MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e574dbdce8f380d63e7755cba71a9c13aeb0640874fef16a01ba2007de629314. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e574dbdce8f380d63e7755cba71a9c13aeb0640874fef16a01ba2007de629314
SHA3-384 hash: 1b5622b27c855428cdc437c45c580ed98881474cbb3db2c8ea72d46c6e3881876b0d27da1ed78083b6d0fdb90efe6da4
SHA1 hash: 08fb01c595186e6275fc2af2dad27434adbd21b3
MD5 hash: 9855ee8e40846eefb4db46678329b3db
humanhash: tennessee-uncle-india-oregon
File name:x86_64
Download: download sample
Signature Mirai
File size:1'605'372 bytes
First seen:2026-02-10 12:29:01 UTC
Last seen:2026-02-11 06:13:37 UTC
File type: elf
MIME type:application/x-executable
ssdeep 24576:wKSc8CzOx8GxVvM3lQ+9Xknlat2lp8MhzUE8swuW46sJ/gWhHhbVlGttgKAmx/D:EpCKabVQ+9qlNlpjN8H8JZGtucD
TLSH T12775339315460FB4AFD3FE3840186D8AE661DEB44B7EB3B8B274967015537E6B230836
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
3
# of downloads :
96
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
0
Number of processes launched:
1
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
no suspicious findings
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Unknown
File Type:
elf.64.le
First seen:
2025-12-11T22:45:00Z UTC
Last seen:
2026-02-10T09:59:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1866666 Sample: x86_64.elf Startdate: 10/02/2026 Architecture: LINUX Score: 48 14 34.243.160.129, 42476, 443 AMAZON-02US United States 2->14 16 Multi AV Scanner detection for submitted file 2->16 6 dash rm 2->6         started        8 dash head 2->8         started        10 dash tr 2->10         started        12 8 other processes 2->12 signatures3 process4
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-12-12 05:23:57 UTC
File Type:
ELF64 Little (Exe)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
linux upx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf e574dbdce8f380d63e7755cba71a9c13aeb0640874fef16a01ba2007de629314

(this sample)

  
Delivery method
Distributed via web download

Comments