MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f935c6158a5b5da6275ca5404cb012ea4c7cadd7714cdcac8fd54473d1968e49. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: f935c6158a5b5da6275ca5404cb012ea4c7cadd7714cdcac8fd54473d1968e49
SHA3-384 hash: 0c0af4575e968920863cee4cf6fbf42bb6146e378a363d3f8f9afb2d1737ab339e83ac67d9e1f60676b6afda424de8b4
SHA1 hash: 05b4d5dd9630a914ba58bc42244a4364de6abe8d
MD5 hash: 750118a03f9b6693dae4b9175fe6dccb
humanhash: double-nevada-april-victor
File name:spc
Download: download sample
Signature Mirai
File size:75'428 bytes
First seen:2025-11-02 11:12:47 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:iT0jCJIdnIPiAbX1L2UIvqd+tdhnt5VcntuR5sOG:Y5+s3bIvXJn/JqB
TLSH T173732A227D360D27C5C1A87A62F34728F1F6538A26ECCA1E7D620D4EBF246403197AF5
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
135
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2025-11-02T08:19:00Z UTC
Last seen:
2025-11-02T10:00:00Z UTC
Hits:
~10
Detections:
HEUR:Backdoor.Linux.Mirai.b
Status:
terminated
Behavior Graph:
%3 guuid=4ce6a090-1600-0000-24aa-2be9940c0000 pid=3220 /usr/bin/sudo guuid=62fdae92-1600-0000-24aa-2be9950c0000 pid=3221 /tmp/sample.bin guuid=4ce6a090-1600-0000-24aa-2be9940c0000 pid=3220->guuid=62fdae92-1600-0000-24aa-2be9950c0000 pid=3221 execve
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
72 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Manipulation of devices in /dev
Multi AV Scanner detection for submitted file
Yara detected Mirai
Behaviour
Behavior Graph:
Threat name:
Linux.Backdoor.Mirai
Status:
Malicious
First seen:
2025-11-02 11:13:25 UTC
File Type:
ELF32 Big (Exe)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf f935c6158a5b5da6275ca5404cb012ea4c7cadd7714cdcac8fd54473d1968e49

(this sample)

  
Delivery method
Distributed via web download

Comments