MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eeee3c36e40f51093e495234b299e7c29bb81dfbdc7d95ff980eb986f4762b7c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 4 File information Comments

SHA256 hash: eeee3c36e40f51093e495234b299e7c29bb81dfbdc7d95ff980eb986f4762b7c
SHA3-384 hash: f7cc2d3f80be8e38943d3e6fe0ed5592e2fa3db92259758b4aaa6630a094197b857413109457eac1de1139a19196d020
SHA1 hash: 7872b5417f3743350bbda5a20fbaaf9d9aa4ae63
MD5 hash: b52150e3f0a4e25540e066f759907dc2
humanhash: river-carbon-autumn-london
File name:putita.ppc
Download: download sample
Signature Mirai
File size:198'040 bytes
First seen:2026-08-18 20:21:40 UTC
Last seen:Never
File type: elf
MIME type:application/x-sharedlib
ssdeep 6144:YCSwKYRAwY0+t/h+eyAoY9Vik8Qo3n2NU8GM/:Jx7RotJl9ViHOB
TLSH T164147E00FB181913C5935DB41B3B0766E379CC8318B9F019290E7B569733AFB9A87B96
Magika elf
Reporter abuse_ch
Tags:elf mirai upx-dec


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 fa4b29660acb3dfa66a511e92f6dc221e4a720c127df0674f6b18007272bed37
File size (compressed) :65'276 bytes
File size (de-compressed) :198'040 bytes
Format:linux/ppc32
Packed file: fa4b29660acb3dfa66a511e92f6dc221e4a720c127df0674f6b18007272bed37

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Opens a port
Sets a written file as executable
Launching a process
Changes the time when the file was created, accessed, or modified
Connection attempt
Runs as daemon
Changes access rights for a written file
Creating a file
Creates or modifies symbolic links
Substitutes an application name
Writes files to system directory
Creates or modifies files in /cron to set up autorun
Creates or modifies files to set up autorun
Deleting of the original file
Creates or modifies symbolic links in /init.d to set up autorun
Creates or modifies files in /init.d to set up autorun
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
gcc masquerade
Status:
terminated
Behavior Graph:
%3 guuid=ecf65fe9-1b00-0000-592c-5bac4a070000 pid=1866 /usr/bin/sudo guuid=cb4724eb-1b00-0000-592c-5bac4b070000 pid=1867 /tmp/sample.bin guuid=ecf65fe9-1b00-0000-592c-5bac4a070000 pid=1866->guuid=cb4724eb-1b00-0000-592c-5bac4b070000 pid=1867 execve
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-08-18 20:22:55 UTC
File Type:
ELF32 Big (SO)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
Rule name:ELF_Mirai
Author:NDA0E
Description:Detects multiple Mirai variants
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags
Rule name:woof_mirai_variant
Author:Nokia Deepfield ERT
Description:Detects Woof Mirai variant (ChaCha20 table, HTTP C2 with token/guid, .woof dropper)
Reference:Internal analysis of sample 6ef4ce02

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf eeee3c36e40f51093e495234b299e7c29bb81dfbdc7d95ff980eb986f4762b7c

(this sample)

  
Delivery method
Distributed via web download

Comments