MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 04536a23b54005b43ecbb7188c39ce992a852e824c608a26a7837b60280ad76c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 04536a23b54005b43ecbb7188c39ce992a852e824c608a26a7837b60280ad76c
SHA3-384 hash: 79cf02402702eb1ebef8eea7cc75a57ea85d1b1a8aeea9083b67cb1b3faaeab5dabd5f070a87c1cf8298edc3c74c0948
SHA1 hash: ae73eeabc05aedee0a377f7fd37065949a1caad7
MD5 hash: a1c0b619c4b6eeb9e3afeb5f1bd5d249
humanhash: harry-red-march-oranges
File name:res
Download: download sample
Signature Mirai
File size:290 bytes
First seen:2025-11-07 23:42:29 UTC
Last seen:2025-11-08 06:12:19 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hftJ+pUKUF2RVYrV/jkOYf53I4Y3FoF/fkVKhOXqIKXD73IKX+N1IEWYq1IKBKW:ZtJ+jRaV7YJF0ghsOTh4WYO8W
TLSH T1B2D0C259FC420836B8758CBA77DB3451910B920B6A06958A31CB520AAAE4960A060453
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-07T21:04:00Z UTC
Last seen:
2025-11-07T22:28:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=b1b9d15c-1900-0000-a299-a8cb64140000 pid=5220 /usr/bin/sudo guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221 /tmp/sample.bin guuid=b1b9d15c-1900-0000-a299-a8cb64140000 pid=5220->guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221 execve guuid=c327c55f-1900-0000-a299-a8cb66140000 pid=5222 /usr/bin/wget net send-data write-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=c327c55f-1900-0000-a299-a8cb66140000 pid=5222 execve guuid=11cdfe98-1900-0000-a299-a8cb6a140000 pid=5226 /usr/bin/chmod guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=11cdfe98-1900-0000-a299-a8cb6a140000 pid=5226 execve guuid=6c5f8f99-1900-0000-a299-a8cb6b140000 pid=5227 /usr/bin/dash guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=6c5f8f99-1900-0000-a299-a8cb6b140000 pid=5227 clone guuid=3a97359a-1900-0000-a299-a8cb6d140000 pid=5229 /usr/bin/rm delete-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=3a97359a-1900-0000-a299-a8cb6d140000 pid=5229 execve guuid=5650819a-1900-0000-a299-a8cb6e140000 pid=5230 /usr/bin/wget net send-data write-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=5650819a-1900-0000-a299-a8cb6e140000 pid=5230 execve guuid=764d31a1-1900-0000-a299-a8cb73140000 pid=5235 /usr/bin/chmod guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=764d31a1-1900-0000-a299-a8cb73140000 pid=5235 execve guuid=eeb980a1-1900-0000-a299-a8cb74140000 pid=5236 /usr/bin/dash guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=eeb980a1-1900-0000-a299-a8cb74140000 pid=5236 clone guuid=41dc31a2-1900-0000-a299-a8cb76140000 pid=5238 /usr/bin/rm delete-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=41dc31a2-1900-0000-a299-a8cb76140000 pid=5238 execve guuid=e06386a2-1900-0000-a299-a8cb77140000 pid=5239 /usr/bin/wget net send-data write-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=e06386a2-1900-0000-a299-a8cb77140000 pid=5239 execve guuid=6d3a3ca7-1900-0000-a299-a8cb78140000 pid=5240 /usr/bin/chmod guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=6d3a3ca7-1900-0000-a299-a8cb78140000 pid=5240 execve guuid=24ef87a7-1900-0000-a299-a8cb79140000 pid=5241 /usr/bin/dash guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=24ef87a7-1900-0000-a299-a8cb79140000 pid=5241 clone guuid=de9123a8-1900-0000-a299-a8cb7b140000 pid=5243 /usr/bin/rm delete-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=de9123a8-1900-0000-a299-a8cb7b140000 pid=5243 execve guuid=74e17aa8-1900-0000-a299-a8cb7c140000 pid=5244 /usr/bin/wget net send-data write-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=74e17aa8-1900-0000-a299-a8cb7c140000 pid=5244 execve guuid=a54d2bad-1900-0000-a299-a8cb7d140000 pid=5245 /usr/bin/chmod guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=a54d2bad-1900-0000-a299-a8cb7d140000 pid=5245 execve guuid=6b1479ad-1900-0000-a299-a8cb7e140000 pid=5246 /usr/bin/dash guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=6b1479ad-1900-0000-a299-a8cb7e140000 pid=5246 clone guuid=eba229ae-1900-0000-a299-a8cb80140000 pid=5248 /usr/bin/rm delete-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=eba229ae-1900-0000-a299-a8cb80140000 pid=5248 execve guuid=e40881ae-1900-0000-a299-a8cb81140000 pid=5249 /usr/bin/wget net send-data write-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=e40881ae-1900-0000-a299-a8cb81140000 pid=5249 execve guuid=0d045fb3-1900-0000-a299-a8cb82140000 pid=5250 /usr/bin/chmod guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=0d045fb3-1900-0000-a299-a8cb82140000 pid=5250 execve guuid=ff89b2b3-1900-0000-a299-a8cb83140000 pid=5251 /usr/bin/dash guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=ff89b2b3-1900-0000-a299-a8cb83140000 pid=5251 clone guuid=acdedbb4-1900-0000-a299-a8cb85140000 pid=5253 /usr/bin/rm delete-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=acdedbb4-1900-0000-a299-a8cb85140000 pid=5253 execve guuid=a0952eb5-1900-0000-a299-a8cb86140000 pid=5254 /usr/bin/wget net send-data write-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=a0952eb5-1900-0000-a299-a8cb86140000 pid=5254 execve guuid=148d81bb-1900-0000-a299-a8cb87140000 pid=5255 /usr/bin/chmod guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=148d81bb-1900-0000-a299-a8cb87140000 pid=5255 execve guuid=a2cddcbb-1900-0000-a299-a8cb88140000 pid=5256 /usr/bin/dash guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=a2cddcbb-1900-0000-a299-a8cb88140000 pid=5256 clone guuid=8e052abd-1900-0000-a299-a8cb8a140000 pid=5258 /usr/bin/rm delete-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=8e052abd-1900-0000-a299-a8cb8a140000 pid=5258 execve guuid=c56b8fbd-1900-0000-a299-a8cb8b140000 pid=5259 /usr/bin/wget net send-data write-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=c56b8fbd-1900-0000-a299-a8cb8b140000 pid=5259 execve guuid=e730aec5-1900-0000-a299-a8cb8c140000 pid=5260 /usr/bin/chmod guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=e730aec5-1900-0000-a299-a8cb8c140000 pid=5260 execve guuid=6feb08c6-1900-0000-a299-a8cb8d140000 pid=5261 /usr/bin/dash guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=6feb08c6-1900-0000-a299-a8cb8d140000 pid=5261 clone guuid=a5adb0c6-1900-0000-a299-a8cb8f140000 pid=5263 /usr/bin/rm delete-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=a5adb0c6-1900-0000-a299-a8cb8f140000 pid=5263 execve guuid=8ca102c7-1900-0000-a299-a8cb90140000 pid=5264 /usr/bin/wget net send-data write-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=8ca102c7-1900-0000-a299-a8cb90140000 pid=5264 execve guuid=6814cfcb-1900-0000-a299-a8cb91140000 pid=5265 /usr/bin/chmod guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=6814cfcb-1900-0000-a299-a8cb91140000 pid=5265 execve guuid=16641ccc-1900-0000-a299-a8cb92140000 pid=5266 /usr/bin/dash guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=16641ccc-1900-0000-a299-a8cb92140000 pid=5266 clone guuid=8df9bbcc-1900-0000-a299-a8cb94140000 pid=5268 /usr/bin/rm delete-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=8df9bbcc-1900-0000-a299-a8cb94140000 pid=5268 execve guuid=47b504cd-1900-0000-a299-a8cb95140000 pid=5269 /usr/bin/wget net send-data write-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=47b504cd-1900-0000-a299-a8cb95140000 pid=5269 execve guuid=c21b03d3-1900-0000-a299-a8cb96140000 pid=5270 /usr/bin/chmod guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=c21b03d3-1900-0000-a299-a8cb96140000 pid=5270 execve guuid=7a1252d3-1900-0000-a299-a8cb97140000 pid=5271 /tmp/telnet guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=7a1252d3-1900-0000-a299-a8cb97140000 pid=5271 execve guuid=35f766d3-1900-0000-a299-a8cb99140000 pid=5273 /usr/bin/rm delete-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=35f766d3-1900-0000-a299-a8cb99140000 pid=5273 execve guuid=1328b4d3-1900-0000-a299-a8cb9a140000 pid=5274 /usr/bin/wget net send-data write-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=1328b4d3-1900-0000-a299-a8cb9a140000 pid=5274 execve guuid=6c0c64d9-1900-0000-a299-a8cb9c140000 pid=5276 /usr/bin/chmod guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=6c0c64d9-1900-0000-a299-a8cb9c140000 pid=5276 execve guuid=9129b1d9-1900-0000-a299-a8cb9d140000 pid=5277 /usr/bin/dash guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=9129b1d9-1900-0000-a299-a8cb9d140000 pid=5277 clone guuid=e1f25fda-1900-0000-a299-a8cb9f140000 pid=5279 /usr/bin/rm delete-file guuid=7d88845f-1900-0000-a299-a8cb65140000 pid=5221->guuid=e1f25fda-1900-0000-a299-a8cb9f140000 pid=5279 execve 4ff2fd4b-3dd8-5d4c-bed3-6ee37e11f24a 213.209.143.41:80 guuid=c327c55f-1900-0000-a299-a8cb66140000 pid=5222->4ff2fd4b-3dd8-5d4c-bed3-6ee37e11f24a send: 142B guuid=5650819a-1900-0000-a299-a8cb6e140000 pid=5230->4ff2fd4b-3dd8-5d4c-bed3-6ee37e11f24a send: 142B guuid=e06386a2-1900-0000-a299-a8cb77140000 pid=5239->4ff2fd4b-3dd8-5d4c-bed3-6ee37e11f24a send: 141B guuid=74e17aa8-1900-0000-a299-a8cb7c140000 pid=5244->4ff2fd4b-3dd8-5d4c-bed3-6ee37e11f24a send: 142B guuid=e40881ae-1900-0000-a299-a8cb81140000 pid=5249->4ff2fd4b-3dd8-5d4c-bed3-6ee37e11f24a send: 142B guuid=a0952eb5-1900-0000-a299-a8cb86140000 pid=5254->4ff2fd4b-3dd8-5d4c-bed3-6ee37e11f24a send: 142B guuid=c56b8fbd-1900-0000-a299-a8cb8b140000 pid=5259->4ff2fd4b-3dd8-5d4c-bed3-6ee37e11f24a send: 141B guuid=8ca102c7-1900-0000-a299-a8cb90140000 pid=5264->4ff2fd4b-3dd8-5d4c-bed3-6ee37e11f24a send: 141B guuid=47b504cd-1900-0000-a299-a8cb95140000 pid=5269->4ff2fd4b-3dd8-5d4c-bed3-6ee37e11f24a send: 141B guuid=2d4861d3-1900-0000-a299-a8cb98140000 pid=5272 /tmp/telnet zombie guuid=7a1252d3-1900-0000-a299-a8cb97140000 pid=5271->guuid=2d4861d3-1900-0000-a299-a8cb98140000 pid=5272 clone guuid=69a5b7d3-1900-0000-a299-a8cb9b140000 pid=5275 /tmp/telnet dns net send-data zombie guuid=2d4861d3-1900-0000-a299-a8cb98140000 pid=5272->guuid=69a5b7d3-1900-0000-a299-a8cb9b140000 pid=5275 clone guuid=1328b4d3-1900-0000-a299-a8cb9a140000 pid=5274->4ff2fd4b-3dd8-5d4c-bed3-6ee37e11f24a send: 141B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=69a5b7d3-1900-0000-a299-a8cb9b140000 pid=5275->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 1080B
Threat name:
Linux.Downloader.MiraiB
Status:
Malicious
First seen:
2025-11-08 00:19:00 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 04536a23b54005b43ecbb7188c39ce992a852e824c608a26a7837b60280ad76c

(this sample)

Comments