🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 243d7d7c79cccb577e5bc2eade7f2b6d32c502cbd39635f80476610035ae080c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 243d7d7c79cccb577e5bc2eade7f2b6d32c502cbd39635f80476610035ae080c
SHA3-384 hash: 8910a30461b7bc6772d29538e4bd395e4769122fa60a2caa83386cf4292948f6cc10a60446b1bc045cbb92451766eb47
SHA1 hash: 7c6bf881210bdb347fb9e53b7516beae3e138eb1
MD5 hash: 313d4a5d2675ddc14e593470cd219230
humanhash: delaware-vegan-queen-mirror
File name:243d7d7c79cccb577e5bc2eade7f2b6d32c502cbd39635f80476610035ae080c
Download: download sample
Signature Mirai
File size:1'469 bytes
First seen:2026-10-06 22:08:38 UTC
Last seen:2026-10-09 22:17:55 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ieP4hrSvQu/fFkdmkhIYnSZVcuw5MMTWZVMSq8jO457YLI3cpHq6ps:pQhrSYulImkyYSfcTezfMSq8jJ57YLI3
TLSH T1D131F0E57172E6BBB8A581BCB2879A30380440EB0C44AA7D344E9B701F8D74CB1657AD
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter c2hunter
Tags:sh wraith
URLMalware sample (SHA256 hash)SignatureTags
http://77.90.57.20:8080/botbcaad64daed3f829c418abe5d8fde4d2588afbec16f95f59cb225874524809a0 Mirai64-bit elf mirai x86-64

Intelligence


File Origin
# of uploads :
2
# of downloads :
98
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-10-06T21:48:00Z UTC
Last seen:
2026-10-07T21:41:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=587093f2-1600-0000-e400-c156d30d0000 pid=3539 /usr/bin/sudo guuid=241272f7-1600-0000-e400-c156e00d0000 pid=3552 /tmp/sample.bin guuid=587093f2-1600-0000-e400-c156d30d0000 pid=3539->guuid=241272f7-1600-0000-e400-c156e00d0000 pid=3552 execve guuid=4e5c20f9-1600-0000-e400-c156e10d0000 pid=3553 /usr/bin/cat write-config guuid=241272f7-1600-0000-e400-c156e00d0000 pid=3552->guuid=4e5c20f9-1600-0000-e400-c156e10d0000 pid=3553 execve guuid=ce9bc6f9-1600-0000-e400-c156e20d0000 pid=3554 /usr/bin/chmod guuid=241272f7-1600-0000-e400-c156e00d0000 pid=3552->guuid=ce9bc6f9-1600-0000-e400-c156e20d0000 pid=3554 execve guuid=c0e94afa-1600-0000-e400-c156e30d0000 pid=3555 /usr/bin/wget net send-data write-file guuid=241272f7-1600-0000-e400-c156e00d0000 pid=3552->guuid=c0e94afa-1600-0000-e400-c156e30d0000 pid=3555 execve guuid=ac8b6803-1700-0000-e400-c156fb0d0000 pid=3579 /usr/bin/chmod guuid=241272f7-1600-0000-e400-c156e00d0000 pid=3552->guuid=ac8b6803-1700-0000-e400-c156fb0d0000 pid=3579 execve guuid=375fff03-1700-0000-e400-c156fe0d0000 pid=3582 /tmp/.bot net zombie guuid=241272f7-1600-0000-e400-c156e00d0000 pid=3552->guuid=375fff03-1700-0000-e400-c156fe0d0000 pid=3582 execve guuid=47b50f04-1700-0000-e400-c156000e0000 pid=3584 /usr/bin/bash guuid=241272f7-1600-0000-e400-c156e00d0000 pid=3552->guuid=47b50f04-1700-0000-e400-c156000e0000 pid=3584 clone 71896bc3-dde7-582d-90c5-2d43936dfafb 77.90.57.20:8080 guuid=c0e94afa-1600-0000-e400-c156e30d0000 pid=3555->71896bc3-dde7-582d-90c5-2d43936dfafb send: 138B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=375fff03-1700-0000-e400-c156fe0d0000 pid=3582->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=27a33504-1700-0000-e400-c156010e0000 pid=3585 /tmp/.bot net send-data zombie guuid=375fff03-1700-0000-e400-c156fe0d0000 pid=3582->guuid=27a33504-1700-0000-e400-c156010e0000 pid=3585 clone guuid=83a34004-1700-0000-e400-c156020e0000 pid=3586 /usr/bin/sleep guuid=47b50f04-1700-0000-e400-c156000e0000 pid=3584->guuid=83a34004-1700-0000-e400-c156020e0000 pid=3586 execve guuid=27a33504-1700-0000-e400-c156010e0000 pid=3585->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con c90702e3-01f0-5c08-b475-299a918f065c 77.90.57.20:4115 guuid=27a33504-1700-0000-e400-c156010e0000 pid=3585->c90702e3-01f0-5c08-b475-299a918f065c send: 7B guuid=5b616704-1700-0000-e400-c156030e0000 pid=3587 /tmp/.bot guuid=27a33504-1700-0000-e400-c156010e0000 pid=3585->guuid=5b616704-1700-0000-e400-c156030e0000 pid=3587 clone guuid=7bbe8f04-1700-0000-e400-c156050e0000 pid=3589 /tmp/.bot net net-scan send-data guuid=27a33504-1700-0000-e400-c156010e0000 pid=3585->guuid=7bbe8f04-1700-0000-e400-c156050e0000 pid=3589 clone guuid=7bbe8f04-1700-0000-e400-c156050e0000 pid=3589|network network activity to 4098 IP addresses review logs to see them all guuid=7bbe8f04-1700-0000-e400-c156050e0000 pid=3589->guuid=7bbe8f04-1700-0000-e400-c156050e0000 pid=3589|network network
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-10-06 22:09:23 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Creates/modifies Cron job
Enumerates running processes
Modifies init.d
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (76292) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Mirai

sh 243d7d7c79cccb577e5bc2eade7f2b6d32c502cbd39635f80476610035ae080c

(this sample)

Comments