MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1d957b711a2616ca00a93c09fe15eaddcf8484ac2c2e4c758c750eef89fc988e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 1d957b711a2616ca00a93c09fe15eaddcf8484ac2c2e4c758c750eef89fc988e
SHA3-384 hash: 772276dcaa1ff5c903ce2eb3abb56e29836f19d5cea585994b64437572123d8d830ddb90972486758345074025565cd4
SHA1 hash: 6f5e520160f0279fa3eb2b4d71c26fec3d3cde20
MD5 hash: 1f841ed637e7e72ce28cac6050157299
humanhash: illinois-equal-hamper-lithium
File name:wget.sh
Download: download sample
Signature Mirai
File size:1'256 bytes
First seen:2025-10-04 13:41:16 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:0UvD6x+VUvDucArE+VUvDoNI+3BEA+VUvDxTKRiH+VUvDGNZIq+VUvDpQi+VUvDE:rNI6VKVN+WmcPJoA3Axn
TLSH T195211BFF03115147841DCFC230AA4711978A82A3A4AC4BB9ABDE4C376E84EC5EC49E1F
Magika csv
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.70.174/00101010101001/morte.arm92018fdead346046615dfc992fb7c6c84340f9f05f4c2a98906879ba19d9d404 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.arm5c89794c5ab693e93db164f0d4523b13934216038cd19ca0365a728ad62d5e3b1 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.arm65803b854959a53e11c8674e88f4922c99549406f23268af4a9c019dfd7d7423f Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.arm7bf45d7db954ae16aa60b9dc7a99341525c9ef9afe154eb7f433ca4a37e1c5e13 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.m68k2f3fbe56d018982fc668c68142ba7c6543650b0269e99384ae6b2ee6bf6d61de Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.mips01bcf55b2cdb1b8242e2aee4223d8b7796f388bf866a54cb554732b89497b15c Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.mpsle8360f4a9be84d5c3c03c774b785e3f9e66a5354dc4b002bf337c2f4f5e4d593 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.ppc22a4b8f57d576892149e04092dfe249438d28a952a7a697030361d94d0a038a5 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.sh4608c89ba1d6caa1cdf1f2fa75d6a6ca259da286bb268495121f8e25d7c9ceef4 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.spc617fc91098b7ff2ed40cfc855ef7cdb9679472a4732601455110e0e62b51a23d Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.x8673d3e88abf499c1f5c15baee9d2a3e79c58a76cec9ce41b379552964270cc787 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.x86_64a9607723c7ee84e7ad4f75738141c805f73783c72b670da534cb74072911783f Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-10-04T13:10:00Z UTC
Last seen:
2025-10-04T15:50:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a8e11bfa-1e00-0000-65b4-afb1120b0000 pid=2834 /usr/bin/sudo guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839 /tmp/sample.bin guuid=a8e11bfa-1e00-0000-65b4-afb1120b0000 pid=2834->guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839 execve guuid=1aee89fc-1e00-0000-65b4-afb1190b0000 pid=2841 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=1aee89fc-1e00-0000-65b4-afb1190b0000 pid=2841 execve guuid=bcedf403-1f00-0000-65b4-afb1240b0000 pid=2852 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=bcedf403-1f00-0000-65b4-afb1240b0000 pid=2852 execve guuid=61c53004-1f00-0000-65b4-afb1260b0000 pid=2854 /usr/bin/dash guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=61c53004-1f00-0000-65b4-afb1260b0000 pid=2854 clone guuid=03b5ac04-1f00-0000-65b4-afb1290b0000 pid=2857 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=03b5ac04-1f00-0000-65b4-afb1290b0000 pid=2857 execve guuid=9a184908-1f00-0000-65b4-afb1330b0000 pid=2867 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=9a184908-1f00-0000-65b4-afb1330b0000 pid=2867 execve guuid=0ef19108-1f00-0000-65b4-afb1350b0000 pid=2869 /usr/bin/dash guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=0ef19108-1f00-0000-65b4-afb1350b0000 pid=2869 clone guuid=85202c09-1f00-0000-65b4-afb1380b0000 pid=2872 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=85202c09-1f00-0000-65b4-afb1380b0000 pid=2872 execve guuid=3ecdc20d-1f00-0000-65b4-afb1450b0000 pid=2885 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=3ecdc20d-1f00-0000-65b4-afb1450b0000 pid=2885 execve guuid=ae8ffc0d-1f00-0000-65b4-afb1470b0000 pid=2887 /usr/bin/dash guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=ae8ffc0d-1f00-0000-65b4-afb1470b0000 pid=2887 clone guuid=1cfb960e-1f00-0000-65b4-afb14a0b0000 pid=2890 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=1cfb960e-1f00-0000-65b4-afb14a0b0000 pid=2890 execve guuid=4fed9415-1f00-0000-65b4-afb1590b0000 pid=2905 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=4fed9415-1f00-0000-65b4-afb1590b0000 pid=2905 execve guuid=d116f815-1f00-0000-65b4-afb15a0b0000 pid=2906 /usr/bin/dash guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=d116f815-1f00-0000-65b4-afb15a0b0000 pid=2906 clone guuid=960b9e16-1f00-0000-65b4-afb15f0b0000 pid=2911 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=960b9e16-1f00-0000-65b4-afb15f0b0000 pid=2911 execve guuid=8005e51b-1f00-0000-65b4-afb16a0b0000 pid=2922 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=8005e51b-1f00-0000-65b4-afb16a0b0000 pid=2922 execve guuid=028a641c-1f00-0000-65b4-afb16c0b0000 pid=2924 /usr/bin/dash guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=028a641c-1f00-0000-65b4-afb16c0b0000 pid=2924 clone guuid=c96ffb1c-1f00-0000-65b4-afb1700b0000 pid=2928 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=c96ffb1c-1f00-0000-65b4-afb1700b0000 pid=2928 execve guuid=1e1b5021-1f00-0000-65b4-afb1790b0000 pid=2937 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=1e1b5021-1f00-0000-65b4-afb1790b0000 pid=2937 execve guuid=1482c921-1f00-0000-65b4-afb17a0b0000 pid=2938 /usr/bin/dash guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=1482c921-1f00-0000-65b4-afb17a0b0000 pid=2938 clone guuid=ff5c5b22-1f00-0000-65b4-afb17e0b0000 pid=2942 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=ff5c5b22-1f00-0000-65b4-afb17e0b0000 pid=2942 execve guuid=5a1dad26-1f00-0000-65b4-afb1800b0000 pid=2944 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=5a1dad26-1f00-0000-65b4-afb1800b0000 pid=2944 execve guuid=55ac0027-1f00-0000-65b4-afb1820b0000 pid=2946 /usr/bin/dash guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=55ac0027-1f00-0000-65b4-afb1820b0000 pid=2946 clone guuid=bbbfea28-1f00-0000-65b4-afb1870b0000 pid=2951 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=bbbfea28-1f00-0000-65b4-afb1870b0000 pid=2951 execve guuid=41cf092e-1f00-0000-65b4-afb1910b0000 pid=2961 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=41cf092e-1f00-0000-65b4-afb1910b0000 pid=2961 execve guuid=175f4a2e-1f00-0000-65b4-afb1930b0000 pid=2963 /usr/bin/dash guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=175f4a2e-1f00-0000-65b4-afb1930b0000 pid=2963 clone guuid=5a45512f-1f00-0000-65b4-afb1950b0000 pid=2965 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=5a45512f-1f00-0000-65b4-afb1950b0000 pid=2965 execve guuid=0da09933-1f00-0000-65b4-afb19d0b0000 pid=2973 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=0da09933-1f00-0000-65b4-afb19d0b0000 pid=2973 execve guuid=261ae533-1f00-0000-65b4-afb19e0b0000 pid=2974 /usr/bin/dash guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=261ae533-1f00-0000-65b4-afb19e0b0000 pid=2974 clone guuid=7878f633-1f00-0000-65b4-afb19f0b0000 pid=2975 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=7878f633-1f00-0000-65b4-afb19f0b0000 pid=2975 execve guuid=fb3a5838-1f00-0000-65b4-afb1a40b0000 pid=2980 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=fb3a5838-1f00-0000-65b4-afb1a40b0000 pid=2980 execve guuid=e234b638-1f00-0000-65b4-afb1a60b0000 pid=2982 /usr/bin/dash guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=e234b638-1f00-0000-65b4-afb1a60b0000 pid=2982 clone guuid=607d433b-1f00-0000-65b4-afb1ad0b0000 pid=2989 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=607d433b-1f00-0000-65b4-afb1ad0b0000 pid=2989 execve guuid=0c7d7540-1f00-0000-65b4-afb1b70b0000 pid=2999 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=0c7d7540-1f00-0000-65b4-afb1b70b0000 pid=2999 execve guuid=429cc040-1f00-0000-65b4-afb1b80b0000 pid=3000 /usr/bin/dash guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=429cc040-1f00-0000-65b4-afb1b80b0000 pid=3000 clone guuid=541b6641-1f00-0000-65b4-afb1bb0b0000 pid=3003 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=541b6641-1f00-0000-65b4-afb1bb0b0000 pid=3003 execve guuid=46df4245-1f00-0000-65b4-afb1c40b0000 pid=3012 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=46df4245-1f00-0000-65b4-afb1c40b0000 pid=3012 execve guuid=eb36a345-1f00-0000-65b4-afb1c50b0000 pid=3013 /home/sandbox/morte.x86 net guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=eb36a345-1f00-0000-65b4-afb1c50b0000 pid=3013 execve guuid=99997b72-2000-0000-65b4-afb1260e0000 pid=3622 /usr/bin/wget net send-data write-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=99997b72-2000-0000-65b4-afb1260e0000 pid=3622 execve guuid=ce12ee77-2000-0000-65b4-afb1350e0000 pid=3637 /usr/bin/chmod guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=ce12ee77-2000-0000-65b4-afb1350e0000 pid=3637 execve guuid=94474378-2000-0000-65b4-afb1370e0000 pid=3639 /home/sandbox/morte.x86_64 mprotect-exec net guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=94474378-2000-0000-65b4-afb1370e0000 pid=3639 execve guuid=9fe816f0-2000-0000-65b4-afb1750f0000 pid=3957 /usr/bin/rm delete-file guuid=07f7fefb-1e00-0000-65b4-afb1170b0000 pid=2839->guuid=9fe816f0-2000-0000-65b4-afb1750f0000 pid=3957 execve 351b6f95-01a4-5d80-a90f-080c92984efa 196.251.70.174:80 guuid=1aee89fc-1e00-0000-65b4-afb1190b0000 pid=2841->351b6f95-01a4-5d80-a90f-080c92984efa send: 153B guuid=03b5ac04-1f00-0000-65b4-afb1290b0000 pid=2857->351b6f95-01a4-5d80-a90f-080c92984efa send: 154B guuid=85202c09-1f00-0000-65b4-afb1380b0000 pid=2872->351b6f95-01a4-5d80-a90f-080c92984efa send: 154B guuid=1cfb960e-1f00-0000-65b4-afb14a0b0000 pid=2890->351b6f95-01a4-5d80-a90f-080c92984efa send: 154B guuid=960b9e16-1f00-0000-65b4-afb15f0b0000 pid=2911->351b6f95-01a4-5d80-a90f-080c92984efa send: 154B guuid=c96ffb1c-1f00-0000-65b4-afb1700b0000 pid=2928->351b6f95-01a4-5d80-a90f-080c92984efa send: 154B guuid=ff5c5b22-1f00-0000-65b4-afb17e0b0000 pid=2942->351b6f95-01a4-5d80-a90f-080c92984efa send: 154B guuid=bbbfea28-1f00-0000-65b4-afb1870b0000 pid=2951->351b6f95-01a4-5d80-a90f-080c92984efa send: 154B guuid=5a45512f-1f00-0000-65b4-afb1950b0000 pid=2965->351b6f95-01a4-5d80-a90f-080c92984efa send: 153B guuid=7878f633-1f00-0000-65b4-afb19f0b0000 pid=2975->351b6f95-01a4-5d80-a90f-080c92984efa send: 153B guuid=607d433b-1f00-0000-65b4-afb1ad0b0000 pid=2989->351b6f95-01a4-5d80-a90f-080c92984efa send: 153B guuid=541b6641-1f00-0000-65b4-afb1bb0b0000 pid=3003->351b6f95-01a4-5d80-a90f-080c92984efa send: 153B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=eb36a345-1f00-0000-65b4-afb1c50b0000 pid=3013->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=94f14c46-1f00-0000-65b4-afb1c60b0000 pid=3014 /home/sandbox/morte.x86 guuid=eb36a345-1f00-0000-65b4-afb1c50b0000 pid=3013->guuid=94f14c46-1f00-0000-65b4-afb1c60b0000 pid=3014 clone guuid=4db96c72-2000-0000-65b4-afb1240e0000 pid=3620 /home/sandbox/morte.x86 guuid=eb36a345-1f00-0000-65b4-afb1c50b0000 pid=3013->guuid=4db96c72-2000-0000-65b4-afb1240e0000 pid=3620 clone guuid=c1b97272-2000-0000-65b4-afb1250e0000 pid=3621 /home/sandbox/morte.x86 net send-data zombie guuid=eb36a345-1f00-0000-65b4-afb1c50b0000 pid=3013->guuid=c1b97272-2000-0000-65b4-afb1250e0000 pid=3621 clone guuid=f1f55546-1f00-0000-65b4-afb1c70b0000 pid=3015 /home/sandbox/morte.x86 guuid=94f14c46-1f00-0000-65b4-afb1c60b0000 pid=3014->guuid=f1f55546-1f00-0000-65b4-afb1c70b0000 pid=3015 clone guuid=2a1d5e46-1f00-0000-65b4-afb1c80b0000 pid=3016 /home/sandbox/morte.x86 dns net send-data zombie guuid=94f14c46-1f00-0000-65b4-afb1c60b0000 pid=3014->guuid=2a1d5e46-1f00-0000-65b4-afb1c80b0000 pid=3016 clone guuid=2a1d5e46-1f00-0000-65b4-afb1c80b0000 pid=3016->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 41B e353146a-5285-5f32-a809-01b9d4b5f0e8 draft247.redirectme.net:3778 guuid=2a1d5e46-1f00-0000-65b4-afb1c80b0000 pid=3016->e353146a-5285-5f32-a809-01b9d4b5f0e8 send: 13B guuid=c1b97272-2000-0000-65b4-afb1250e0000 pid=3621->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 205B 8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 103.77.241.144:80 guuid=c1b97272-2000-0000-65b4-afb1250e0000 pid=3621->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 con d308db0e-95e7-5190-8562-6f6532001047 draft247.redirectme.net:80 guuid=99997b72-2000-0000-65b4-afb1260e0000 pid=3622->d308db0e-95e7-5190-8562-6f6532001047 send: 156B guuid=94474378-2000-0000-65b4-afb1370e0000 pid=3639->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 51f90012-4021-58ad-8b9d-c1c2f6ed80cd 0.0.0.0:3778 guuid=94474378-2000-0000-65b4-afb1370e0000 pid=3639->51f90012-4021-58ad-8b9d-c1c2f6ed80cd con
Threat name:
Document-HTML.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-10-04 13:23:17 UTC
File Type:
Text (Shell)
AV detection:
18 of 38 (47.37%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1d957b711a2616ca00a93c09fe15eaddcf8484ac2c2e4c758c750eef89fc988e

(this sample)

  
Delivery method
Distributed via web download

Comments