MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 163a2c04fa5a1a8607a3aa00791c044bf68f7b20d610d555f9991aca861028ac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 163a2c04fa5a1a8607a3aa00791c044bf68f7b20d610d555f9991aca861028ac
SHA3-384 hash: 509bec5aacbaeaf6f6de9d64f1449a6e7648f4d95b1713c32d7cd364e6bb97e8fde6f73675c9c85e48102528991e5de7
SHA1 hash: 402ef77ef8aa8eaab8f30c13e377ae43126e1aa9
MD5 hash: 310fad1251675a0cd1eb104dec70489d
humanhash: east-ceiling-indigo-ohio
File name:wget.sh
Download: download sample
Signature Mirai
File size:810 bytes
First seen:2025-08-21 07:52:23 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:h93Yk8NI7tEK99+Ih2jyOT5QHlJaturJgksn:TYiuRI4f50U
TLSH T15C0125DE67B271624E88CE64606944C49536E2D032D80F6EDCC62CF3C8E97013235E7B
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://161.97.74.69/systemcl/arma2812bf91c1836b0749615f8c92f49b055ed1152a0cfcb03cffb4473388ae1f9 Mirai32-bit elf mirai Mozi
http://161.97.74.69/systemcl/arm5467ca3ecdb388a31f9687f3f93134ae992fbfbe2936cfbd700c3d198b3b65ecb Miraielf mirai ua-wget
http://161.97.74.69/systemcl/arm67a4627901da5e02ceacaf688cc103b4944a3cf75b4f1f4316ee638893eaa4104 Miraielf mirai ua-wget
http://161.97.74.69/systemcl/arm71745a1dc09e108e719186017f4d6f10e1835aa4ba3f74b50b8394e3268c66524 Miraielf mirai ua-wget
http://161.97.74.69/systemcl/m68k19abfca0200531ee5ddc2dd7bc4454af84d9ffe0ef2e12cd2a54fc828ebdc659 Miraielf mirai ua-wget
http://161.97.74.69/systemcl/mipsad42066092b60784e1579fb3742cf3a41450dacc13b254e9c3a0c5b84aaf0db4 Mirai32-bit elf mirai Mozi
http://161.97.74.69/systemcl/mpsl7365564e3fc5bc60caa91eb8b6b87a6d8da423389be87134899fcd0caaeb3242 Miraielf mirai ua-wget
http://161.97.74.69/systemcl/ppcabfd19ac36a02a8d3552a65a6e023b7499af427f7ea558cbc5064b8475bd955e Miraielf mirai ua-wget
http://161.97.74.69/systemcl/sh4b5d5a320320766751e9a1e31bc6ff850196e0c3f0b5baee15eee600b8a3cdae2 Miraielf mirai ua-wget
http://161.97.74.69/systemcl/spc2b4e44a8a37c63ce0a2c007bb22d903ae9d13b643b6b556f4d15199926cdd54c Miraielf mirai ua-wget
http://161.97.74.69/systemcl/x862e9b4bb064c078485eab38389da45cfecd1f865d77cd5c199ae3c2fe195daf72 Mirai32-bit elf mirai Mozi
http://161.97.74.69/systemcl/x86_6447a0fa2b9aa3ebdb48324d5ad43903187a528176193716db81991191b3d3b230 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=9da8769b-2100-0000-822f-ac81cc090000 pid=2508 /usr/bin/sudo guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513 /tmp/sample.bin guuid=9da8769b-2100-0000-822f-ac81cc090000 pid=2508->guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513 execve guuid=09e6969d-2100-0000-822f-ac81d2090000 pid=2514 /usr/bin/wget net send-data write-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=09e6969d-2100-0000-822f-ac81d2090000 pid=2514 execve guuid=b877b1a3-2100-0000-822f-ac81de090000 pid=2526 /usr/bin/chmod guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=b877b1a3-2100-0000-822f-ac81de090000 pid=2526 execve guuid=e8011ea4-2100-0000-822f-ac81df090000 pid=2527 /usr/bin/dash guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=e8011ea4-2100-0000-822f-ac81df090000 pid=2527 clone guuid=8e4c91a6-2100-0000-822f-ac81e2090000 pid=2530 /usr/bin/wget net send-data write-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=8e4c91a6-2100-0000-822f-ac81e2090000 pid=2530 execve guuid=260f7cac-2100-0000-822f-ac81ee090000 pid=2542 /usr/bin/chmod guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=260f7cac-2100-0000-822f-ac81ee090000 pid=2542 execve guuid=768eceac-2100-0000-822f-ac81ef090000 pid=2543 /usr/bin/dash guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=768eceac-2100-0000-822f-ac81ef090000 pid=2543 clone guuid=b41f80ad-2100-0000-822f-ac81f3090000 pid=2547 /usr/bin/wget net send-data write-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=b41f80ad-2100-0000-822f-ac81f3090000 pid=2547 execve guuid=e4a5a1b0-2100-0000-822f-ac81fd090000 pid=2557 /usr/bin/chmod guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=e4a5a1b0-2100-0000-822f-ac81fd090000 pid=2557 execve guuid=f659e5b0-2100-0000-822f-ac81ff090000 pid=2559 /usr/bin/dash guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=f659e5b0-2100-0000-822f-ac81ff090000 pid=2559 clone guuid=7b706bb2-2100-0000-822f-ac81040a0000 pid=2564 /usr/bin/wget net send-data write-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=7b706bb2-2100-0000-822f-ac81040a0000 pid=2564 execve guuid=cc6ae5b8-2100-0000-822f-ac81150a0000 pid=2581 /usr/bin/chmod guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=cc6ae5b8-2100-0000-822f-ac81150a0000 pid=2581 execve guuid=76992fb9-2100-0000-822f-ac81170a0000 pid=2583 /usr/bin/dash guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=76992fb9-2100-0000-822f-ac81170a0000 pid=2583 clone guuid=2902e5b9-2100-0000-822f-ac811a0a0000 pid=2586 /usr/bin/wget net send-data write-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=2902e5b9-2100-0000-822f-ac811a0a0000 pid=2586 execve guuid=ddcd9dc2-2100-0000-822f-ac81310a0000 pid=2609 /usr/bin/chmod guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=ddcd9dc2-2100-0000-822f-ac81310a0000 pid=2609 execve guuid=e5bcdcc2-2100-0000-822f-ac81320a0000 pid=2610 /usr/bin/dash guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=e5bcdcc2-2100-0000-822f-ac81320a0000 pid=2610 clone guuid=338f5ac3-2100-0000-822f-ac81360a0000 pid=2614 /usr/bin/wget net send-data write-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=338f5ac3-2100-0000-822f-ac81360a0000 pid=2614 execve guuid=0005ecc6-2100-0000-822f-ac81420a0000 pid=2626 /usr/bin/chmod guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=0005ecc6-2100-0000-822f-ac81420a0000 pid=2626 execve guuid=9d1731c7-2100-0000-822f-ac81440a0000 pid=2628 /usr/bin/dash guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=9d1731c7-2100-0000-822f-ac81440a0000 pid=2628 clone guuid=1dbfb6c8-2100-0000-822f-ac814a0a0000 pid=2634 /usr/bin/wget net send-data write-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=1dbfb6c8-2100-0000-822f-ac814a0a0000 pid=2634 execve guuid=5b8b05d3-2100-0000-822f-ac81670a0000 pid=2663 /usr/bin/chmod guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=5b8b05d3-2100-0000-822f-ac81670a0000 pid=2663 execve guuid=c31956d3-2100-0000-822f-ac81690a0000 pid=2665 /usr/bin/dash guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=c31956d3-2100-0000-822f-ac81690a0000 pid=2665 clone guuid=d43c12d4-2100-0000-822f-ac816c0a0000 pid=2668 /usr/bin/wget net send-data write-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=d43c12d4-2100-0000-822f-ac816c0a0000 pid=2668 execve guuid=a3297fd9-2100-0000-822f-ac81770a0000 pid=2679 /usr/bin/chmod guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=a3297fd9-2100-0000-822f-ac81770a0000 pid=2679 execve guuid=de1704da-2100-0000-822f-ac81790a0000 pid=2681 /usr/bin/dash guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=de1704da-2100-0000-822f-ac81790a0000 pid=2681 clone guuid=432e09db-2100-0000-822f-ac817d0a0000 pid=2685 /usr/bin/wget net send-data write-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=432e09db-2100-0000-822f-ac817d0a0000 pid=2685 execve guuid=8b0a6ce2-2100-0000-822f-ac81900a0000 pid=2704 /usr/bin/chmod guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=8b0a6ce2-2100-0000-822f-ac81900a0000 pid=2704 execve guuid=26c8b1e2-2100-0000-822f-ac81920a0000 pid=2706 /usr/bin/dash guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=26c8b1e2-2100-0000-822f-ac81920a0000 pid=2706 clone guuid=2ab470e3-2100-0000-822f-ac81960a0000 pid=2710 /usr/bin/wget net send-data write-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=2ab470e3-2100-0000-822f-ac81960a0000 pid=2710 execve guuid=d9296be7-2100-0000-822f-ac81a10a0000 pid=2721 /usr/bin/chmod guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=d9296be7-2100-0000-822f-ac81a10a0000 pid=2721 execve guuid=c9aab7e7-2100-0000-822f-ac81a40a0000 pid=2724 /usr/bin/dash guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=c9aab7e7-2100-0000-822f-ac81a40a0000 pid=2724 clone guuid=e7053ee8-2100-0000-822f-ac81a70a0000 pid=2727 /usr/bin/wget net send-data write-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=e7053ee8-2100-0000-822f-ac81a70a0000 pid=2727 execve guuid=b24dd7eb-2100-0000-822f-ac81b00a0000 pid=2736 /usr/bin/chmod guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=b24dd7eb-2100-0000-822f-ac81b00a0000 pid=2736 execve guuid=26a53dec-2100-0000-822f-ac81b20a0000 pid=2738 /home/sandbox/x86 net guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=26a53dec-2100-0000-822f-ac81b20a0000 pid=2738 execve guuid=02a667ff-2100-0000-822f-ac81e20a0000 pid=2786 /usr/bin/wget net send-data write-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=02a667ff-2100-0000-822f-ac81e20a0000 pid=2786 execve guuid=c402f107-2200-0000-822f-ac81f30a0000 pid=2803 /usr/bin/chmod guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=c402f107-2200-0000-822f-ac81f30a0000 pid=2803 execve guuid=9c953608-2200-0000-822f-ac81f40a0000 pid=2804 /usr/bin/dash guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=9c953608-2200-0000-822f-ac81f40a0000 pid=2804 clone guuid=4c00f009-2200-0000-822f-ac81f60a0000 pid=2806 /usr/bin/rm delete-file guuid=b291329d-2100-0000-822f-ac81d1090000 pid=2513->guuid=4c00f009-2200-0000-822f-ac81f60a0000 pid=2806 execve 1859fa66-700c-573f-a69b-967c040da2df 161.97.74.69:80 guuid=09e6969d-2100-0000-822f-ac81d2090000 pid=2514->1859fa66-700c-573f-a69b-967c040da2df send: 139B guuid=8e4c91a6-2100-0000-822f-ac81e2090000 pid=2530->1859fa66-700c-573f-a69b-967c040da2df send: 140B guuid=b41f80ad-2100-0000-822f-ac81f3090000 pid=2547->1859fa66-700c-573f-a69b-967c040da2df send: 140B guuid=7b706bb2-2100-0000-822f-ac81040a0000 pid=2564->1859fa66-700c-573f-a69b-967c040da2df send: 140B guuid=2902e5b9-2100-0000-822f-ac811a0a0000 pid=2586->1859fa66-700c-573f-a69b-967c040da2df send: 140B guuid=338f5ac3-2100-0000-822f-ac81360a0000 pid=2614->1859fa66-700c-573f-a69b-967c040da2df send: 140B guuid=1dbfb6c8-2100-0000-822f-ac814a0a0000 pid=2634->1859fa66-700c-573f-a69b-967c040da2df send: 140B guuid=d43c12d4-2100-0000-822f-ac816c0a0000 pid=2668->1859fa66-700c-573f-a69b-967c040da2df send: 139B guuid=432e09db-2100-0000-822f-ac817d0a0000 pid=2685->1859fa66-700c-573f-a69b-967c040da2df send: 139B guuid=2ab470e3-2100-0000-822f-ac81960a0000 pid=2710->1859fa66-700c-573f-a69b-967c040da2df send: 139B guuid=e7053ee8-2100-0000-822f-ac81a70a0000 pid=2727->1859fa66-700c-573f-a69b-967c040da2df send: 139B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=26a53dec-2100-0000-822f-ac81b20a0000 pid=2738->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=494f5aff-2100-0000-822f-ac81e00a0000 pid=2784 /home/sandbox/x86 guuid=26a53dec-2100-0000-822f-ac81b20a0000 pid=2738->guuid=494f5aff-2100-0000-822f-ac81e00a0000 pid=2784 clone guuid=0ac260ff-2100-0000-822f-ac81e10a0000 pid=2785 /home/sandbox/x86 net send-data zombie guuid=26a53dec-2100-0000-822f-ac81b20a0000 pid=2738->guuid=0ac260ff-2100-0000-822f-ac81e10a0000 pid=2785 clone guuid=0ac260ff-2100-0000-822f-ac81e10a0000 pid=2785->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con dfbb6132-9b3a-5fcc-ae73-0a5bea22ee6b 87.121.84.220:61459 guuid=0ac260ff-2100-0000-822f-ac81e10a0000 pid=2785->dfbb6132-9b3a-5fcc-ae73-0a5bea22ee6b send: 43B guuid=02a667ff-2100-0000-822f-ac81e20a0000 pid=2786->1859fa66-700c-573f-a69b-967c040da2df send: 142B
Threat name:
Linux.Trojan.Alevaul
Status:
Malicious
First seen:
2025-08-21 06:35:33 UTC
File Type:
Text (Shell)
AV detection:
20 of 38 (52.63%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 163a2c04fa5a1a8607a3aa00791c044bf68f7b20d610d555f9991aca861028ac

(this sample)

  
Delivery method
Distributed via web download

Comments