MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e1f506c9def99b6f1333d312a0ba8f43d6ab44b83c8bc45da37d66ccf00fef7a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 4 File information Comments

SHA256 hash: e1f506c9def99b6f1333d312a0ba8f43d6ab44b83c8bc45da37d66ccf00fef7a
SHA3-384 hash: c06e94e0444166b988311cccbf185d1954a90817f4b44f2de7d4e672f09d719327f9afa23b87e3b6d8e3e373ee025593
SHA1 hash: 22316ca93f8e7120e907705c4fd0f4313fdb4e0d
MD5 hash: bf67c1cfe948bfa65094c2f8aef8892e
humanhash: arizona-earth-pip-california
File name:x86_64
Download: download sample
Signature Mirai
File size:149'560 bytes
First seen:2026-08-10 17:41:23 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 3072:a9PscaJqypQp/zwgQYrYZBTI68lpIERFfa+lbPnU:uyvpAbwVI6sjl/bPU
TLSH T1FBE34B13A58084FDC49AD2748B9FD137FB32F89A1334774F2B906E712D36E616B19A81
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 689a56e6252bfcae50ec716f3b736ebc1a21bf6a47c152e0a59ab41e21151aaf
File size (compressed) :76'920 bytes
File size (de-compressed) :149'560 bytes
Format:linux/amd64
Packed file: 689a56e6252bfcae50ec716f3b736ebc1a21bf6a47c152e0a59ab41e21151aaf

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Kills processes
Launching a process
Manages services
Runs as daemon
Changes access rights for a written file
Opens a port
Receives data from a server
Changes the time when the file was created, accessed, or modified
Connection attempt
DNS request
Creating a file
Creating a file in the %temp% directory
Sets a written file as executable
Locks files
Sends data to a server
Changes access rights for a file
Substitutes an application name
Creates or modifies files in /cron to set up autorun
Creates or modifies files in /init.d to set up autorun
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
expand lolbin
Status:
terminated
Behavior Graph:
%3 guuid=7ecba1ae-1a00-0000-10a5-1c3e5e0a0000 pid=2654 /usr/bin/sudo guuid=4092a1b2-1a00-0000-10a5-1c3e640a0000 pid=2660 /tmp/sample.bin dns net send-data write-file guuid=7ecba1ae-1a00-0000-10a5-1c3e5e0a0000 pid=2654->guuid=4092a1b2-1a00-0000-10a5-1c3e640a0000 pid=2660 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=4092a1b2-1a00-0000-10a5-1c3e640a0000 pid=2660->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 31B b22bb4dc-07fc-50c6-aa61-19e0dd703acf iloveboats.st:4444 guuid=4092a1b2-1a00-0000-10a5-1c3e640a0000 pid=2660->b22bb4dc-07fc-50c6-aa61-19e0dd703acf con guuid=dab77cb6-1a00-0000-10a5-1c3e6a0a0000 pid=2666 /usr/bin/dash guuid=4092a1b2-1a00-0000-10a5-1c3e640a0000 pid=2660->guuid=dab77cb6-1a00-0000-10a5-1c3e6a0a0000 pid=2666 execve guuid=2d4456b7-1a00-0000-10a5-1c3e6f0a0000 pid=2671 /tmp/sample.bin net send-data write-config write-file zombie guuid=4092a1b2-1a00-0000-10a5-1c3e640a0000 pid=2660->guuid=2d4456b7-1a00-0000-10a5-1c3e6f0a0000 pid=2671 clone guuid=fbc8b9b6-1a00-0000-10a5-1c3e6c0a0000 pid=2668 /usr/bin/id guuid=dab77cb6-1a00-0000-10a5-1c3e6a0a0000 pid=2666->guuid=fbc8b9b6-1a00-0000-10a5-1c3e6c0a0000 pid=2668 execve guuid=2d4456b7-1a00-0000-10a5-1c3e6f0a0000 pid=2671->b22bb4dc-07fc-50c6-aa61-19e0dd703acf send: 3652B guuid=d67790b7-1a00-0000-10a5-1c3e700a0000 pid=2672 /usr/bin/dash guuid=2d4456b7-1a00-0000-10a5-1c3e6f0a0000 pid=2671->guuid=d67790b7-1a00-0000-10a5-1c3e700a0000 pid=2672 execve guuid=6807bb00-1b00-0000-10a5-1c3ecd0a0000 pid=2765 /usr/bin/dash guuid=2d4456b7-1a00-0000-10a5-1c3e6f0a0000 pid=2671->guuid=6807bb00-1b00-0000-10a5-1c3ecd0a0000 pid=2765 execve guuid=4d22ba01-1b00-0000-10a5-1c3ed60a0000 pid=2774 /tmp/sample.bin guuid=2d4456b7-1a00-0000-10a5-1c3e6f0a0000 pid=2671->guuid=4d22ba01-1b00-0000-10a5-1c3ed60a0000 pid=2774 clone guuid=df66be01-1b00-0000-10a5-1c3ed70a0000 pid=2775 /tmp/sample.bin net send-data guuid=2d4456b7-1a00-0000-10a5-1c3e6f0a0000 pid=2671->guuid=df66be01-1b00-0000-10a5-1c3ed70a0000 pid=2775 clone guuid=4b35c801-1b00-0000-10a5-1c3ed80a0000 pid=2776 /tmp/sample.bin guuid=2d4456b7-1a00-0000-10a5-1c3e6f0a0000 pid=2671->guuid=4b35c801-1b00-0000-10a5-1c3ed80a0000 pid=2776 clone guuid=0e7bcd01-1b00-0000-10a5-1c3ed90a0000 pid=2777 /tmp/sample.bin guuid=2d4456b7-1a00-0000-10a5-1c3e6f0a0000 pid=2671->guuid=0e7bcd01-1b00-0000-10a5-1c3ed90a0000 pid=2777 clone guuid=b898d101-1b00-0000-10a5-1c3eda0a0000 pid=2778 /tmp/sample.bin guuid=2d4456b7-1a00-0000-10a5-1c3e6f0a0000 pid=2671->guuid=b898d101-1b00-0000-10a5-1c3eda0a0000 pid=2778 clone guuid=9b728db8-1a00-0000-10a5-1c3e730a0000 pid=2675 /usr/bin/systemctl guuid=d67790b7-1a00-0000-10a5-1c3e700a0000 pid=2672->guuid=9b728db8-1a00-0000-10a5-1c3e730a0000 pid=2675 execve guuid=e53af900-1b00-0000-10a5-1c3ecf0a0000 pid=2767 /usr/bin/dash guuid=6807bb00-1b00-0000-10a5-1c3ecd0a0000 pid=2765->guuid=e53af900-1b00-0000-10a5-1c3ecf0a0000 pid=2767 clone guuid=951b9201-1b00-0000-10a5-1c3ed30a0000 pid=2771 /usr/bin/dash guuid=6807bb00-1b00-0000-10a5-1c3ecd0a0000 pid=2765->guuid=951b9201-1b00-0000-10a5-1c3ed30a0000 pid=2771 clone guuid=33579701-1b00-0000-10a5-1c3ed40a0000 pid=2772 /usr/bin/dash guuid=6807bb00-1b00-0000-10a5-1c3ecd0a0000 pid=2765->guuid=33579701-1b00-0000-10a5-1c3ed40a0000 pid=2772 clone guuid=a11e0501-1b00-0000-10a5-1c3ed00a0000 pid=2768 /usr/bin/dash guuid=e53af900-1b00-0000-10a5-1c3ecf0a0000 pid=2767->guuid=a11e0501-1b00-0000-10a5-1c3ed00a0000 pid=2768 clone guuid=441e0b01-1b00-0000-10a5-1c3ed10a0000 pid=2769 /usr/bin/grep guuid=e53af900-1b00-0000-10a5-1c3ecf0a0000 pid=2767->guuid=441e0b01-1b00-0000-10a5-1c3ed10a0000 pid=2769 execve 2c327a97-612e-51d4-a753-91523bef871d iloveboats.st:4821 guuid=df66be01-1b00-0000-10a5-1c3ed70a0000 pid=2775->2c327a97-612e-51d4-a753-91523bef871d send: 16B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-08-10 17:45:51 UTC
File Type:
ELF64 Little (SO)
AV detection:
9 of 36 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Creates/modifies Cron job
Enumerates running processes
Looks up external IP address via web service
Modifies rc script
Modifies systemd
Write file to user bin folder
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf e1f506c9def99b6f1333d312a0ba8f43d6ab44b83c8bc45da37d66ccf00fef7a

(this sample)

Comments