MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1dacc14342923347c798bb044e1d9bdca818d81907526db670fa29687ad159d1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 1dacc14342923347c798bb044e1d9bdca818d81907526db670fa29687ad159d1
SHA3-384 hash: 32140386adcc8dd4c0adf32c85810f66137459273caf5eb2c286e616cb07fa5d6282d9cd781fcb3c661f5035a1ffdef0
SHA1 hash: b43fa6d6f540d7e3a9c802c5391d49b81abe6b80
MD5 hash: 6eb2645673b30a68d0163f598306cd66
humanhash: nebraska-white-zulu-uranus
File name:tbk
Download: download sample
Signature Mirai
File size:677 bytes
First seen:2026-01-25 00:43:33 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:BufSnGf2FhfAewofiOWNn+0cfSnvivfsfAewt8fiZt+JGy:+Vi5ABC5TWABIn
TLSH T10601F7D10332EAA1F805BD1430B2744A23C77FAC22A87F4DBC7C499395499B0B901B29
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.100.211/n2/armv5lfa1718e2fddd1d0c8408bc4a63391ddeb26c7468de3891f4ae0421e638e32944 Miraiarm elf geofenced mirai ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=988d1c64-1800-0000-b784-2189130a0000 pid=2579 /usr/bin/sudo guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585 /tmp/sample.bin guuid=988d1c64-1800-0000-b784-2189130a0000 pid=2579->guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585 execve guuid=76402566-1800-0000-b784-21891b0a0000 pid=2587 /usr/bin/wget net send-data write-file guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=76402566-1800-0000-b784-21891b0a0000 pid=2587 execve guuid=bfd84e7d-1800-0000-b784-21895d0a0000 pid=2653 /usr/bin/chmod guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=bfd84e7d-1800-0000-b784-21895d0a0000 pid=2653 execve guuid=3300897d-1800-0000-b784-21895e0a0000 pid=2654 /usr/bin/dash guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=3300897d-1800-0000-b784-21895e0a0000 pid=2654 clone guuid=c80eff7d-1800-0000-b784-2189610a0000 pid=2657 /usr/bin/wget net send-data write-file guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=c80eff7d-1800-0000-b784-2189610a0000 pid=2657 execve guuid=e5e04993-1800-0000-b784-21899d0a0000 pid=2717 /usr/bin/chmod guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=e5e04993-1800-0000-b784-21899d0a0000 pid=2717 execve guuid=ecfaab93-1800-0000-b784-21899f0a0000 pid=2719 /usr/bin/dash guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=ecfaab93-1800-0000-b784-21899f0a0000 pid=2719 clone guuid=e95f6a94-1800-0000-b784-2189a20a0000 pid=2722 /usr/bin/wget net send-data write-file guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=e95f6a94-1800-0000-b784-2189a20a0000 pid=2722 execve guuid=d8cc8aa9-1800-0000-b784-2189cc0a0000 pid=2764 /usr/bin/chmod guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=d8cc8aa9-1800-0000-b784-2189cc0a0000 pid=2764 execve guuid=cb3bd7a9-1800-0000-b784-2189cd0a0000 pid=2765 /dev/x86 net guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=cb3bd7a9-1800-0000-b784-2189cd0a0000 pid=2765 execve guuid=2dea30ab-1800-0000-b784-2189d00a0000 pid=2768 /usr/bin/wget net send-data write-file guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=2dea30ab-1800-0000-b784-2189d00a0000 pid=2768 execve guuid=f75e78c0-1800-0000-b784-2189f90a0000 pid=2809 /usr/bin/chmod guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=f75e78c0-1800-0000-b784-2189f90a0000 pid=2809 execve guuid=2260d3c0-1800-0000-b784-2189fa0a0000 pid=2810 /usr/bin/dash guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=2260d3c0-1800-0000-b784-2189fa0a0000 pid=2810 clone guuid=ab0474c1-1800-0000-b784-2189fc0a0000 pid=2812 /usr/bin/rm delete-file guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=ab0474c1-1800-0000-b784-2189fc0a0000 pid=2812 execve guuid=e927b4c1-1800-0000-b784-2189fe0a0000 pid=2814 /usr/bin/busybox net send-data write-file guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=e927b4c1-1800-0000-b784-2189fe0a0000 pid=2814 execve guuid=04e948d6-1800-0000-b784-21892a0b0000 pid=2858 /usr/bin/chmod guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=04e948d6-1800-0000-b784-21892a0b0000 pid=2858 execve guuid=b0fb8dd6-1800-0000-b784-21892b0b0000 pid=2859 /usr/bin/dash guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=b0fb8dd6-1800-0000-b784-21892b0b0000 pid=2859 clone guuid=b9a29ad7-1800-0000-b784-21892e0b0000 pid=2862 /usr/bin/busybox net send-data write-file guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=b9a29ad7-1800-0000-b784-21892e0b0000 pid=2862 execve guuid=533378ec-1800-0000-b784-2189660b0000 pid=2918 /usr/bin/chmod guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=533378ec-1800-0000-b784-2189660b0000 pid=2918 execve guuid=85f9c5ec-1800-0000-b784-2189680b0000 pid=2920 /usr/bin/dash guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=85f9c5ec-1800-0000-b784-2189680b0000 pid=2920 clone guuid=ac7970ee-1800-0000-b784-21896d0b0000 pid=2925 /usr/bin/busybox net send-data write-file guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=ac7970ee-1800-0000-b784-21896d0b0000 pid=2925 execve guuid=7c7cb502-1900-0000-b784-21898f0b0000 pid=2959 /usr/bin/chmod guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=7c7cb502-1900-0000-b784-21898f0b0000 pid=2959 execve guuid=8aa93c03-1900-0000-b784-2189900b0000 pid=2960 /dev/x86 net guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=8aa93c03-1900-0000-b784-2189900b0000 pid=2960 execve guuid=7fb34104-1900-0000-b784-2189920b0000 pid=2962 /usr/bin/busybox net send-data write-file guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=7fb34104-1900-0000-b784-2189920b0000 pid=2962 execve guuid=63468918-1900-0000-b784-2189bd0b0000 pid=3005 /usr/bin/chmod guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=63468918-1900-0000-b784-2189bd0b0000 pid=3005 execve guuid=7896d118-1900-0000-b784-2189be0b0000 pid=3006 /usr/bin/dash guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=7896d118-1900-0000-b784-2189be0b0000 pid=3006 clone guuid=7d24e319-1900-0000-b784-2189c20b0000 pid=3010 /usr/bin/rm delete-file guuid=e1d4e965-1800-0000-b784-2189190a0000 pid=2585->guuid=7d24e319-1900-0000-b784-2189c20b0000 pid=3010 execve bc0093a4-142b-5795-92c3-10bb9de91a2a 162.248.100.211:80 guuid=76402566-1800-0000-b784-21891b0a0000 pid=2587->bc0093a4-142b-5795-92c3-10bb9de91a2a send: 137B guuid=c80eff7d-1800-0000-b784-2189610a0000 pid=2657->bc0093a4-142b-5795-92c3-10bb9de91a2a send: 137B guuid=e95f6a94-1800-0000-b784-2189a20a0000 pid=2722->bc0093a4-142b-5795-92c3-10bb9de91a2a send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=cb3bd7a9-1800-0000-b784-2189cd0a0000 pid=2765->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=579327ab-1800-0000-b784-2189cf0a0000 pid=2767 /dev/x86 dns net send-data zombie guuid=cb3bd7a9-1800-0000-b784-2189cd0a0000 pid=2765->guuid=579327ab-1800-0000-b784-2189cf0a0000 pid=2767 clone guuid=579327ab-1800-0000-b784-2189cf0a0000 pid=2767->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 54d92a3b-1447-55af-b534-047898c60c8d 1.1.1.1:53 guuid=579327ab-1800-0000-b784-2189cf0a0000 pid=2767->54d92a3b-1447-55af-b534-047898c60c8d send: 57B e3f9fb10-0e66-5c7e-83de-a37e64ad6f88 jaffacakes118-is-a-stupid-nigger.online:25565 guuid=579327ab-1800-0000-b784-2189cf0a0000 pid=2767->e3f9fb10-0e66-5c7e-83de-a37e64ad6f88 send: 4B 9c10d2f0-7907-502e-8787-432da9fcaae4 jaffacakes118-is-a-stupid-nigger.online:80 guuid=579327ab-1800-0000-b784-2189cf0a0000 pid=2767->9c10d2f0-7907-502e-8787-432da9fcaae4 send: 139B guuid=b6f13eab-1800-0000-b784-2189d10a0000 pid=2769 /dev/x86 guuid=579327ab-1800-0000-b784-2189cf0a0000 pid=2767->guuid=b6f13eab-1800-0000-b784-2189d10a0000 pid=2769 clone guuid=2dea30ab-1800-0000-b784-2189d00a0000 pid=2768->bc0093a4-142b-5795-92c3-10bb9de91a2a send: 139B guuid=81d24cab-1800-0000-b784-2189d20a0000 pid=2770 /dev/x86 send-data guuid=b6f13eab-1800-0000-b784-2189d10a0000 pid=2769->guuid=81d24cab-1800-0000-b784-2189d20a0000 pid=2770 clone 5fd7270e-42a1-58af-801e-5d648b08aa1f 127.0.0.1:39300 guuid=81d24cab-1800-0000-b784-2189d20a0000 pid=2770->5fd7270e-42a1-58af-801e-5d648b08aa1f send: 1B guuid=e927b4c1-1800-0000-b784-2189fe0a0000 pid=2814->bc0093a4-142b-5795-92c3-10bb9de91a2a send: 85B guuid=b9a29ad7-1800-0000-b784-21892e0b0000 pid=2862->bc0093a4-142b-5795-92c3-10bb9de91a2a send: 85B guuid=ac7970ee-1800-0000-b784-21896d0b0000 pid=2925->bc0093a4-142b-5795-92c3-10bb9de91a2a send: 84B guuid=8aa93c03-1900-0000-b784-2189900b0000 pid=2960->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0f0b3a04-1900-0000-b784-2189910b0000 pid=2961 /dev/x86 net send-data zombie guuid=8aa93c03-1900-0000-b784-2189900b0000 pid=2960->guuid=0f0b3a04-1900-0000-b784-2189910b0000 pid=2961 clone guuid=0f0b3a04-1900-0000-b784-2189910b0000 pid=2961->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 307db2dd-32a0-52fe-a412-5478b0ff6eae 127.0.0.1:63464 guuid=0f0b3a04-1900-0000-b784-2189910b0000 pid=2961->307db2dd-32a0-52fe-a412-5478b0ff6eae send: 2B guuid=7fb34104-1900-0000-b784-2189920b0000 pid=2962->bc0093a4-142b-5795-92c3-10bb9de91a2a send: 87B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-01-06 03:39:59 UTC
File Type:
Text (Shell)
AV detection:
3 of 36 (8.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1dacc14342923347c798bb044e1d9bdca818d81907526db670fa29687ad159d1

(this sample)

  
Delivery method
Distributed via web download

Comments