MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2df134470ad019b6181d7e09e29fa8d30cecf8dec48c2e1851c14d3c49591236. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 2df134470ad019b6181d7e09e29fa8d30cecf8dec48c2e1851c14d3c49591236
SHA3-384 hash: 1de0d2440d0664a0402d97011aabb974cb9f318211d798f7f1f20d2dcde4342b62d1855e23b473da32579d2cee7a445b
SHA1 hash: 6fc3ea1b6b9b3ee576f342b8eae57eff13e9157b
MD5 hash: 5daa02e0bc17a8c37985a73faf87b099
humanhash: ten-lactose-red-stream
File name:d
Download: download sample
Signature Mirai
File size:257 bytes
First seen:2025-09-18 13:49:33 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:/VJ+pUKUF2RVYs5CYf53Iao3FsDKVKAOZwIKa03IKq1IEE1IKBKW:/VJ+jREYjjWgAkMNI08W
TLSH T1C7D02E1CF80208B7F0388CF8B7DB2094E60FA2092A0AA9CE6888012BE0F0C20A060493
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
ps1
First seen:
2025-09-18T13:22:00Z UTC
Last seen:
2025-09-18T13:22:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=f9bcad27-1a00-0000-3cd3-2f65090a0000 pid=2569 /usr/bin/sudo guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576 /tmp/sample.bin guuid=f9bcad27-1a00-0000-3cd3-2f65090a0000 pid=2569->guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576 execve guuid=60c4da29-1a00-0000-3cd3-2f65110a0000 pid=2577 /usr/bin/wget dns net send-data write-file guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=60c4da29-1a00-0000-3cd3-2f65110a0000 pid=2577 execve guuid=2003d85b-1a00-0000-3cd3-2f659c0a0000 pid=2716 /usr/bin/chmod guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=2003d85b-1a00-0000-3cd3-2f659c0a0000 pid=2716 execve guuid=bc364e5c-1a00-0000-3cd3-2f659e0a0000 pid=2718 /usr/bin/dash guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=bc364e5c-1a00-0000-3cd3-2f659e0a0000 pid=2718 clone guuid=a7c55b5c-1a00-0000-3cd3-2f65a00a0000 pid=2720 /usr/bin/rm guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=a7c55b5c-1a00-0000-3cd3-2f65a00a0000 pid=2720 execve guuid=2f82b65c-1a00-0000-3cd3-2f65a10a0000 pid=2721 /usr/bin/wget dns net send-data write-file guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=2f82b65c-1a00-0000-3cd3-2f65a10a0000 pid=2721 execve guuid=8269628d-1a00-0000-3cd3-2f65fd0a0000 pid=2813 /usr/bin/chmod guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=8269628d-1a00-0000-3cd3-2f65fd0a0000 pid=2813 execve guuid=ae1ea28d-1a00-0000-3cd3-2f65ff0a0000 pid=2815 /usr/bin/dash guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=ae1ea28d-1a00-0000-3cd3-2f65ff0a0000 pid=2815 clone guuid=f98ba88d-1a00-0000-3cd3-2f65000b0000 pid=2816 /usr/bin/rm guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=f98ba88d-1a00-0000-3cd3-2f65000b0000 pid=2816 execve guuid=5e27e58d-1a00-0000-3cd3-2f65010b0000 pid=2817 /usr/bin/wget dns net send-data write-file guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=5e27e58d-1a00-0000-3cd3-2f65010b0000 pid=2817 execve guuid=7b3df6b1-1a00-0000-3cd3-2f655b0b0000 pid=2907 /usr/bin/chmod guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=7b3df6b1-1a00-0000-3cd3-2f655b0b0000 pid=2907 execve guuid=fc4d59b2-1a00-0000-3cd3-2f655d0b0000 pid=2909 /usr/bin/dash guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=fc4d59b2-1a00-0000-3cd3-2f655d0b0000 pid=2909 clone guuid=6ea369b2-1a00-0000-3cd3-2f655f0b0000 pid=2911 /usr/bin/rm guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=6ea369b2-1a00-0000-3cd3-2f655f0b0000 pid=2911 execve guuid=7972c9b2-1a00-0000-3cd3-2f65600b0000 pid=2912 /usr/bin/wget dns net send-data write-file guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=7972c9b2-1a00-0000-3cd3-2f65600b0000 pid=2912 execve guuid=4dbb60dc-1a00-0000-3cd3-2f65970b0000 pid=2967 /usr/bin/chmod guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=4dbb60dc-1a00-0000-3cd3-2f65970b0000 pid=2967 execve guuid=00becbdc-1a00-0000-3cd3-2f659a0b0000 pid=2970 /usr/bin/dash guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=00becbdc-1a00-0000-3cd3-2f659a0b0000 pid=2970 clone guuid=a694d8dc-1a00-0000-3cd3-2f659b0b0000 pid=2971 /usr/bin/rm guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=a694d8dc-1a00-0000-3cd3-2f659b0b0000 pid=2971 execve guuid=468b40dd-1a00-0000-3cd3-2f659d0b0000 pid=2973 /usr/bin/wget dns net send-data write-file guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=468b40dd-1a00-0000-3cd3-2f659d0b0000 pid=2973 execve guuid=329b2d03-1b00-0000-3cd3-2f65fc0b0000 pid=3068 /usr/bin/chmod guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=329b2d03-1b00-0000-3cd3-2f65fc0b0000 pid=3068 execve guuid=2a019703-1b00-0000-3cd3-2f65fe0b0000 pid=3070 /usr/bin/dash guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=2a019703-1b00-0000-3cd3-2f65fe0b0000 pid=3070 clone guuid=aebfa303-1b00-0000-3cd3-2f65ff0b0000 pid=3071 /usr/bin/rm guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=aebfa303-1b00-0000-3cd3-2f65ff0b0000 pid=3071 execve guuid=dd23fa03-1b00-0000-3cd3-2f65010c0000 pid=3073 /usr/bin/wget dns net send-data write-file guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=dd23fa03-1b00-0000-3cd3-2f65010c0000 pid=3073 execve guuid=2737d938-1b00-0000-3cd3-2f657c0c0000 pid=3196 /usr/bin/chmod guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=2737d938-1b00-0000-3cd3-2f657c0c0000 pid=3196 execve guuid=0b3b3c39-1b00-0000-3cd3-2f657d0c0000 pid=3197 /usr/bin/dash guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=0b3b3c39-1b00-0000-3cd3-2f657d0c0000 pid=3197 clone guuid=f32c4939-1b00-0000-3cd3-2f657e0c0000 pid=3198 /usr/bin/rm guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=f32c4939-1b00-0000-3cd3-2f657e0c0000 pid=3198 execve guuid=03e49c39-1b00-0000-3cd3-2f657f0c0000 pid=3199 /usr/bin/wget dns net send-data write-file guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=03e49c39-1b00-0000-3cd3-2f657f0c0000 pid=3199 execve guuid=47f38b72-1b00-0000-3cd3-2f65b90c0000 pid=3257 /usr/bin/chmod guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=47f38b72-1b00-0000-3cd3-2f65b90c0000 pid=3257 execve guuid=0021ec72-1b00-0000-3cd3-2f65ba0c0000 pid=3258 /usr/bin/dash guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=0021ec72-1b00-0000-3cd3-2f65ba0c0000 pid=3258 clone guuid=cbddff72-1b00-0000-3cd3-2f65bb0c0000 pid=3259 /usr/bin/rm guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=cbddff72-1b00-0000-3cd3-2f65bb0c0000 pid=3259 execve guuid=c36d5a73-1b00-0000-3cd3-2f65bc0c0000 pid=3260 /usr/bin/wget dns net send-data write-file guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=c36d5a73-1b00-0000-3cd3-2f65bc0c0000 pid=3260 execve guuid=ca266cb3-1b00-0000-3cd3-2f65300d0000 pid=3376 /usr/bin/chmod guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=ca266cb3-1b00-0000-3cd3-2f65300d0000 pid=3376 execve guuid=3809a8b3-1b00-0000-3cd3-2f65310d0000 pid=3377 /usr/bin/dash guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=3809a8b3-1b00-0000-3cd3-2f65310d0000 pid=3377 clone guuid=584fb3b3-1b00-0000-3cd3-2f65330d0000 pid=3379 /usr/bin/rm guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=584fb3b3-1b00-0000-3cd3-2f65330d0000 pid=3379 execve guuid=5e0647b4-1b00-0000-3cd3-2f65350d0000 pid=3381 /usr/bin/wget dns net send-data write-file guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=5e0647b4-1b00-0000-3cd3-2f65350d0000 pid=3381 execve guuid=baf111ea-1b00-0000-3cd3-2f65af0d0000 pid=3503 /usr/bin/chmod guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=baf111ea-1b00-0000-3cd3-2f65af0d0000 pid=3503 execve guuid=bee457ea-1b00-0000-3cd3-2f65b10d0000 pid=3505 /usr/bin/dash guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=bee457ea-1b00-0000-3cd3-2f65b10d0000 pid=3505 clone guuid=6dd266ea-1b00-0000-3cd3-2f65b20d0000 pid=3506 /usr/bin/rm guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=6dd266ea-1b00-0000-3cd3-2f65b20d0000 pid=3506 execve guuid=ff03b9ea-1b00-0000-3cd3-2f65b40d0000 pid=3508 /usr/bin/wget dns net send-data write-file guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=ff03b9ea-1b00-0000-3cd3-2f65b40d0000 pid=3508 execve guuid=49e2b327-1c00-0000-3cd3-2f65140e0000 pid=3604 /usr/bin/chmod guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=49e2b327-1c00-0000-3cd3-2f65140e0000 pid=3604 execve guuid=38922228-1c00-0000-3cd3-2f65170e0000 pid=3607 /usr/bin/dash guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=38922228-1c00-0000-3cd3-2f65170e0000 pid=3607 clone guuid=8d8a3628-1c00-0000-3cd3-2f65180e0000 pid=3608 /usr/bin/rm guuid=793b8e29-1a00-0000-3cd3-2f65100a0000 pid=2576->guuid=8d8a3628-1c00-0000-3cd3-2f65180e0000 pid=3608 execve 9df19bce-d755-5940-91ff-d0e847757959 109.205.213.5:80 guuid=60c4da29-1a00-0000-3cd3-2f65110a0000 pid=2577->9df19bce-d755-5940-91ff-d0e847757959 send: 142B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=60c4da29-1a00-0000-3cd3-2f65110a0000 pid=2577->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=2f82b65c-1a00-0000-3cd3-2f65a10a0000 pid=2721->9df19bce-d755-5940-91ff-d0e847757959 send: 142B guuid=2f82b65c-1a00-0000-3cd3-2f65a10a0000 pid=2721->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=5e27e58d-1a00-0000-3cd3-2f65010b0000 pid=2817->9df19bce-d755-5940-91ff-d0e847757959 send: 141B guuid=5e27e58d-1a00-0000-3cd3-2f65010b0000 pid=2817->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=7972c9b2-1a00-0000-3cd3-2f65600b0000 pid=2912->9df19bce-d755-5940-91ff-d0e847757959 send: 142B guuid=7972c9b2-1a00-0000-3cd3-2f65600b0000 pid=2912->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=468b40dd-1a00-0000-3cd3-2f659d0b0000 pid=2973->9df19bce-d755-5940-91ff-d0e847757959 send: 142B guuid=468b40dd-1a00-0000-3cd3-2f659d0b0000 pid=2973->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=dd23fa03-1b00-0000-3cd3-2f65010c0000 pid=3073->9df19bce-d755-5940-91ff-d0e847757959 send: 142B guuid=dd23fa03-1b00-0000-3cd3-2f65010c0000 pid=3073->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=03e49c39-1b00-0000-3cd3-2f657f0c0000 pid=3199->9df19bce-d755-5940-91ff-d0e847757959 send: 141B guuid=03e49c39-1b00-0000-3cd3-2f657f0c0000 pid=3199->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=c36d5a73-1b00-0000-3cd3-2f65bc0c0000 pid=3260->9df19bce-d755-5940-91ff-d0e847757959 send: 141B guuid=c36d5a73-1b00-0000-3cd3-2f65bc0c0000 pid=3260->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=5e0647b4-1b00-0000-3cd3-2f65350d0000 pid=3381->9df19bce-d755-5940-91ff-d0e847757959 send: 141B guuid=5e0647b4-1b00-0000-3cd3-2f65350d0000 pid=3381->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=ff03b9ea-1b00-0000-3cd3-2f65b40d0000 pid=3508->9df19bce-d755-5940-91ff-d0e847757959 send: 141B guuid=ff03b9ea-1b00-0000-3cd3-2f65b40d0000 pid=3508->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B
Threat name:
Script-Shell.Downloader.MiraiB
Status:
Malicious
First seen:
2025-09-18 14:10:26 UTC
File Type:
Text (Shell)
AV detection:
10 of 38 (26.32%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2df134470ad019b6181d7e09e29fa8d30cecf8dec48c2e1851c14d3c49591236

(this sample)

  
Delivery method
Distributed via web download

Comments