MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2753f5f7771d268ea371bd7f3a582295397b5df2877d4ab251358860ad153279. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 2753f5f7771d268ea371bd7f3a582295397b5df2877d4ab251358860ad153279
SHA3-384 hash: 5736420b96b4a35697337fc1965fb985daf1b1d924fba9e1e5faedebe5d4d5139d59900a48f2bc3f598781ec2e3a6b31
SHA1 hash: 7d0498cbda55c6b54b2014efceaa17fd322b631b
MD5 hash: 121a400fa65d095f9ab05a3ecfb6cb0e
humanhash: purple-sierra-violet-magazine
File name:c.sh
Download: download sample
Signature Mirai
File size:852 bytes
First seen:2025-12-24 08:01:49 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:3J3n7fdURDiNIx9GRKe1JZiNckRo/EOX3oP3pfBGg9GttHA:xq34Rn0+kRo/FXYP5fhitg
TLSH T12E01E38F115DF582774C8F58B19FD15C7ED0A9E27A760921FB64C8B284E420037A8BF5
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.127/ntarm37490b35b3b2ad15b38e07c6d2614e277d2a43c76355f140c7c7ef6d7cf0f5ac Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.127/ntarm5e5e9346a47bce22519a79482111400fa4d1cb57614773f44d27c47574d1fa442 Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.127/ntarm64822e668692794fad83477e8ba761b11c25d57428ee6665f0f0cef3e7ba4873a Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.127/ntarm781aad7c6c7e13e69d0759539801b14a00e44d1363adf39ba5ecddb1874709e91 Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.127/ntm68k93b5e35d52129a8f694081b56cd71ca7bd3f53481c32b80e4d653a6039a90af6 Miraielf geofenced m68k mirai ua-wget USA
http://130.12.180.127/ntmips67d445a8aafcd3e7c47746cfcda4ad4a92f00fe2b67fb4f4564d9a5b6f219491 Miraielf geofenced mips mirai ua-wget USA
http://130.12.180.127/ntmpsla97f2be659972982b61aee906b13d8ea4e9e16a2d1284c33f8ed99d8ea41ff59 Miraielf geofenced mips mirai ua-wget USA
http://130.12.180.127/ntppc562f58604b6c7b9a5a7f174b53301b48afc8fab79fff7de2086ea8943978b735 Miraielf geofenced mirai PowerPC ua-wget USA
http://130.12.180.127/ntsh4b7f840ae5abdf8f07a1ec90a5841a7f875ccec5c064482eee8f935d12f9c8fa6 Miraielf geofenced mirai SuperH ua-wget USA
http://130.12.180.127/ntspcff07e6e405b5008d7f2227624d592cd35a30b45bcdf0ee2a91ef6d9f7aff9c73 Miraielf geofenced mirai sparc ua-wget USA
http://130.12.180.127/ntx868198e09fd8d9e79cd05d5b00f01c4199706fc156a45ac0bf74f251c8f36d385e Miraielf geofenced mirai ua-wget USA x86
http://130.12.180.127/ntx86_64n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
27
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Result
Gathering data
Verdict:
Malicious
File Type:
ps1
First seen:
2025-12-24T03:48:00Z UTC
Last seen:
2025-12-24T04:01:00Z UTC
Hits:
~10
Detections:
Backdoor.Linux.Mirai.c HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Backdoor.Linux.Mirai.hv HEUR:Backdoor.Linux.Mirai.b
Status:
terminated
Behavior Graph:
%3 guuid=30858e06-1800-0000-29ef-6c32560a0000 pid=2646 /usr/bin/sudo guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652 /tmp/sample.bin guuid=30858e06-1800-0000-29ef-6c32560a0000 pid=2646->guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652 execve guuid=b4f99108-1800-0000-29ef-6c325e0a0000 pid=2654 /usr/bin/curl net send-data guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=b4f99108-1800-0000-29ef-6c325e0a0000 pid=2654 execve guuid=4d774510-1800-0000-29ef-6c32760a0000 pid=2678 /usr/bin/chmod guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=4d774510-1800-0000-29ef-6c32760a0000 pid=2678 execve guuid=38559910-1800-0000-29ef-6c32780a0000 pid=2680 /usr/bin/dash guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=38559910-1800-0000-29ef-6c32780a0000 pid=2680 clone guuid=70fbbf10-1800-0000-29ef-6c32790a0000 pid=2681 /usr/bin/curl net send-data guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=70fbbf10-1800-0000-29ef-6c32790a0000 pid=2681 execve guuid=f216f417-1800-0000-29ef-6c32890a0000 pid=2697 /usr/bin/chmod guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=f216f417-1800-0000-29ef-6c32890a0000 pid=2697 execve guuid=ec2d2e18-1800-0000-29ef-6c328b0a0000 pid=2699 /usr/bin/dash guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=ec2d2e18-1800-0000-29ef-6c328b0a0000 pid=2699 clone guuid=c3aa3918-1800-0000-29ef-6c328c0a0000 pid=2700 /usr/bin/curl net send-data guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=c3aa3918-1800-0000-29ef-6c328c0a0000 pid=2700 execve guuid=795d161f-1800-0000-29ef-6c329d0a0000 pid=2717 /usr/bin/chmod guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=795d161f-1800-0000-29ef-6c329d0a0000 pid=2717 execve guuid=1eec621f-1800-0000-29ef-6c32a00a0000 pid=2720 /usr/bin/dash guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=1eec621f-1800-0000-29ef-6c32a00a0000 pid=2720 clone guuid=417a6a1f-1800-0000-29ef-6c32a10a0000 pid=2721 /usr/bin/curl net send-data guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=417a6a1f-1800-0000-29ef-6c32a10a0000 pid=2721 execve guuid=e659bf24-1800-0000-29ef-6c32b20a0000 pid=2738 /usr/bin/chmod guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=e659bf24-1800-0000-29ef-6c32b20a0000 pid=2738 execve guuid=08791025-1800-0000-29ef-6c32b30a0000 pid=2739 /usr/bin/dash guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=08791025-1800-0000-29ef-6c32b30a0000 pid=2739 clone guuid=60ee1d25-1800-0000-29ef-6c32b40a0000 pid=2740 /usr/bin/curl net send-data guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=60ee1d25-1800-0000-29ef-6c32b40a0000 pid=2740 execve guuid=323c652a-1800-0000-29ef-6c32c20a0000 pid=2754 /usr/bin/chmod guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=323c652a-1800-0000-29ef-6c32c20a0000 pid=2754 execve guuid=2c1ca82a-1800-0000-29ef-6c32c40a0000 pid=2756 /usr/bin/dash guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=2c1ca82a-1800-0000-29ef-6c32c40a0000 pid=2756 clone guuid=fa22b62a-1800-0000-29ef-6c32c50a0000 pid=2757 /usr/bin/curl net send-data guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=fa22b62a-1800-0000-29ef-6c32c50a0000 pid=2757 execve guuid=94577332-1800-0000-29ef-6c32d00a0000 pid=2768 /usr/bin/chmod guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=94577332-1800-0000-29ef-6c32d00a0000 pid=2768 execve guuid=3a81b032-1800-0000-29ef-6c32d20a0000 pid=2770 /usr/bin/dash guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=3a81b032-1800-0000-29ef-6c32d20a0000 pid=2770 clone guuid=3a8abb32-1800-0000-29ef-6c32d30a0000 pid=2771 /usr/bin/curl net send-data guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=3a8abb32-1800-0000-29ef-6c32d30a0000 pid=2771 execve guuid=ec3f4037-1800-0000-29ef-6c32de0a0000 pid=2782 /usr/bin/chmod guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=ec3f4037-1800-0000-29ef-6c32de0a0000 pid=2782 execve guuid=349ebc37-1800-0000-29ef-6c32df0a0000 pid=2783 /usr/bin/dash guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=349ebc37-1800-0000-29ef-6c32df0a0000 pid=2783 clone guuid=6bbeca37-1800-0000-29ef-6c32e00a0000 pid=2784 /usr/bin/curl net send-data guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=6bbeca37-1800-0000-29ef-6c32e00a0000 pid=2784 execve guuid=b4033b3c-1800-0000-29ef-6c32ed0a0000 pid=2797 /usr/bin/chmod guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=b4033b3c-1800-0000-29ef-6c32ed0a0000 pid=2797 execve guuid=d2e97c3c-1800-0000-29ef-6c32ef0a0000 pid=2799 /usr/bin/dash guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=d2e97c3c-1800-0000-29ef-6c32ef0a0000 pid=2799 clone guuid=b865a03c-1800-0000-29ef-6c32f00a0000 pid=2800 /usr/bin/curl net send-data guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=b865a03c-1800-0000-29ef-6c32f00a0000 pid=2800 execve guuid=4c132943-1800-0000-29ef-6c32ff0a0000 pid=2815 /usr/bin/chmod guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=4c132943-1800-0000-29ef-6c32ff0a0000 pid=2815 execve guuid=e3d96d43-1800-0000-29ef-6c32010b0000 pid=2817 /usr/bin/dash guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=e3d96d43-1800-0000-29ef-6c32010b0000 pid=2817 clone guuid=28317d43-1800-0000-29ef-6c32020b0000 pid=2818 /usr/bin/curl net send-data guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=28317d43-1800-0000-29ef-6c32020b0000 pid=2818 execve guuid=519e2549-1800-0000-29ef-6c320c0b0000 pid=2828 /usr/bin/chmod guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=519e2549-1800-0000-29ef-6c320c0b0000 pid=2828 execve guuid=2a0c6b49-1800-0000-29ef-6c320e0b0000 pid=2830 /usr/bin/dash guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=2a0c6b49-1800-0000-29ef-6c320e0b0000 pid=2830 clone guuid=d81e7a49-1800-0000-29ef-6c320f0b0000 pid=2831 /usr/bin/curl net send-data guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=d81e7a49-1800-0000-29ef-6c320f0b0000 pid=2831 execve guuid=bbc2444f-1800-0000-29ef-6c321c0b0000 pid=2844 /usr/bin/chmod guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=bbc2444f-1800-0000-29ef-6c321c0b0000 pid=2844 execve guuid=6f547f4f-1800-0000-29ef-6c321e0b0000 pid=2846 /usr/bin/dash guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=6f547f4f-1800-0000-29ef-6c321e0b0000 pid=2846 clone guuid=9bf0834f-1800-0000-29ef-6c321f0b0000 pid=2847 /usr/bin/curl net send-data guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=9bf0834f-1800-0000-29ef-6c321f0b0000 pid=2847 execve guuid=5c0e9454-1800-0000-29ef-6c322a0b0000 pid=2858 /usr/bin/chmod guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=5c0e9454-1800-0000-29ef-6c322a0b0000 pid=2858 execve guuid=a30ae754-1800-0000-29ef-6c322c0b0000 pid=2860 /usr/bin/dash guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=a30ae754-1800-0000-29ef-6c322c0b0000 pid=2860 clone guuid=ed86fc54-1800-0000-29ef-6c322d0b0000 pid=2861 /usr/bin/rm guuid=c9725208-1800-0000-29ef-6c325c0a0000 pid=2652->guuid=ed86fc54-1800-0000-29ef-6c322d0b0000 pid=2861 execve 5e5f7305-15b5-5488-9f49-ae1b177ec723 130.12.180.127:80 guuid=b4f99108-1800-0000-29ef-6c325e0a0000 pid=2654->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 83B guuid=70fbbf10-1800-0000-29ef-6c32790a0000 pid=2681->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B guuid=c3aa3918-1800-0000-29ef-6c328c0a0000 pid=2700->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B guuid=417a6a1f-1800-0000-29ef-6c32a10a0000 pid=2721->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B guuid=60ee1d25-1800-0000-29ef-6c32b40a0000 pid=2740->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B guuid=fa22b62a-1800-0000-29ef-6c32c50a0000 pid=2757->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B guuid=3a8abb32-1800-0000-29ef-6c32d30a0000 pid=2771->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B guuid=6bbeca37-1800-0000-29ef-6c32e00a0000 pid=2784->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 83B guuid=b865a03c-1800-0000-29ef-6c32f00a0000 pid=2800->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 83B guuid=28317d43-1800-0000-29ef-6c32020b0000 pid=2818->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 83B guuid=d81e7a49-1800-0000-29ef-6c320f0b0000 pid=2831->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 83B guuid=9bf0834f-1800-0000-29ef-6c321f0b0000 pid=2847->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 86B
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-12-24 08:02:15 UTC
File Type:
Text (Shell)
AV detection:
10 of 36 (27.78%)
Threat level:
  2/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2753f5f7771d268ea371bd7f3a582295397b5df2877d4ab251358860ad153279

(this sample)

Comments