d4a4a0080000 pid=2208 execve guuid=89a4833e-1900-0000-109e-d4a4a2080000 pid=2210 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=89a4833e-1900-0000-109e-d4a4a2080000 pid=2210 execve guuid=de102d3f-1900-0000-109e-d4a4a5080000 pid=2213 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=de102d3f-1900-0000-109e-d4a4a5080000 pid=2213 execve guuid=ebb8b23f-1900-0000-109e-d4a4a6080000 pid=2214 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=ebb8b23f-1900-0000-109e-d4a4a6080000 pid=2214 execve guuid=43816840-1900-0000-109e-d4a4a9080000 pid=2217 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=43816840-1900-0000-109e-d4a4a9080000 pid=2217 execve guuid=dfee0441-1900-0000-109e-d4a4ac080000 pid=2220 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=dfee0441-1900-0000-109e-d4a4ac080000 pid=2220 execve guuid=4d957541-1900-0000-109e-d4a4ae080000 pid=2222 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=4d957541-1900-0000-109e-d4a4ae080000 pid=2222 execve guuid=ac1a4742-1900-0000-109e-d4a4b0080000 pid=2224 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=ac1a4742-1900-0000-109e-d4a4b0080000 pid=2224 execve guuid=79e15158-1900-0000-109e-d4a4d7080000 pid=2263 /usr/bin/systemctl guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=79e15158-1900-0000-109e-d4a4d7080000 pid=2263 execve guuid=a4c5e8ae-1900-0000-109e-d4a46a090000 pid=2410 /usr/bin/systemctl guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=a4c5e8ae-1900-0000-109e-d4a46a090000 pid=2410 execve guuid=5d7ccae7-1900-0000-109e-d4a4d9090000 pid=2521 /tmp/sample.bin write-file guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=5d7ccae7-1900-0000-109e-d4a4d9090000 pid=2521 clone guuid=67cabff5-1900-0000-109e-d4a4eb090000 pid=2539 /usr/sbin/xtables-nft-multi guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=67cabff5-1900-0000-109e-d4a4eb090000 pid=2539 execve guuid=57e558f6-1900-0000-109e-d4a4ec090000 pid=2540 /tmp/sample.bin write-file guuid=7bb8922e-1900-0000-109e-d4a47d080000 pid=2173->guuid=57e558f6-1900-0000-109e-d4a4ec090000 pid=2540 clone
Threat name:
Linux.Trojan.FlyLegitBot
Status:
Malicious
First seen:
2026-08-20 02:10:14 UTC
AV detection:
13 of 38 (34.21%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
Changes its process name
Checks CPU configuration
Enumerates running processes
Deletes itself
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_Mirai
Author:NDA0E
Description:Detects multiple Mirai variants
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:has_telegram_urls
Author:Aaron DeVera<aaron@backchannel.re>
Description:Detects Telegram URLs
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
Rule name:test_rule_vldslv
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
Rule name:virustotal
Author:Tracel
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf dc2a1a46c9f2849eb08496416d5d040b43db95ec52ff5fc49a91ca629dccc756

(this sample)

  
Delivery method
Distributed via web download

Comments