MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc5f410ff368910037e8ca73cd9024694eea4083af51990892a44b57938c6bf5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: fc5f410ff368910037e8ca73cd9024694eea4083af51990892a44b57938c6bf5
SHA3-384 hash: 6694574c40b254bf1605c592cbb299e68a8b4641c610db9ecc085c957b8264bcb901d6d9cbc0b5e0188f27257194babe
SHA1 hash: 4690703db8a3be608740e32d8f9b7b3dcd66d7de
MD5 hash: e3429e177b5baf2b245e073603927c7d
humanhash: uniform-lamp-arizona-papa
File name:spc
Download: download sample
Signature Mirai
File size:88'732 bytes
First seen:2025-11-09 17:35:39 UTC
Last seen:2025-11-10 20:18:57 UTC
File type: elf
MIME type:application/x-executable
ssdeep 1536:EzNoZzlh6FgCWQtlaXtq1yt5mIoEZfjtc7MGP:o+zfM+Ic/2EQ
TLSH T141832A2279761D2BC4C1A8BB22F34725F2F6538A25F8CA0E7D620D4EBF256503147AF5
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
3
# of downloads :
115
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
gafgyt mirai
Verdict:
Malicious
File Type:
elf.32.be
First seen:
2025-11-09T14:45:00Z UTC
Last seen:
2025-11-11T10:18:00Z UTC
Hits:
~10
Detections:
HEUR:Backdoor.Linux.Mirai.b
Status:
terminated
Behavior Graph:
%3 guuid=a45fd272-1500-0000-c99e-733d600b0000 pid=2912 /usr/bin/sudo guuid=7dd41e75-1500-0000-c99e-733d620b0000 pid=2914 /tmp/sample.bin guuid=a45fd272-1500-0000-c99e-733d600b0000 pid=2912->guuid=7dd41e75-1500-0000-c99e-733d620b0000 pid=2914 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1810989 Sample: spc.elf Startdate: 09/11/2025 Architecture: LINUX Score: 48 12 109.202.202.202, 80 INIT7CH Switzerland 2->12 14 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->14 16 2 other IPs or domains 2->16 18 Multi AV Scanner detection for submitted file 2->18 6 dash rm 2->6         started        8 dash rm 2->8         started        10 spc.elf 2->10         started        signatures3 process4
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-11-09 17:36:16 UTC
File Type:
ELF32 Big (Exe)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf fc5f410ff368910037e8ca73cd9024694eea4083af51990892a44b57938c6bf5

(this sample)

  
Delivery method
Distributed via web download

Comments