MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1cf3b8d29609d0c4be3e81b39f83ca5de32f13b4ac309e397aca1d451a56339f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 1cf3b8d29609d0c4be3e81b39f83ca5de32f13b4ac309e397aca1d451a56339f
SHA3-384 hash: 96079b5b4253ed8d3d8baf53a26cabee527c401ec4f857a0b44b65aab01fcc2a463a62108164a40f9e3f91e4790aeae3
SHA1 hash: 70c7ccbcf9c63002026f1c1d31a5fff56d01b853
MD5 hash: 19a254a1c12a929b63cd0f97216a349c
humanhash: autumn-echo-friend-arizona
File name:t
Download: download sample
Signature Mirai
File size:992 bytes
First seen:2026-07-17 23:09:28 UTC
Last seen:2026-07-18 21:59:10 UTC
File type: sh
MIME type:text/plain
ssdeep 12:QvWXOp3dKU2hCUKAMzhKdqxrpZDAgHW80yAhHW80QA7HW80YIjDAYIMHW80/DA4X:QvQhBh9M0onZVWJWJW4AhWfNWW
TLSH T14911B49F818244D12F84EA89B587083BB1055BDE39F34EDCAC0E3D72649D84CB931E69
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://205.237.110.232/tvt/mips580ffce9b7b58f51cc4db2973f83300e79ee67583f59a96ebdbb4cc0c65710fb Miraielf gafgyt mirai ua-wget
http://205.237.110.232/tvt/mpsln/an/aelf mirai ua-wget
http://205.237.110.232/tvt/arm477c66e0e4a9353c29d5aa3b5d750ffabee1a65496401f4303b9b874c13e6ce5 Miraielf gafgyt mirai ua-wget
http://205.237.110.232/tvt/arm5abbeaa41254ac515bb1c2218485f5f6339cdfc83796ca31e260935e81373fd06 Miraielf mirai ua-wget
http://205.237.110.232/tvt/arm7769bd770366308fa1f6edbb235da42b5a6296ab0d3c5d672f291ae1cc566106d Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
442
# of downloads :
15
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-07-17T21:07:00Z UTC
Last seen:
2026-07-18T15:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a3939035-1a00-0000-bab7-db0e4a0d0000 pid=3402 /usr/bin/sudo guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403 /tmp/sample.bin guuid=a3939035-1a00-0000-bab7-db0e4a0d0000 pid=3402->guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403 execve guuid=7e87ca3c-1a00-0000-bab7-db0e590d0000 pid=3417 /usr/bin/dash guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=7e87ca3c-1a00-0000-bab7-db0e590d0000 pid=3417 clone guuid=41e13b59-1a00-0000-bab7-db0e730d0000 pid=3443 /usr/bin/chmod guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=41e13b59-1a00-0000-bab7-db0e730d0000 pid=3443 execve guuid=d044185a-1a00-0000-bab7-db0e740d0000 pid=3444 /usr/bin/dash guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=d044185a-1a00-0000-bab7-db0e740d0000 pid=3444 clone guuid=4ff75e5b-1a00-0000-bab7-db0e760d0000 pid=3446 /usr/bin/rm delete-file guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=4ff75e5b-1a00-0000-bab7-db0e760d0000 pid=3446 execve guuid=140ce85b-1a00-0000-bab7-db0e770d0000 pid=3447 /usr/bin/dash guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=140ce85b-1a00-0000-bab7-db0e770d0000 pid=3447 clone guuid=9090ab6b-1a00-0000-bab7-db0ea10d0000 pid=3489 /usr/bin/chmod guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=9090ab6b-1a00-0000-bab7-db0ea10d0000 pid=3489 execve guuid=92d9036c-1a00-0000-bab7-db0ea30d0000 pid=3491 /usr/bin/dash guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=92d9036c-1a00-0000-bab7-db0ea30d0000 pid=3491 clone guuid=c50e8e6c-1a00-0000-bab7-db0ea60d0000 pid=3494 /usr/bin/rm delete-file guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=c50e8e6c-1a00-0000-bab7-db0ea60d0000 pid=3494 execve guuid=e47ffe6c-1a00-0000-bab7-db0ea80d0000 pid=3496 /usr/bin/dash guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=e47ffe6c-1a00-0000-bab7-db0ea80d0000 pid=3496 clone guuid=f8b6627b-1a00-0000-bab7-db0eca0d0000 pid=3530 /usr/bin/chmod guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=f8b6627b-1a00-0000-bab7-db0eca0d0000 pid=3530 execve guuid=d2adb77b-1a00-0000-bab7-db0ecc0d0000 pid=3532 /usr/bin/dash guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=d2adb77b-1a00-0000-bab7-db0ecc0d0000 pid=3532 clone guuid=2221c47c-1a00-0000-bab7-db0ed10d0000 pid=3537 /usr/bin/rm delete-file guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=2221c47c-1a00-0000-bab7-db0ed10d0000 pid=3537 execve guuid=b634027d-1a00-0000-bab7-db0ed30d0000 pid=3539 /usr/bin/dash guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=b634027d-1a00-0000-bab7-db0ed30d0000 pid=3539 clone guuid=5ae7fb8a-1a00-0000-bab7-db0efd0d0000 pid=3581 /usr/bin/chmod guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=5ae7fb8a-1a00-0000-bab7-db0efd0d0000 pid=3581 execve guuid=896f578b-1a00-0000-bab7-db0eff0d0000 pid=3583 /usr/bin/dash guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=896f578b-1a00-0000-bab7-db0eff0d0000 pid=3583 clone guuid=e19ac48c-1a00-0000-bab7-db0e050e0000 pid=3589 /usr/bin/rm delete-file guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=e19ac48c-1a00-0000-bab7-db0e050e0000 pid=3589 execve guuid=64770f8d-1a00-0000-bab7-db0e090e0000 pid=3593 /usr/bin/dash guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=64770f8d-1a00-0000-bab7-db0e090e0000 pid=3593 clone guuid=1ca7729a-1a00-0000-bab7-db0e1d0e0000 pid=3613 /usr/bin/chmod guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=1ca7729a-1a00-0000-bab7-db0e1d0e0000 pid=3613 execve guuid=66e7ae9a-1a00-0000-bab7-db0e1e0e0000 pid=3614 /usr/bin/dash guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=66e7ae9a-1a00-0000-bab7-db0e1e0e0000 pid=3614 clone guuid=d45bb59c-1a00-0000-bab7-db0e200e0000 pid=3616 /usr/bin/rm delete-file guuid=89ba3937-1a00-0000-bab7-db0e4b0d0000 pid=3403->guuid=d45bb59c-1a00-0000-bab7-db0e200e0000 pid=3616 execve guuid=aaa41747-1a00-0000-bab7-db0e5a0d0000 pid=3418 /usr/bin/wget net send-data write-file guuid=7e87ca3c-1a00-0000-bab7-db0e590d0000 pid=3417->guuid=aaa41747-1a00-0000-bab7-db0e5a0d0000 pid=3418 execve fa76a0f2-99b2-55a3-830c-43db003be0f4 205.237.110.232:80 guuid=aaa41747-1a00-0000-bab7-db0e5a0d0000 pid=3418->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 138B guuid=acb2fe5b-1a00-0000-bab7-db0e780d0000 pid=3448 /usr/bin/wget net send-data write-file guuid=140ce85b-1a00-0000-bab7-db0e770d0000 pid=3447->guuid=acb2fe5b-1a00-0000-bab7-db0e780d0000 pid=3448 execve guuid=acb2fe5b-1a00-0000-bab7-db0e780d0000 pid=3448->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 138B guuid=69170c6d-1a00-0000-bab7-db0ea90d0000 pid=3497 /usr/bin/wget net send-data write-file guuid=e47ffe6c-1a00-0000-bab7-db0ea80d0000 pid=3496->guuid=69170c6d-1a00-0000-bab7-db0ea90d0000 pid=3497 execve guuid=69170c6d-1a00-0000-bab7-db0ea90d0000 pid=3497->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 137B guuid=600f0a7d-1a00-0000-bab7-db0ed40d0000 pid=3540 /usr/bin/wget net send-data write-file guuid=b634027d-1a00-0000-bab7-db0ed30d0000 pid=3539->guuid=600f0a7d-1a00-0000-bab7-db0ed40d0000 pid=3540 execve guuid=600f0a7d-1a00-0000-bab7-db0ed40d0000 pid=3540->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 138B guuid=584f1a8d-1a00-0000-bab7-db0e0a0e0000 pid=3594 /usr/bin/wget net send-data write-file guuid=64770f8d-1a00-0000-bab7-db0e090e0000 pid=3593->guuid=584f1a8d-1a00-0000-bab7-db0e0a0e0000 pid=3594 execve guuid=584f1a8d-1a00-0000-bab7-db0e0a0e0000 pid=3594->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 138B
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-18 02:19:02 UTC
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1cf3b8d29609d0c4be3e81b39f83ca5de32f13b4ac309e397aca1d451a56339f

(this sample)

  
Delivery method
Distributed via web download

Comments