MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0b768ac1a55b164a39dc9af29102016a5417b6c038b427683641333881b3867b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 0b768ac1a55b164a39dc9af29102016a5417b6c038b427683641333881b3867b
SHA3-384 hash: 2961078b528b2c94d644555b88c5b3fa364ef2a4f692023bc6741785150d7d611f44c0cfc1f35026bbccbd170cef8930
SHA1 hash: 8414a70b755f1281df0f46b16d022b89c03aca08
MD5 hash: e2d0bc211a7ae1f7550b1af20ee60894
humanhash: mountain-lake-winner-princess
File name:wget.sh
Download: download sample
Signature Mirai
File size:880 bytes
First seen:2025-06-18 23:09:53 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:9cs+So/csTSDocsZNIxSydcsFSIKxKcsAThcsA+9csAokJcsIRBWR/WRFcs9ex8Z:9d+So/dTSDodKSyddFSISKdAThdA+9dv
TLSH T1F611889D1051724D4919CFCB71590B046F45CBE4F0ED9F8A6AA44733889A510B83DF0F
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.149.252.178/bot.arm93eb8e223410f702c1be6d9388205a25066cd8ee5c669e1e0954eed51b61d99c Miraielf mirai ua-wget
http://103.149.252.178/bot.arm567ba445f4d39c217eb3911c0b41ed7e4ca87c175535b1f08501e8d157c2bbd26 Miraielf mirai ua-wget
http://103.149.252.178/bot.arm661f1709d5d81bc6a521d005312751b7cfa5e5efa4a87b36c78d1df6a56166243 Miraielf mirai ua-wget
http://103.149.252.178/bot.arm799145d8a8d2bd7a401a9fac5ffc9413987eb507fd8f35b0be2d1641f285f4baa Miraielf mirai ua-wget
http://103.149.252.178/bot.m68k269ee46bd65dd8c96ad5ea5872ba50f12572714521430f410e73046afc372cee Miraielf mirai ua-wget
http://103.149.252.178/bot.mipse3b227f81a4eb81c43b5764316f3632fd41367cbb0706951b2375f43f906e8ff Miraielf mirai ua-wget
http://103.149.252.178/bot.mpsl9f1f56a03f2046fa18c79a9505f2a9fbb5272549da3eb9507b3495602246be54 Miraielf mirai ua-wget
http://103.149.252.178/bot.powerpcn/an/an/a
http://103.149.252.178/bot.sh4db65c6ad097c998d7cab2fd9bce177aa17f74a8179ac36a67c62f845285612b0 Miraielf mirai ua-wget
http://103.149.252.178/bot.x864427f663b9ef45d01d7925efe57d5670b5e27efc3e35c61abdda4786b681066d Miraielf mirai ua-wget
http://103.149.252.178/bot.x86_64dcf79d68228bb95fe49c4e3a9d0167aaef4abd8946bae55855d825b68b19cc26 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
125
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=e549638f-1800-0000-9e1a-1836630c0000 pid=3171 /usr/bin/sudo guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172 /tmp/sample.bin guuid=e549638f-1800-0000-9e1a-1836630c0000 pid=3171->guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172 execve guuid=63ad6592-1800-0000-9e1a-1836650c0000 pid=3173 /usr/bin/wget net send-data write-file guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=63ad6592-1800-0000-9e1a-1836650c0000 pid=3173 execve guuid=bac8a1f2-1800-0000-9e1a-1836d70c0000 pid=3287 /usr/bin/chmod guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=bac8a1f2-1800-0000-9e1a-1836d70c0000 pid=3287 execve guuid=fca21cf3-1800-0000-9e1a-1836d90c0000 pid=3289 /usr/bin/dash guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=fca21cf3-1800-0000-9e1a-1836d90c0000 pid=3289 clone guuid=8945f2f4-1800-0000-9e1a-1836de0c0000 pid=3294 /usr/bin/wget net send-data write-file guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=8945f2f4-1800-0000-9e1a-1836de0c0000 pid=3294 execve guuid=1d603e54-1900-0000-9e1a-1836640d0000 pid=3428 /usr/bin/chmod guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=1d603e54-1900-0000-9e1a-1836640d0000 pid=3428 execve guuid=0b1bbe54-1900-0000-9e1a-1836660d0000 pid=3430 /usr/bin/dash guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=0b1bbe54-1900-0000-9e1a-1836660d0000 pid=3430 clone guuid=efc0aa55-1900-0000-9e1a-1836690d0000 pid=3433 /usr/bin/wget net send-data write-file guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=efc0aa55-1900-0000-9e1a-1836690d0000 pid=3433 execve guuid=fee44bc0-1900-0000-9e1a-18360e0e0000 pid=3598 /usr/bin/chmod guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=fee44bc0-1900-0000-9e1a-18360e0e0000 pid=3598 execve guuid=734b13c1-1900-0000-9e1a-1836100e0000 pid=3600 /usr/bin/dash guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=734b13c1-1900-0000-9e1a-1836100e0000 pid=3600 clone guuid=ffd440c2-1900-0000-9e1a-1836140e0000 pid=3604 /usr/bin/wget net send-data write-file guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=ffd440c2-1900-0000-9e1a-1836140e0000 pid=3604 execve guuid=a5429441-1a00-0000-9e1a-1836220f0000 pid=3874 /usr/bin/chmod guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=a5429441-1a00-0000-9e1a-1836220f0000 pid=3874 execve guuid=c7fed341-1a00-0000-9e1a-1836260f0000 pid=3878 /usr/bin/dash guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=c7fed341-1a00-0000-9e1a-1836260f0000 pid=3878 clone guuid=9f091c43-1a00-0000-9e1a-18362d0f0000 pid=3885 /usr/bin/wget net send-data write-file guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=9f091c43-1a00-0000-9e1a-18362d0f0000 pid=3885 execve guuid=cd2f72b1-1a00-0000-9e1a-18360e100000 pid=4110 /usr/bin/chmod guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=cd2f72b1-1a00-0000-9e1a-18360e100000 pid=4110 execve guuid=24c0bcb1-1a00-0000-9e1a-183610100000 pid=4112 /usr/bin/dash guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=24c0bcb1-1a00-0000-9e1a-183610100000 pid=4112 clone guuid=ed29cfb3-1a00-0000-9e1a-183618100000 pid=4120 /usr/bin/wget net send-data write-file guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=ed29cfb3-1a00-0000-9e1a-183618100000 pid=4120 execve guuid=4259682b-1b00-0000-9e1a-183657110000 pid=4439 /usr/bin/chmod guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=4259682b-1b00-0000-9e1a-183657110000 pid=4439 execve guuid=81aee22b-1b00-0000-9e1a-18365a110000 pid=4442 /usr/bin/dash guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=81aee22b-1b00-0000-9e1a-18365a110000 pid=4442 clone guuid=220cf52d-1b00-0000-9e1a-183660110000 pid=4448 /usr/bin/wget net send-data write-file guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=220cf52d-1b00-0000-9e1a-183660110000 pid=4448 execve guuid=f54bc4a4-1b00-0000-9e1a-183679120000 pid=4729 /usr/bin/chmod guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=f54bc4a4-1b00-0000-9e1a-183679120000 pid=4729 execve guuid=e78058a5-1b00-0000-9e1a-18367a120000 pid=4730 /usr/bin/dash guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=e78058a5-1b00-0000-9e1a-18367a120000 pid=4730 clone guuid=499566a7-1b00-0000-9e1a-183681120000 pid=4737 /usr/bin/wget net send-data guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=499566a7-1b00-0000-9e1a-183681120000 pid=4737 execve guuid=79477fc5-1b00-0000-9e1a-1836b7120000 pid=4791 /usr/bin/chmod guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=79477fc5-1b00-0000-9e1a-1836b7120000 pid=4791 execve guuid=36a736c6-1b00-0000-9e1a-1836ba120000 pid=4794 /usr/bin/dash guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=36a736c6-1b00-0000-9e1a-1836ba120000 pid=4794 clone guuid=104d40c6-1b00-0000-9e1a-1836bb120000 pid=4795 /usr/bin/wget net send-data write-file guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=104d40c6-1b00-0000-9e1a-1836bb120000 pid=4795 execve guuid=bd293126-1c00-0000-9e1a-18368f130000 pid=5007 /usr/bin/chmod guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=bd293126-1c00-0000-9e1a-18368f130000 pid=5007 execve guuid=9459ba26-1c00-0000-9e1a-183690130000 pid=5008 /usr/bin/dash guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=9459ba26-1c00-0000-9e1a-183690130000 pid=5008 clone guuid=e94ef127-1c00-0000-9e1a-183694130000 pid=5012 /usr/bin/wget net send-data write-file guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=e94ef127-1c00-0000-9e1a-183694130000 pid=5012 execve guuid=ca715f79-1c00-0000-9e1a-183622140000 pid=5154 /usr/bin/chmod guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=ca715f79-1c00-0000-9e1a-183622140000 pid=5154 execve guuid=2974ab79-1c00-0000-9e1a-183623140000 pid=5155 /home/sandbox/bot.x86 delete-file net guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=2974ab79-1c00-0000-9e1a-183623140000 pid=5155 execve guuid=da9aea79-1c00-0000-9e1a-183626140000 pid=5158 /usr/bin/wget net send-data guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=da9aea79-1c00-0000-9e1a-183626140000 pid=5158 execve guuid=8e99277d-1c00-0000-9e1a-18362e140000 pid=5166 /usr/bin/chmod guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=8e99277d-1c00-0000-9e1a-18362e140000 pid=5166 execve guuid=a27a827d-1c00-0000-9e1a-183630140000 pid=5168 /usr/bin/dash guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=a27a827d-1c00-0000-9e1a-183630140000 pid=5168 clone guuid=361e947d-1c00-0000-9e1a-183631140000 pid=5169 /usr/bin/rm delete-file guuid=93e71492-1800-0000-9e1a-1836640c0000 pid=3172->guuid=361e947d-1c00-0000-9e1a-183631140000 pid=5169 execve b95ce511-3591-5114-995b-9ce77bb440cb 103.149.252.178:80 guuid=63ad6592-1800-0000-9e1a-1836650c0000 pid=3173->b95ce511-3591-5114-995b-9ce77bb440cb send: 137B guuid=8945f2f4-1800-0000-9e1a-1836de0c0000 pid=3294->b95ce511-3591-5114-995b-9ce77bb440cb send: 138B guuid=efc0aa55-1900-0000-9e1a-1836690d0000 pid=3433->b95ce511-3591-5114-995b-9ce77bb440cb send: 138B guuid=ffd440c2-1900-0000-9e1a-1836140e0000 pid=3604->b95ce511-3591-5114-995b-9ce77bb440cb send: 138B guuid=9f091c43-1a00-0000-9e1a-18362d0f0000 pid=3885->b95ce511-3591-5114-995b-9ce77bb440cb send: 138B guuid=ed29cfb3-1a00-0000-9e1a-183618100000 pid=4120->b95ce511-3591-5114-995b-9ce77bb440cb send: 138B guuid=220cf52d-1b00-0000-9e1a-183660110000 pid=4448->b95ce511-3591-5114-995b-9ce77bb440cb send: 138B guuid=499566a7-1b00-0000-9e1a-183681120000 pid=4737->b95ce511-3591-5114-995b-9ce77bb440cb send: 141B guuid=104d40c6-1b00-0000-9e1a-1836bb120000 pid=4795->b95ce511-3591-5114-995b-9ce77bb440cb send: 137B guuid=e94ef127-1c00-0000-9e1a-183694130000 pid=5012->b95ce511-3591-5114-995b-9ce77bb440cb send: 137B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=2974ab79-1c00-0000-9e1a-183623140000 pid=5155->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=df66e579-1c00-0000-9e1a-183625140000 pid=5157 /home/sandbox/bot.x86 dns net send-data zombie guuid=2974ab79-1c00-0000-9e1a-183623140000 pid=5155->guuid=df66e579-1c00-0000-9e1a-183625140000 pid=5157 clone guuid=df66e579-1c00-0000-9e1a-183625140000 pid=5157->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 31B 677ce3b8-4421-5add-bafd-dad229dad2e0 voucher.io.vn:47925 guuid=df66e579-1c00-0000-9e1a-183625140000 pid=5157->677ce3b8-4421-5add-bafd-dad229dad2e0 send: 13B guuid=5d92fa79-1c00-0000-9e1a-183627140000 pid=5159 /home/sandbox/bot.x86 guuid=df66e579-1c00-0000-9e1a-183625140000 pid=5157->guuid=5d92fa79-1c00-0000-9e1a-183627140000 pid=5159 clone guuid=da9aea79-1c00-0000-9e1a-183626140000 pid=5158->b95ce511-3591-5114-995b-9ce77bb440cb send: 140B
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-06-18 23:10:50 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0b768ac1a55b164a39dc9af29102016a5417b6c038b427683641333881b3867b

(this sample)

  
Delivery method
Distributed via web download

Comments