MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1c77a5531b83f013596e2e68b7973ba16e3494507b469e2845348f05a6c19e90. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 1c77a5531b83f013596e2e68b7973ba16e3494507b469e2845348f05a6c19e90
SHA3-384 hash: 4ae1f0999d7631b4b37f7aab3ba9d12600b40a431efaf895cd2e7141cacbc1f7ee6ec72d321ff37c2409246993edd518
SHA1 hash: b2bcf382a523a07d1e0a99acdf2198ee198daca8
MD5 hash: ce57d6c9e66647b278cf860f80348e57
humanhash: undress-snake-beryllium-montana
File name:bins.sh
Download: download sample
Signature Mirai
File size:523 bytes
First seen:2025-07-08 08:06:35 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:lOnFflE0FKeQiMxweQiMBviMuiM6eL9cbnMAMQrAs8peNNgPcbZus6R5evD5MAM2:v0F6kTNnr7NYxRYD5N7Q5q
TLSH T1ABF0B4C80625243616D39A4B1727C988F3968459EC131DF81C9DE8D2A89AC221D2CEBD
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.42.88.254/0x83911d24Fx.sh6bea5bfb85bd161d88fa18028f6fd759f43da6840877d7e632f5d548857c9a55 Miraicensys mirai sh ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
downloader shellcode agent
Status:
terminated
Behavior Graph:
%3 guuid=f7df1151-1a00-0000-0902-5f57250c0000 pid=3109 /usr/bin/sudo guuid=6e998d53-1a00-0000-0902-5f572c0c0000 pid=3116 /tmp/sample.bin guuid=f7df1151-1a00-0000-0902-5f57250c0000 pid=3109->guuid=6e998d53-1a00-0000-0902-5f572c0c0000 pid=3116 execve guuid=daaed353-1a00-0000-0902-5f572e0c0000 pid=3118 /usr/bin/wget net send-data write-file guuid=6e998d53-1a00-0000-0902-5f572c0c0000 pid=3116->guuid=daaed353-1a00-0000-0902-5f572e0c0000 pid=3118 execve guuid=d995b858-1a00-0000-0902-5f573e0c0000 pid=3134 /usr/bin/curl net send-data write-file guuid=6e998d53-1a00-0000-0902-5f572c0c0000 pid=3116->guuid=d995b858-1a00-0000-0902-5f573e0c0000 pid=3134 execve guuid=55431661-1a00-0000-0902-5f57530c0000 pid=3155 /usr/bin/chmod guuid=6e998d53-1a00-0000-0902-5f572c0c0000 pid=3116->guuid=55431661-1a00-0000-0902-5f57530c0000 pid=3155 execve guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158 /usr/bin/dash guuid=6e998d53-1a00-0000-0902-5f572c0c0000 pid=3116->guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158 execve 95b00e83-4876-5de1-b149-99b92eaf5c8d 89.42.88.254:80 guuid=daaed353-1a00-0000-0902-5f572e0c0000 pid=3118->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 142B guuid=d995b858-1a00-0000-0902-5f573e0c0000 pid=3134->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 91B guuid=9ff1c061-1a00-0000-0902-5f57570c0000 pid=3159 /usr/bin/wget net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=9ff1c061-1a00-0000-0902-5f57570c0000 pid=3159 execve guuid=a337c677-1a00-0000-0902-5f575d0c0000 pid=3165 /usr/bin/curl net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=a337c677-1a00-0000-0902-5f575d0c0000 pid=3165 execve guuid=ecc7aa7d-1a00-0000-0902-5f57670c0000 pid=3175 /usr/bin/cat guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=ecc7aa7d-1a00-0000-0902-5f57670c0000 pid=3175 execve guuid=d3d5127e-1a00-0000-0902-5f57680c0000 pid=3176 /usr/bin/chmod guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=d3d5127e-1a00-0000-0902-5f57680c0000 pid=3176 execve guuid=c306517e-1a00-0000-0902-5f57690c0000 pid=3177 /tmp/x net guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=c306517e-1a00-0000-0902-5f57690c0000 pid=3177 execve guuid=7934787e-1a00-0000-0902-5f576b0c0000 pid=3179 /usr/bin/wget net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=7934787e-1a00-0000-0902-5f576b0c0000 pid=3179 execve guuid=b7753f84-1a00-0000-0902-5f57740c0000 pid=3188 /usr/bin/curl net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=b7753f84-1a00-0000-0902-5f57740c0000 pid=3188 execve guuid=1b8db28c-1a00-0000-0902-5f57750c0000 pid=3189 /usr/bin/chmod guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=1b8db28c-1a00-0000-0902-5f57750c0000 pid=3189 execve guuid=dd761b8d-1a00-0000-0902-5f57760c0000 pid=3190 /tmp/x net guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=dd761b8d-1a00-0000-0902-5f57760c0000 pid=3190 execve guuid=c3c084f1-1c00-0000-0902-5f571b130000 pid=4891 /usr/bin/wget net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=c3c084f1-1c00-0000-0902-5f571b130000 pid=4891 execve guuid=44cfcbf7-1c00-0000-0902-5f572e130000 pid=4910 /usr/bin/curl net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=44cfcbf7-1c00-0000-0902-5f572e130000 pid=4910 execve guuid=61243a06-1d00-0000-0902-5f575c130000 pid=4956 /usr/bin/chmod guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=61243a06-1d00-0000-0902-5f575c130000 pid=4956 execve guuid=87cce219-1d00-0000-0902-5f57a2130000 pid=5026 /tmp/x net guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=87cce219-1d00-0000-0902-5f57a2130000 pid=5026 execve guuid=d3f10580-1f00-0000-0902-5f5792140000 pid=5266 /usr/bin/wget net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=d3f10580-1f00-0000-0902-5f5792140000 pid=5266 execve guuid=fe3a7c84-1f00-0000-0902-5f5794140000 pid=5268 /usr/bin/curl net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=fe3a7c84-1f00-0000-0902-5f5794140000 pid=5268 execve guuid=21d8918a-1f00-0000-0902-5f5796140000 pid=5270 /usr/bin/chmod guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=21d8918a-1f00-0000-0902-5f5796140000 pid=5270 execve guuid=6489ca8a-1f00-0000-0902-5f5797140000 pid=5271 /tmp/x net guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=6489ca8a-1f00-0000-0902-5f5797140000 pid=5271 execve guuid=e21717f2-2100-0000-0902-5f57ab140000 pid=5291 /usr/bin/wget net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=e21717f2-2100-0000-0902-5f57ab140000 pid=5291 execve guuid=5f1d5af6-2100-0000-0902-5f57ad140000 pid=5293 /usr/bin/curl net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=5f1d5af6-2100-0000-0902-5f57ad140000 pid=5293 execve guuid=c7b19cfb-2100-0000-0902-5f57ae140000 pid=5294 /usr/bin/chmod guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=c7b19cfb-2100-0000-0902-5f57ae140000 pid=5294 execve guuid=7125dafb-2100-0000-0902-5f57af140000 pid=5295 /tmp/x net guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=7125dafb-2100-0000-0902-5f57af140000 pid=5295 execve guuid=31f53364-2400-0000-0902-5f57b1140000 pid=5297 /usr/bin/wget net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=31f53364-2400-0000-0902-5f57b1140000 pid=5297 execve guuid=d450d568-2400-0000-0902-5f57b3140000 pid=5299 /usr/bin/curl net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=d450d568-2400-0000-0902-5f57b3140000 pid=5299 execve guuid=91b13a6e-2400-0000-0902-5f57b4140000 pid=5300 /usr/bin/chmod guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=91b13a6e-2400-0000-0902-5f57b4140000 pid=5300 execve guuid=040e746e-2400-0000-0902-5f57b5140000 pid=5301 /tmp/x net guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=040e746e-2400-0000-0902-5f57b5140000 pid=5301 execve guuid=efead6da-2600-0000-0902-5f57b7140000 pid=5303 /usr/bin/wget net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=efead6da-2600-0000-0902-5f57b7140000 pid=5303 execve guuid=8a7040e0-2600-0000-0902-5f57b9140000 pid=5305 /usr/bin/curl net send-data write-file guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=8a7040e0-2600-0000-0902-5f57b9140000 pid=5305 execve guuid=0f8e40e7-2600-0000-0902-5f57ba140000 pid=5306 /usr/bin/chmod guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=0f8e40e7-2600-0000-0902-5f57ba140000 pid=5306 execve guuid=aae0aae7-2600-0000-0902-5f57bb140000 pid=5307 /tmp/x net guuid=6d408261-1a00-0000-0902-5f57560c0000 pid=3158->guuid=aae0aae7-2600-0000-0902-5f57bb140000 pid=5307 execve guuid=9ff1c061-1a00-0000-0902-5f57570c0000 pid=3159->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 142B guuid=a337c677-1a00-0000-0902-5f575d0c0000 pid=3165->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 91B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=c306517e-1a00-0000-0902-5f57690c0000 pid=3177->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bc496f7e-1a00-0000-0902-5f576a0c0000 pid=3178 /tmp/x net zombie guuid=c306517e-1a00-0000-0902-5f57690c0000 pid=3177->guuid=bc496f7e-1a00-0000-0902-5f576a0c0000 pid=3178 clone 7cfb7ecf-865e-539b-8afd-0e060816e033 91.208.184.248:1302 guuid=bc496f7e-1a00-0000-0902-5f576a0c0000 pid=3178->7cfb7ecf-865e-539b-8afd-0e060816e033 con guuid=f3cf7d7e-1a00-0000-0902-5f576c0c0000 pid=3180 /tmp/x guuid=bc496f7e-1a00-0000-0902-5f576a0c0000 pid=3178->guuid=f3cf7d7e-1a00-0000-0902-5f576c0c0000 pid=3180 clone guuid=7934787e-1a00-0000-0902-5f576b0c0000 pid=3179->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 143B guuid=b7753f84-1a00-0000-0902-5f57740c0000 pid=3188->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 92B guuid=dd761b8d-1a00-0000-0902-5f57760c0000 pid=3190->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 836dce14-4611-5ec0-94fd-a9232d5a3558 0.0.0.0:9473 guuid=dd761b8d-1a00-0000-0902-5f57760c0000 pid=3190->836dce14-4611-5ec0-94fd-a9232d5a3558 con guuid=fbd272f1-1c00-0000-0902-5f5718130000 pid=4888 /tmp/x net zombie guuid=dd761b8d-1a00-0000-0902-5f57760c0000 pid=3190->guuid=fbd272f1-1c00-0000-0902-5f5718130000 pid=4888 clone guuid=fbd272f1-1c00-0000-0902-5f5718130000 pid=4888->7cfb7ecf-865e-539b-8afd-0e060816e033 con guuid=21d07ff1-1c00-0000-0902-5f5719130000 pid=4889 /tmp/x guuid=fbd272f1-1c00-0000-0902-5f5718130000 pid=4888->guuid=21d07ff1-1c00-0000-0902-5f5719130000 pid=4889 clone guuid=c3c084f1-1c00-0000-0902-5f571b130000 pid=4891->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 143B guuid=44cfcbf7-1c00-0000-0902-5f572e130000 pid=4910->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 92B guuid=87cce219-1d00-0000-0902-5f57a2130000 pid=5026->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=87cce219-1d00-0000-0902-5f57a2130000 pid=5026->836dce14-4611-5ec0-94fd-a9232d5a3558 con guuid=e1b5fa7f-1f00-0000-0902-5f5791140000 pid=5265 /tmp/x net zombie guuid=87cce219-1d00-0000-0902-5f57a2130000 pid=5026->guuid=e1b5fa7f-1f00-0000-0902-5f5791140000 pid=5265 clone guuid=e1b5fa7f-1f00-0000-0902-5f5791140000 pid=5265->7cfb7ecf-865e-539b-8afd-0e060816e033 con guuid=1efc0e80-1f00-0000-0902-5f5793140000 pid=5267 /tmp/x guuid=e1b5fa7f-1f00-0000-0902-5f5791140000 pid=5265->guuid=1efc0e80-1f00-0000-0902-5f5793140000 pid=5267 clone guuid=d3f10580-1f00-0000-0902-5f5792140000 pid=5266->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 142B guuid=fe3a7c84-1f00-0000-0902-5f5794140000 pid=5268->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 91B guuid=6489ca8a-1f00-0000-0902-5f5797140000 pid=5271->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6489ca8a-1f00-0000-0902-5f5797140000 pid=5271->836dce14-4611-5ec0-94fd-a9232d5a3558 con guuid=41720af2-2100-0000-0902-5f57aa140000 pid=5290 /tmp/x net zombie guuid=6489ca8a-1f00-0000-0902-5f5797140000 pid=5271->guuid=41720af2-2100-0000-0902-5f57aa140000 pid=5290 clone guuid=41720af2-2100-0000-0902-5f57aa140000 pid=5290->7cfb7ecf-865e-539b-8afd-0e060816e033 con guuid=36b81bf2-2100-0000-0902-5f57ac140000 pid=5292 /tmp/x guuid=41720af2-2100-0000-0902-5f57aa140000 pid=5290->guuid=36b81bf2-2100-0000-0902-5f57ac140000 pid=5292 clone guuid=e21717f2-2100-0000-0902-5f57ab140000 pid=5291->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 143B guuid=5f1d5af6-2100-0000-0902-5f57ad140000 pid=5293->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 92B guuid=7125dafb-2100-0000-0902-5f57af140000 pid=5295->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7125dafb-2100-0000-0902-5f57af140000 pid=5295->836dce14-4611-5ec0-94fd-a9232d5a3558 con guuid=a29b2a64-2400-0000-0902-5f57b0140000 pid=5296 /tmp/x net zombie guuid=7125dafb-2100-0000-0902-5f57af140000 pid=5295->guuid=a29b2a64-2400-0000-0902-5f57b0140000 pid=5296 clone guuid=a29b2a64-2400-0000-0902-5f57b0140000 pid=5296->7cfb7ecf-865e-539b-8afd-0e060816e033 con guuid=46503a64-2400-0000-0902-5f57b2140000 pid=5298 /tmp/x guuid=a29b2a64-2400-0000-0902-5f57b0140000 pid=5296->guuid=46503a64-2400-0000-0902-5f57b2140000 pid=5298 clone guuid=31f53364-2400-0000-0902-5f57b1140000 pid=5297->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 143B guuid=d450d568-2400-0000-0902-5f57b3140000 pid=5299->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 92B guuid=040e746e-2400-0000-0902-5f57b5140000 pid=5301->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=040e746e-2400-0000-0902-5f57b5140000 pid=5301->836dce14-4611-5ec0-94fd-a9232d5a3558 con guuid=7c5ec9da-2600-0000-0902-5f57b6140000 pid=5302 /tmp/x guuid=040e746e-2400-0000-0902-5f57b5140000 pid=5301->guuid=7c5ec9da-2600-0000-0902-5f57b6140000 pid=5302 clone guuid=4ce9deda-2600-0000-0902-5f57b8140000 pid=5304 /tmp/x guuid=7c5ec9da-2600-0000-0902-5f57b6140000 pid=5302->guuid=4ce9deda-2600-0000-0902-5f57b8140000 pid=5304 clone guuid=efead6da-2600-0000-0902-5f57b7140000 pid=5303->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 143B guuid=8a7040e0-2600-0000-0902-5f57b9140000 pid=5305->95b00e83-4876-5de1-b149-99b92eaf5c8d send: 92B guuid=aae0aae7-2600-0000-0902-5f57bb140000 pid=5307->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=aae0aae7-2600-0000-0902-5f57bb140000 pid=5307->836dce14-4611-5ec0-94fd-a9232d5a3558 con
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-07-08 08:07:31 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1c77a5531b83f013596e2e68b7973ba16e3494507b469e2845348f05a6c19e90

(this sample)

  
Delivery method
Distributed via web download

Comments