MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe4ee19554e105da2e904d29eeacf28b55f862577d8beb4dcd63ba61ce470cd9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: fe4ee19554e105da2e904d29eeacf28b55f862577d8beb4dcd63ba61ce470cd9
SHA3-384 hash: a71862ded0bc27722ce341a0c81fb032a9c3150a47bfede47eb90a30fcb2f9b88d22aeb0670effa2f0648a276747763a
SHA1 hash: 9651e4670cc942d6b0ca06c317bc6b8b7688e2aa
MD5 hash: d4eeb2fada66a8a08f4eeebc7cf24a3f
humanhash: pennsylvania-triple-six-cold
File name:fe4ee19554e105da2e904d29eeacf28b55f862577d8beb4dcd63ba61ce470cd9.elf
Download: download sample
Signature Mirai
File size:1'504 bytes
First seen:2026-08-21 07:21:01 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 24:FluHHAAsMKm8G38+MEpCD3ktXV9HkF6vwGQdRq7ixQL5r2J7G8XCzu3:f+AfMx8Fko3k9VlkEYvbq77c7G8XCM
TLSH T11431CE69D517F039E61611F6C05177732A3D8DADC3469712DC79CA02ED6E6CEE0A3481
Magika elf
Reporter whack_sh
Tags:elf exe mirai whack.sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
133
Origin country :
US US
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:

Behaviour
Connection attempt
Creating a file
Status:
terminated
Behavior Graph:
%3 guuid=4d87aa9c-1b00-0000-636b-874be8080000 pid=2280 /usr/bin/sudo guuid=e0df8ba5-1b00-0000-636b-874bf2080000 pid=2290 /tmp/sample.bin net send-data write-file guuid=4d87aa9c-1b00-0000-636b-874be8080000 pid=2280->guuid=e0df8ba5-1b00-0000-636b-874bf2080000 pid=2290 execve 68a2f4c7-41e6-5d77-b8ef-ef54db09e0e2 46.151.182.200:80 guuid=e0df8ba5-1b00-0000-636b-874bf2080000 pid=2290->68a2f4c7-41e6-5d77-b8ef-ef54db09e0e2 send: 27B
Threat name:
Linux.Dropper.MiraiDown
Status:
Malicious
First seen:
2026-08-21 07:21:26 UTC
File Type:
ELF32 Little (Exe)
AV detection:
4 of 36 (11.11%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:sora botnet linux
Behaviour
Writes file to tmp directory
Family: Mirai
Malware Config
C2 Extraction:
46.151.182.200
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf fe4ee19554e105da2e904d29eeacf28b55f862577d8beb4dcd63ba61ce470cd9

(this sample)

  
Delivery method
Distributed via web download

Comments