MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 214d5d6282dd79a1729b150546b9586ab74484d5cfd993375dbd6c389956aab5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 214d5d6282dd79a1729b150546b9586ab74484d5cfd993375dbd6c389956aab5
SHA3-384 hash: 3bb12a4928992ecb2490b773c9c37b71539de9422106f1179fb250e807801a9de594dd53ae0befc1174d77af5285cfab
SHA1 hash: 5b5319fd40e60a06c9f5d949b43442077f0754c5
MD5 hash: 7b108a5e250c820ea184b978028d0b4a
humanhash: steak-don-bacon-indigo
File name:toto
Download: download sample
Signature Mirai
File size:1'112 bytes
First seen:2025-09-30 03:55:44 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:HftifnGZqM0RAM0RRPiM0RE6SM0RDaM0RL:H1i/GZqxRAxRExRmxRGxRL
TLSH T1BB2151EF6245E2F08E9CE5926EAF851971161DC724C0DEAEF85E4C123D48A94B474E4C
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.250.134.61/mips8e8239ebc8b41e0cb7f7452f6293f5a5dd4d2f7bd706df0f9e399413e8df328b Gafgytelf gafgyt geofenced mips ua-wget USA
http://160.250.134.61/mpslaea8ad044799f08ef2a9d6bf1617de28d4669ba1fea99f308550af3c87b70349 Gafgytelf gafgyt geofenced mips mirai ua-wget USA
http://160.250.134.61/arm86c913791bb43de279ba0ecacbe54a5ba85bfbc96a23824ff9c6fd6644f7def7 Miraiarm elf geofenced mirai ua-wget USA
http://160.250.134.61/arm50841551fe33de70d71ebe9a6b62bc95ab0b532eff3e22b642d1d070055f45c3c Miraiarm elf geofenced mirai ua-wget USA
http://160.250.134.61/arm7dd42fda90826e3f259b46e9817c9449571a35a4fe6a067440adc8051c250dfa5 Miraiarm elf geofenced mirai ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-30T01:35:00Z UTC
Last seen:
2025-09-30T01:35:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=274da1f2-1800-0000-2050-db93a40d0000 pid=3492 /usr/bin/sudo guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499 /tmp/sample.bin guuid=274da1f2-1800-0000-2050-db93a40d0000 pid=3492->guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499 execve guuid=dd39a4f5-1800-0000-2050-db93ac0d0000 pid=3500 /usr/bin/busybox guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=dd39a4f5-1800-0000-2050-db93ac0d0000 pid=3500 execve guuid=a8a908f6-1800-0000-2050-db93ad0d0000 pid=3501 /usr/bin/busybox guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=a8a908f6-1800-0000-2050-db93ad0d0000 pid=3501 execve guuid=3ecf5df6-1800-0000-2050-db93af0d0000 pid=3503 /usr/bin/busybox guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=3ecf5df6-1800-0000-2050-db93af0d0000 pid=3503 execve guuid=ab36a5f6-1800-0000-2050-db93b00d0000 pid=3504 /usr/bin/cp guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=ab36a5f6-1800-0000-2050-db93b00d0000 pid=3504 execve guuid=aa0ab1fc-1800-0000-2050-db93b70d0000 pid=3511 /usr/bin/dash guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=aa0ab1fc-1800-0000-2050-db93b70d0000 pid=3511 clone guuid=10cfb33a-1900-0000-2050-db93280e0000 pid=3624 /usr/bin/chmod guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=10cfb33a-1900-0000-2050-db93280e0000 pid=3624 execve guuid=c093273b-1900-0000-2050-db932c0e0000 pid=3628 /usr/bin/dash guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=c093273b-1900-0000-2050-db932c0e0000 pid=3628 clone guuid=c6bdf33b-1900-0000-2050-db93310e0000 pid=3633 /usr/bin/rm delete-file guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=c6bdf33b-1900-0000-2050-db93310e0000 pid=3633 execve guuid=70ee5e3c-1900-0000-2050-db93320e0000 pid=3634 /usr/bin/dash guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=70ee5e3c-1900-0000-2050-db93320e0000 pid=3634 clone guuid=a51cb079-1900-0000-2050-db93a90e0000 pid=3753 /usr/bin/chmod guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=a51cb079-1900-0000-2050-db93a90e0000 pid=3753 execve guuid=0f54087a-1900-0000-2050-db93ab0e0000 pid=3755 /usr/bin/dash guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=0f54087a-1900-0000-2050-db93ab0e0000 pid=3755 clone guuid=4f16cd7b-1900-0000-2050-db93b00e0000 pid=3760 /usr/bin/rm delete-file guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=4f16cd7b-1900-0000-2050-db93b00e0000 pid=3760 execve guuid=e7f0267c-1900-0000-2050-db93b20e0000 pid=3762 /usr/bin/dash guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=e7f0267c-1900-0000-2050-db93b20e0000 pid=3762 clone guuid=4b15f4b9-1900-0000-2050-db935f0f0000 pid=3935 /usr/bin/chmod guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=4b15f4b9-1900-0000-2050-db935f0f0000 pid=3935 execve guuid=9ea498ba-1900-0000-2050-db93630f0000 pid=3939 /usr/bin/dash guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=9ea498ba-1900-0000-2050-db93630f0000 pid=3939 clone guuid=5798c2bc-1900-0000-2050-db936a0f0000 pid=3946 /usr/bin/rm delete-file guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=5798c2bc-1900-0000-2050-db936a0f0000 pid=3946 execve guuid=07d70dbd-1900-0000-2050-db936b0f0000 pid=3947 /usr/bin/dash guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=07d70dbd-1900-0000-2050-db936b0f0000 pid=3947 clone guuid=645f73f8-1900-0000-2050-db93fb0f0000 pid=4091 /usr/bin/chmod guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=645f73f8-1900-0000-2050-db93fb0f0000 pid=4091 execve guuid=cda2c6f8-1900-0000-2050-db93fd0f0000 pid=4093 /usr/bin/dash guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=cda2c6f8-1900-0000-2050-db93fd0f0000 pid=4093 clone guuid=885176f9-1900-0000-2050-db9300100000 pid=4096 /usr/bin/rm delete-file guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=885176f9-1900-0000-2050-db9300100000 pid=4096 execve guuid=7405c8f9-1900-0000-2050-db9302100000 pid=4098 /usr/bin/dash guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=7405c8f9-1900-0000-2050-db9302100000 pid=4098 clone guuid=e7c1023e-1a00-0000-2050-db93a7100000 pid=4263 /usr/bin/chmod guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=e7c1023e-1a00-0000-2050-db93a7100000 pid=4263 execve guuid=10f2403e-1a00-0000-2050-db93a8100000 pid=4264 /usr/bin/dash guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=10f2403e-1a00-0000-2050-db93a8100000 pid=4264 clone guuid=e0f6563f-1a00-0000-2050-db93af100000 pid=4271 /usr/bin/rm delete-file guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=e0f6563f-1a00-0000-2050-db93af100000 pid=4271 execve guuid=212a913f-1a00-0000-2050-db93b1100000 pid=4273 /usr/bin/rm delete-file guuid=ecf0eef4-1800-0000-2050-db93ab0d0000 pid=3499->guuid=212a913f-1a00-0000-2050-db93b1100000 pid=4273 execve guuid=47f4bbfc-1800-0000-2050-db93b80d0000 pid=3512 /usr/bin/busybox net send-data write-file guuid=aa0ab1fc-1800-0000-2050-db93b70d0000 pid=3511->guuid=47f4bbfc-1800-0000-2050-db93b80d0000 pid=3512 execve 0dc21e74-2c96-5836-aca6-ed80e44c888b 160.250.134.61:80 guuid=47f4bbfc-1800-0000-2050-db93b80d0000 pid=3512->0dc21e74-2c96-5836-aca6-ed80e44c888b send: 81B guuid=f5f0753c-1900-0000-2050-db93330e0000 pid=3635 /usr/bin/busybox net send-data write-file guuid=70ee5e3c-1900-0000-2050-db93320e0000 pid=3634->guuid=f5f0753c-1900-0000-2050-db93330e0000 pid=3635 execve guuid=f5f0753c-1900-0000-2050-db93330e0000 pid=3635->0dc21e74-2c96-5836-aca6-ed80e44c888b send: 81B guuid=59e5337c-1900-0000-2050-db93b30e0000 pid=3763 /usr/bin/busybox net send-data write-file guuid=e7f0267c-1900-0000-2050-db93b20e0000 pid=3762->guuid=59e5337c-1900-0000-2050-db93b30e0000 pid=3763 execve guuid=59e5337c-1900-0000-2050-db93b30e0000 pid=3763->0dc21e74-2c96-5836-aca6-ed80e44c888b send: 80B guuid=c31c1ebd-1900-0000-2050-db936d0f0000 pid=3949 /usr/bin/busybox net send-data write-file guuid=07d70dbd-1900-0000-2050-db936b0f0000 pid=3947->guuid=c31c1ebd-1900-0000-2050-db936d0f0000 pid=3949 execve guuid=c31c1ebd-1900-0000-2050-db936d0f0000 pid=3949->0dc21e74-2c96-5836-aca6-ed80e44c888b send: 81B guuid=949fd6f9-1900-0000-2050-db9303100000 pid=4099 /usr/bin/busybox net send-data write-file guuid=7405c8f9-1900-0000-2050-db9302100000 pid=4098->guuid=949fd6f9-1900-0000-2050-db9303100000 pid=4099 execve guuid=949fd6f9-1900-0000-2050-db9303100000 pid=4099->0dc21e74-2c96-5836-aca6-ed80e44c888b send: 81B
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-09-30 04:10:19 UTC
File Type:
Text (Shell)
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 214d5d6282dd79a1729b150546b9586ab74484d5cfd993375dbd6c389956aab5

(this sample)

  
Delivery method
Distributed via web download

Comments