🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 041d376124ec0e341b8b9f5e4db1343dd4ec32cd6f2085b866fa3b98ad4fc5c6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 041d376124ec0e341b8b9f5e4db1343dd4ec32cd6f2085b866fa3b98ad4fc5c6
SHA3-384 hash: d3187c08e3c9ac7f13eb116b35e891e2bfb4c021e5be8e02465f8c075638fd0bbae45b3681caa47bdb0ebe656afaf9b3
SHA1 hash: da6d4a33a311cb35deb4259ed0453857241a9995
MD5 hash: 841eaf139ae4ec999b3efa667f1e33c4
humanhash: rugby-one-quebec-thirteen
File name:cat.sh
Download: download sample
Signature Mirai
File size:719 bytes
First seen:2026-09-02 11:28:16 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:PETF3bwARCNFeNvorO9yYz5k0MFnws/srAst/dy7ARp7gk99:M53V2Mx8QyYze0Mdws/scs1okRpUkT
TLSH T1290176D337639073A59C147A436EB320C4878C4B09A2FE20788C3D507F6AA06F851E18
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter adliwahid
Tags:mirai
URLMalware sample (SHA256 hash)SignatureTags
http://103.28.35.195/n/an/an/a
http://103.28.35.195/x86_643ee78d558443d91f414d2838f3ad18eb2742b9a67792cb736e6330ad5191de9b Miraimirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-01T22:16:00Z UTC
Last seen:
2026-09-02T14:44:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=86b23ef2-1b00-0000-b4f6-ce67640a0000 pid=2660 /usr/bin/sudo guuid=5980f9f4-1b00-0000-b4f6-ce676a0a0000 pid=2666 /tmp/sample.bin guuid=86b23ef2-1b00-0000-b4f6-ce67640a0000 pid=2660->guuid=5980f9f4-1b00-0000-b4f6-ce676a0a0000 pid=2666 execve guuid=ed444af5-1b00-0000-b4f6-ce676c0a0000 pid=2668 /usr/bin/uname guuid=5980f9f4-1b00-0000-b4f6-ce676a0a0000 pid=2666->guuid=ed444af5-1b00-0000-b4f6-ce676c0a0000 pid=2668 execve guuid=ff25b5f5-1b00-0000-b4f6-ce676e0a0000 pid=2670 /usr/bin/wget net send-data write-file guuid=5980f9f4-1b00-0000-b4f6-ce676a0a0000 pid=2666->guuid=ff25b5f5-1b00-0000-b4f6-ce676e0a0000 pid=2670 execve guuid=1903a33b-1e00-0000-b4f6-ce676a0d0000 pid=3434 /usr/bin/chmod guuid=5980f9f4-1b00-0000-b4f6-ce676a0a0000 pid=2666->guuid=1903a33b-1e00-0000-b4f6-ce676a0d0000 pid=3434 execve guuid=89d9e13b-1e00-0000-b4f6-ce676c0d0000 pid=3436 /tmp/bot net guuid=5980f9f4-1b00-0000-b4f6-ce676a0a0000 pid=2666->guuid=89d9e13b-1e00-0000-b4f6-ce676c0d0000 pid=3436 execve guuid=8caf0f3c-1e00-0000-b4f6-ce676e0d0000 pid=3438 /usr/bin/rm delete-file guuid=5980f9f4-1b00-0000-b4f6-ce676a0a0000 pid=2666->guuid=8caf0f3c-1e00-0000-b4f6-ce676e0d0000 pid=3438 execve b60a8341-f3e7-5377-a39e-d6cc18aa8025 103.28.35.195:80 guuid=ff25b5f5-1b00-0000-b4f6-ce676e0a0000 pid=2670->b60a8341-f3e7-5377-a39e-d6cc18aa8025 send: 134B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=89d9e13b-1e00-0000-b4f6-ce676c0d0000 pid=3436->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=79b2043c-1e00-0000-b4f6-ce676d0d0000 pid=3437 /tmp/bot dns net send-data zombie guuid=89d9e13b-1e00-0000-b4f6-ce676c0d0000 pid=3436->guuid=79b2043c-1e00-0000-b4f6-ce676d0d0000 pid=3437 clone guuid=79b2043c-1e00-0000-b4f6-ce676d0d0000 pid=3437->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 43B 7ccf7252-d22f-59f4-a2dc-43bcd82fb12d anhminhdzvclxyz.devs.surf:56999 guuid=79b2043c-1e00-0000-b4f6-ce676d0d0000 pid=3437->7ccf7252-d22f-59f4-a2dc-43bcd82fb12d send: 10B guuid=3e6a103c-1e00-0000-b4f6-ce676f0d0000 pid=3439 /tmp/bot guuid=79b2043c-1e00-0000-b4f6-ce676d0d0000 pid=3437->guuid=3e6a103c-1e00-0000-b4f6-ce676f0d0000 pid=3439 clone
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-09-02 03:29:05 UTC
File Type:
Text (Shell)
AV detection:
4 of 36 (11.11%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Unexpected DNS network traffic destination
Family: Mirai
Malware Config
C2 Extraction:
anhminhdzvclxyz.devs.surf
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Mirai

sh 041d376124ec0e341b8b9f5e4db1343dd4ec32cd6f2085b866fa3b98ad4fc5c6

(this sample)

Comments