MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1fa35c23b8830fdef00fca8e03eda8994879970e808b806914897b3ad98310ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 1fa35c23b8830fdef00fca8e03eda8994879970e808b806914897b3ad98310ec
SHA3-384 hash: d9330abb5d75057fea047765c55af96578518b97579f85022c0cd0e4fa7181feab5a9ad83f5d045285c11303cbf5d79b
SHA1 hash: e5a4616e7c9aea50c6f124a8f284e6733f02efb3
MD5 hash: 65411ae8c9b9b48ffd07af1c7cdea608
humanhash: cold-indigo-florida-lion
File name:f
Download: download sample
Signature Mirai
File size:1'345 bytes
First seen:2025-10-25 15:06:07 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:vUQKKzp5ZMoV0UuAlOB0AMRyemy9LAiyGIjDmyGIMLAiyimyxLAiydDmyyLAnqy7:c10p5z8oOB0p9L5hJuq6ZVZ5gVr6nj
TLSH T164214BFF90D13E531841689EB8930F14AA01A5CE75C8CF8916EB0D7565CDB08B76AFA4
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://78.153.140.124/b1n/arm6d36a432aa0165f19b64365eb1339c9ad2593d2fb49db18581654042f67390bf Miraiarm elf geofenced mirai ua-wget USA
http://78.153.140.124/b1n/arm5c4a1f4db8f6a5c9a040403905726c6d56d448eff3654765283fd7c768a881a87 Miraiarm elf geofenced mirai ua-wget USA
http://78.153.140.124/b1n/arm676cb047623f8b366cd1d6c949c30a9ef394bd6a9337b97afbb2ea5b9fffb5fc2 Miraiarm elf geofenced mirai ua-wget USA
http://78.153.140.124/b1n/arm7bdba01cbfa0b446e9486d55b37340d1347789b88693f6e1c85ed6c02b838b90b Miraiarm elf geofenced mirai ua-wget USA
http://78.153.140.124/b1n/mipse143e72541d710a377db83b1a71968648e8ed280ab9a5ac02cd2678963001fef Gafgytelf gafgyt geofenced mips ua-wget USA
http://78.153.140.124/b1n/mpsl630aa755331ab6e986384bc6e760b8aaaddea550ac2921124ff7b3e2ce142acc Gafgytelf gafgyt geofenced mips ua-wget USA
http://78.153.140.124/b1n/x86289510dd049a4e5c6dbe146d858ffbafdb53b2d0aa91f229b449ab7341af1b71 Miraielf geofenced mirai ua-wget USA x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
ps1
First seen:
2025-10-25T12:52:00Z UTC
Last seen:
2025-10-25T21:17:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=dab7571a-1a00-0000-fbe9-944191090000 pid=2449 /usr/bin/sudo guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455 /tmp/sample.bin guuid=dab7571a-1a00-0000-fbe9-944191090000 pid=2449->guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455 execve guuid=c3563b1d-1a00-0000-fbe9-944198090000 pid=2456 /usr/bin/rm delete-file guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=c3563b1d-1a00-0000-fbe9-944198090000 pid=2456 execve guuid=75b8991d-1a00-0000-fbe9-944199090000 pid=2457 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=75b8991d-1a00-0000-fbe9-944199090000 pid=2457 clone guuid=5644b41e-1a00-0000-fbe9-9441a1090000 pid=2465 /usr/bin/rm delete-file guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=5644b41e-1a00-0000-fbe9-9441a1090000 pid=2465 execve guuid=d099121f-1a00-0000-fbe9-9441a3090000 pid=2467 /usr/bin/rm delete-file guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=d099121f-1a00-0000-fbe9-9441a3090000 pid=2467 execve guuid=ac476e1f-1a00-0000-fbe9-9441a5090000 pid=2469 /usr/bin/rm delete-file guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=ac476e1f-1a00-0000-fbe9-9441a5090000 pid=2469 execve guuid=5c86ce1f-1a00-0000-fbe9-9441a7090000 pid=2471 /usr/bin/mkdir guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=5c86ce1f-1a00-0000-fbe9-9441a7090000 pid=2471 execve guuid=f46e4020-1a00-0000-fbe9-9441a9090000 pid=2473 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=f46e4020-1a00-0000-fbe9-9441a9090000 pid=2473 clone guuid=582df620-1a00-0000-fbe9-9441ad090000 pid=2477 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=582df620-1a00-0000-fbe9-9441ad090000 pid=2477 clone guuid=d6d24221-1a00-0000-fbe9-9441b0090000 pid=2480 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=d6d24221-1a00-0000-fbe9-9441b0090000 pid=2480 clone guuid=f5d38735-1a00-0000-fbe9-9441d4090000 pid=2516 /usr/bin/chmod guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=f5d38735-1a00-0000-fbe9-9441d4090000 pid=2516 execve guuid=7c93c335-1a00-0000-fbe9-9441d5090000 pid=2517 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=7c93c335-1a00-0000-fbe9-9441d5090000 pid=2517 clone guuid=01464f36-1a00-0000-fbe9-9441d8090000 pid=2520 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=01464f36-1a00-0000-fbe9-9441d8090000 pid=2520 clone guuid=d0ad724a-1a00-0000-fbe9-9441020a0000 pid=2562 /usr/bin/chmod guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=d0ad724a-1a00-0000-fbe9-9441020a0000 pid=2562 execve guuid=3618ad4a-1a00-0000-fbe9-9441040a0000 pid=2564 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=3618ad4a-1a00-0000-fbe9-9441040a0000 pid=2564 clone guuid=c22b354b-1a00-0000-fbe9-9441080a0000 pid=2568 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=c22b354b-1a00-0000-fbe9-9441080a0000 pid=2568 clone guuid=2dcbbe5c-1a00-0000-fbe9-9441380a0000 pid=2616 /usr/bin/chmod guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=2dcbbe5c-1a00-0000-fbe9-9441380a0000 pid=2616 execve guuid=87334d5d-1a00-0000-fbe9-94413b0a0000 pid=2619 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=87334d5d-1a00-0000-fbe9-94413b0a0000 pid=2619 clone guuid=d1632a5e-1a00-0000-fbe9-94413f0a0000 pid=2623 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=d1632a5e-1a00-0000-fbe9-94413f0a0000 pid=2623 clone guuid=15b41471-1a00-0000-fbe9-94417a0a0000 pid=2682 /usr/bin/chmod guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=15b41471-1a00-0000-fbe9-94417a0a0000 pid=2682 execve guuid=5adf5271-1a00-0000-fbe9-94417b0a0000 pid=2683 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=5adf5271-1a00-0000-fbe9-94417b0a0000 pid=2683 clone guuid=d69de571-1a00-0000-fbe9-94417f0a0000 pid=2687 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=d69de571-1a00-0000-fbe9-94417f0a0000 pid=2687 clone guuid=0ff80a86-1a00-0000-fbe9-9441bb0a0000 pid=2747 /usr/bin/chmod guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=0ff80a86-1a00-0000-fbe9-9441bb0a0000 pid=2747 execve guuid=33f25886-1a00-0000-fbe9-9441bd0a0000 pid=2749 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=33f25886-1a00-0000-fbe9-9441bd0a0000 pid=2749 clone guuid=e19b4a87-1a00-0000-fbe9-9441c20a0000 pid=2754 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=e19b4a87-1a00-0000-fbe9-9441c20a0000 pid=2754 clone guuid=1f9c46b4-1a00-0000-fbe9-9441160b0000 pid=2838 /usr/bin/chmod guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=1f9c46b4-1a00-0000-fbe9-9441160b0000 pid=2838 execve guuid=f533c7b4-1a00-0000-fbe9-9441170b0000 pid=2839 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=f533c7b4-1a00-0000-fbe9-9441170b0000 pid=2839 clone guuid=b78bb9b6-1a00-0000-fbe9-94411c0b0000 pid=2844 /usr/bin/dash guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=b78bb9b6-1a00-0000-fbe9-94411c0b0000 pid=2844 clone guuid=36c9e8c7-1a00-0000-fbe9-9441390b0000 pid=2873 /usr/bin/chmod guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=36c9e8c7-1a00-0000-fbe9-9441390b0000 pid=2873 execve guuid=ed8634c8-1a00-0000-fbe9-94413b0b0000 pid=2875 /run/user/1000/p/.e delete-file net write-file guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=ed8634c8-1a00-0000-fbe9-94413b0b0000 pid=2875 execve guuid=e69e8bd0-1a00-0000-fbe9-94414b0b0000 pid=2891 /usr/bin/rm delete-file guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=e69e8bd0-1a00-0000-fbe9-94414b0b0000 pid=2891 execve guuid=845cd7d0-1a00-0000-fbe9-94414e0b0000 pid=2894 /usr/bin/rm guuid=14c2e91c-1a00-0000-fbe9-944197090000 pid=2455->guuid=845cd7d0-1a00-0000-fbe9-94414e0b0000 pid=2894 execve guuid=601da41d-1a00-0000-fbe9-94419a090000 pid=2458 /usr/bin/cat guuid=75b8991d-1a00-0000-fbe9-944199090000 pid=2457->guuid=601da41d-1a00-0000-fbe9-94419a090000 pid=2458 execve guuid=3b04aa1d-1a00-0000-fbe9-94419b090000 pid=2459 /usr/bin/grep guuid=75b8991d-1a00-0000-fbe9-944199090000 pid=2457->guuid=3b04aa1d-1a00-0000-fbe9-94419b090000 pid=2459 execve guuid=a0f6af1d-1a00-0000-fbe9-94419c090000 pid=2460 /usr/bin/grep guuid=75b8991d-1a00-0000-fbe9-944199090000 pid=2457->guuid=a0f6af1d-1a00-0000-fbe9-94419c090000 pid=2460 execve guuid=5d62b41d-1a00-0000-fbe9-94419d090000 pid=2461 /usr/bin/grep guuid=75b8991d-1a00-0000-fbe9-944199090000 pid=2457->guuid=5d62b41d-1a00-0000-fbe9-94419d090000 pid=2461 execve guuid=882aba1d-1a00-0000-fbe9-94419e090000 pid=2462 /usr/bin/cut guuid=75b8991d-1a00-0000-fbe9-944199090000 pid=2457->guuid=882aba1d-1a00-0000-fbe9-94419e090000 pid=2462 execve guuid=4c854820-1a00-0000-fbe9-9441aa090000 pid=2474 /usr/bin/cp write-file guuid=f46e4020-1a00-0000-fbe9-9441a9090000 pid=2473->guuid=4c854820-1a00-0000-fbe9-9441aa090000 pid=2474 execve guuid=011efe20-1a00-0000-fbe9-9441ae090000 pid=2478 /usr/bin/chmod guuid=582df620-1a00-0000-fbe9-9441ad090000 pid=2477->guuid=011efe20-1a00-0000-fbe9-9441ae090000 pid=2478 execve guuid=ad0d4c21-1a00-0000-fbe9-9441b1090000 pid=2481 /usr/bin/wget net send-data write-file guuid=d6d24221-1a00-0000-fbe9-9441b0090000 pid=2480->guuid=ad0d4c21-1a00-0000-fbe9-9441b1090000 pid=2481 execve 97d25fe6-b635-5dc4-b4bb-dbe8c55c614e 78.153.140.124:80 guuid=ad0d4c21-1a00-0000-fbe9-9441b1090000 pid=2481->97d25fe6-b635-5dc4-b4bb-dbe8c55c614e send: 136B guuid=84a55b36-1a00-0000-fbe9-9441d9090000 pid=2521 /usr/bin/wget net send-data write-file guuid=01464f36-1a00-0000-fbe9-9441d8090000 pid=2520->guuid=84a55b36-1a00-0000-fbe9-9441d9090000 pid=2521 execve guuid=84a55b36-1a00-0000-fbe9-9441d9090000 pid=2521->97d25fe6-b635-5dc4-b4bb-dbe8c55c614e send: 137B guuid=b0e23b4b-1a00-0000-fbe9-9441090a0000 pid=2569 /usr/bin/wget net send-data write-file guuid=c22b354b-1a00-0000-fbe9-9441080a0000 pid=2568->guuid=b0e23b4b-1a00-0000-fbe9-9441090a0000 pid=2569 execve guuid=b0e23b4b-1a00-0000-fbe9-9441090a0000 pid=2569->97d25fe6-b635-5dc4-b4bb-dbe8c55c614e send: 137B guuid=87c0375e-1a00-0000-fbe9-9441400a0000 pid=2624 /usr/bin/wget net send-data write-file guuid=d1632a5e-1a00-0000-fbe9-94413f0a0000 pid=2623->guuid=87c0375e-1a00-0000-fbe9-9441400a0000 pid=2624 execve guuid=87c0375e-1a00-0000-fbe9-9441400a0000 pid=2624->97d25fe6-b635-5dc4-b4bb-dbe8c55c614e send: 137B guuid=1985f371-1a00-0000-fbe9-9441800a0000 pid=2688 /usr/bin/wget net send-data write-file guuid=d69de571-1a00-0000-fbe9-94417f0a0000 pid=2687->guuid=1985f371-1a00-0000-fbe9-9441800a0000 pid=2688 execve guuid=1985f371-1a00-0000-fbe9-9441800a0000 pid=2688->97d25fe6-b635-5dc4-b4bb-dbe8c55c614e send: 137B guuid=5e095a87-1a00-0000-fbe9-9441c40a0000 pid=2756 /usr/bin/wget net send-data write-file guuid=e19b4a87-1a00-0000-fbe9-9441c20a0000 pid=2754->guuid=5e095a87-1a00-0000-fbe9-9441c40a0000 pid=2756 execve guuid=5e095a87-1a00-0000-fbe9-9441c40a0000 pid=2756->97d25fe6-b635-5dc4-b4bb-dbe8c55c614e send: 137B guuid=410ac0b6-1a00-0000-fbe9-94411d0b0000 pid=2845 /usr/bin/wget net send-data write-file guuid=b78bb9b6-1a00-0000-fbe9-94411c0b0000 pid=2844->guuid=410ac0b6-1a00-0000-fbe9-94411d0b0000 pid=2845 execve guuid=410ac0b6-1a00-0000-fbe9-94411d0b0000 pid=2845->97d25fe6-b635-5dc4-b4bb-dbe8c55c614e send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ed8634c8-1a00-0000-fbe9-94413b0b0000 pid=2875->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=468f81d0-1a00-0000-fbe9-94414a0b0000 pid=2890 /run/user/1000/p/.e dns net send-data write-file zombie guuid=ed8634c8-1a00-0000-fbe9-94413b0b0000 pid=2875->guuid=468f81d0-1a00-0000-fbe9-94414a0b0000 pid=2890 clone guuid=468f81d0-1a00-0000-fbe9-94414a0b0000 pid=2890->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 70B 523636b0-16d0-5e72-9d3f-603f4ac36272 blueblackside.com:9090 guuid=468f81d0-1a00-0000-fbe9-94414a0b0000 pid=2890->523636b0-16d0-5e72-9d3f-603f4ac36272 send: 49B 7f30281f-6565-565b-903e-76ab0b9d4286 stun.l.google.com:19302 guuid=468f81d0-1a00-0000-fbe9-94414a0b0000 pid=2890->7f30281f-6565-565b-903e-76ab0b9d4286 send: 20B guuid=f4179bd0-1a00-0000-fbe9-94414c0b0000 pid=2892 /run/user/1000/p/.e write-file guuid=468f81d0-1a00-0000-fbe9-94414a0b0000 pid=2890->guuid=f4179bd0-1a00-0000-fbe9-94414c0b0000 pid=2892 clone
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-10-25 15:08:40 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1fa35c23b8830fdef00fca8e03eda8994879970e808b806914897b3ad98310ec

(this sample)

  
Delivery method
Distributed via web download

Comments