MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2edf0a19d074fb88dba301442d78321e59a37a671cd45b7a9c2af216341fc951. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 2edf0a19d074fb88dba301442d78321e59a37a671cd45b7a9c2af216341fc951
SHA3-384 hash: 2f4ee52139d84be7b255111570d76bde55dd62ea777fe60904d7432dad36b696989115265f717cb43776aff16db8362c
SHA1 hash: 0e1c544140ff92df0c339dffc9238b825442b968
MD5 hash: 42225d45c7c391200cd3040522e0fb0b
humanhash: double-fillet-autumn-triple
File name:wget.sh
Download: download sample
Signature Mirai
File size:754 bytes
First seen:2025-06-21 19:31:03 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:kuQj+/bLq+/xNIl5zA+/if0LKj+/SgOs+/VC+/oa/+/kSE+/FtaKA+/U0j+/HiA4:NQeLZNI7HKDgGIajutBGvAxv
TLSH T10D0195DE25715369050CCE18F16F4B6C6A8B9BC0B0748E99AC88197BBCD9F04B068F4B
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.20.102.84/arm2a1784fe8e62a215af8edbf16a1be72eb97436e5b314014fc67c69e063f82628 Miraicensys elf mirai ua-wget
http://103.20.102.84/arm5718c9d1905c62a6fed982fb0d52366417cc88c50482d924d8521c62c0cf01eba Miraicensys elf mirai ua-wget
http://103.20.102.84/arm6b78a40c5cfe60dac573574bc6d166596fe6053f24646bbf65468d8272bf82f90 Miraicensys elf mirai ua-wget
http://103.20.102.84/arm7ed3f02939036caf9222d47af47e32a1cab1d8fb3e8614f0281f3e2bc768f444b Miraicensys DEU elf geofenced mirai ua-wget
http://103.20.102.84/m68ka1b3a375a2a86d3ca87efb0ad6821d48958b020ca2240440f091a67441d6ae0b Miraicensys elf mirai ua-wget
http://103.20.102.84/mips1696726d9e61fdb92483cd792fe78121f10e6f46489fce7e78f975cc132d10cf Miraicensys elf mirai ua-wget
http://103.20.102.84/mpsl04d9d3b365ade8ea025dc8e7bb3dc5624ea89185435263b00cb96d238cf76ba2 Miraicensys elf mirai ua-wget
http://103.20.102.84/ppc00d5063c4ed84d4fd055d039da489c07e0cd10f9f7c52332cd2b5695145ffe3b Miraicensys elf mirai ua-wget
http://103.20.102.84/sh480f711fa14fe135a23c1d31064d83545f41f3df1e0c8c88ec0442ec7b8eb9d34 Miraicensys elf mirai ua-wget
http://103.20.102.84/spcae7f4dd7ff7cc7f64216b92e26366797247a61e47e0524433284613304b14e78 Miraicensys elf mirai ua-wget
http://103.20.102.84/x86ce6595654dcd1cf8e6802e0538b82d06a3c44ec488bcf9e3331bc74bad6ad017 Miraicensys elf mirai ua-wget
http://103.20.102.84/x86_649e892c7701dabb3f4f898ecf9b49c764fa217d0510776a1c79f73034445905f6 Miraicensys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
lolbin remote
Status:
terminated
Behavior Graph:
%3 guuid=aab45055-2100-0000-db95-92e77f070000 pid=1919 /usr/bin/sudo guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920 /tmp/sample.bin guuid=aab45055-2100-0000-db95-92e77f070000 pid=1919->guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920 execve guuid=7e919a58-2100-0000-db95-92e781070000 pid=1921 /usr/bin/wget net send-data write-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=7e919a58-2100-0000-db95-92e781070000 pid=1921 execve guuid=38b242a8-2100-0000-db95-92e7df070000 pid=2015 /usr/bin/chmod guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=38b242a8-2100-0000-db95-92e7df070000 pid=2015 execve guuid=36a292a8-2100-0000-db95-92e7e1070000 pid=2017 /usr/bin/dash guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=36a292a8-2100-0000-db95-92e7e1070000 pid=2017 clone guuid=49256baa-2100-0000-db95-92e7e5070000 pid=2021 /usr/bin/wget net send-data write-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=49256baa-2100-0000-db95-92e7e5070000 pid=2021 execve guuid=a80114d3-2100-0000-db95-92e73b080000 pid=2107 /usr/bin/chmod guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=a80114d3-2100-0000-db95-92e73b080000 pid=2107 execve guuid=b35ecfd3-2100-0000-db95-92e73e080000 pid=2110 /usr/bin/dash guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=b35ecfd3-2100-0000-db95-92e73e080000 pid=2110 clone guuid=32395ad4-2100-0000-db95-92e741080000 pid=2113 /usr/bin/wget net send-data write-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=32395ad4-2100-0000-db95-92e741080000 pid=2113 execve guuid=d338130a-2200-0000-db95-92e7c3080000 pid=2243 /usr/bin/chmod guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=d338130a-2200-0000-db95-92e7c3080000 pid=2243 execve guuid=dc65550a-2200-0000-db95-92e7c4080000 pid=2244 /usr/bin/dash guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=dc65550a-2200-0000-db95-92e7c4080000 pid=2244 clone guuid=f87e8a0b-2200-0000-db95-92e7c6080000 pid=2246 /usr/bin/wget net send-data write-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=f87e8a0b-2200-0000-db95-92e7c6080000 pid=2246 execve guuid=794fe84e-2200-0000-db95-92e736090000 pid=2358 /usr/bin/chmod guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=794fe84e-2200-0000-db95-92e736090000 pid=2358 execve guuid=cc637c4f-2200-0000-db95-92e738090000 pid=2360 /usr/bin/dash guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=cc637c4f-2200-0000-db95-92e738090000 pid=2360 clone guuid=f0701a50-2200-0000-db95-92e73c090000 pid=2364 /usr/bin/wget net send-data write-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=f0701a50-2200-0000-db95-92e73c090000 pid=2364 execve guuid=b3923488-2200-0000-db95-92e7b9090000 pid=2489 /usr/bin/chmod guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=b3923488-2200-0000-db95-92e7b9090000 pid=2489 execve guuid=be0f7888-2200-0000-db95-92e7ba090000 pid=2490 /usr/bin/dash guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=be0f7888-2200-0000-db95-92e7ba090000 pid=2490 clone guuid=33811589-2200-0000-db95-92e7bd090000 pid=2493 /usr/bin/wget net send-data write-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=33811589-2200-0000-db95-92e7bd090000 pid=2493 execve guuid=8bb820bf-2200-0000-db95-92e73d0a0000 pid=2621 /usr/bin/chmod guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=8bb820bf-2200-0000-db95-92e73d0a0000 pid=2621 execve guuid=281adebf-2200-0000-db95-92e7400a0000 pid=2624 /usr/bin/dash guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=281adebf-2200-0000-db95-92e7400a0000 pid=2624 clone guuid=de6673c0-2200-0000-db95-92e7440a0000 pid=2628 /usr/bin/wget net send-data write-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=de6673c0-2200-0000-db95-92e7440a0000 pid=2628 execve guuid=6125d4f4-2200-0000-db95-92e7cf0a0000 pid=2767 /usr/bin/chmod guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=6125d4f4-2200-0000-db95-92e7cf0a0000 pid=2767 execve guuid=20181cf5-2200-0000-db95-92e7d00a0000 pid=2768 /usr/bin/dash guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=20181cf5-2200-0000-db95-92e7d00a0000 pid=2768 clone guuid=b658cdf5-2200-0000-db95-92e7d50a0000 pid=2773 /usr/bin/wget net send-data write-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=b658cdf5-2200-0000-db95-92e7d50a0000 pid=2773 execve guuid=8406b82b-2300-0000-db95-92e72a0b0000 pid=2858 /usr/bin/chmod guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=8406b82b-2300-0000-db95-92e72a0b0000 pid=2858 execve guuid=56eff62b-2300-0000-db95-92e72c0b0000 pid=2860 /usr/bin/dash guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=56eff62b-2300-0000-db95-92e72c0b0000 pid=2860 clone guuid=d3e5822c-2300-0000-db95-92e72f0b0000 pid=2863 /usr/bin/wget net send-data write-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=d3e5822c-2300-0000-db95-92e72f0b0000 pid=2863 execve guuid=8e2b6962-2300-0000-db95-92e7ae0b0000 pid=2990 /usr/bin/chmod guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=8e2b6962-2300-0000-db95-92e7ae0b0000 pid=2990 execve guuid=e71aa762-2300-0000-db95-92e7af0b0000 pid=2991 /usr/bin/dash guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=e71aa762-2300-0000-db95-92e7af0b0000 pid=2991 clone guuid=402f1c63-2300-0000-db95-92e7b10b0000 pid=2993 /usr/bin/wget net send-data write-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=402f1c63-2300-0000-db95-92e7b10b0000 pid=2993 execve guuid=cfca2a98-2300-0000-db95-92e7380c0000 pid=3128 /usr/bin/chmod guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=cfca2a98-2300-0000-db95-92e7380c0000 pid=3128 execve guuid=bac28098-2300-0000-db95-92e73a0c0000 pid=3130 /usr/bin/dash guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=bac28098-2300-0000-db95-92e73a0c0000 pid=3130 clone guuid=9d1dff98-2300-0000-db95-92e73e0c0000 pid=3134 /usr/bin/wget net send-data write-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=9d1dff98-2300-0000-db95-92e73e0c0000 pid=3134 execve guuid=67c64fd1-2300-0000-db95-92e7980c0000 pid=3224 /usr/bin/chmod guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=67c64fd1-2300-0000-db95-92e7980c0000 pid=3224 execve guuid=f4fb9ad1-2300-0000-db95-92e7990c0000 pid=3225 /home/sandbox/x86 net guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=f4fb9ad1-2300-0000-db95-92e7990c0000 pid=3225 execve guuid=367fffd1-2300-0000-db95-92e79c0c0000 pid=3228 /usr/bin/wget net send-data write-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=367fffd1-2300-0000-db95-92e79c0c0000 pid=3228 execve guuid=1a79ab0a-2400-0000-db95-92e7ce0c0000 pid=3278 /usr/bin/chmod guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=1a79ab0a-2400-0000-db95-92e7ce0c0000 pid=3278 execve guuid=a158f20a-2400-0000-db95-92e7d00c0000 pid=3280 /home/sandbox/x86_64 net guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=a158f20a-2400-0000-db95-92e7d00c0000 pid=3280 execve guuid=63ee2b0c-2400-0000-db95-92e7da0c0000 pid=3290 /usr/bin/rm delete-file guuid=f08e5e58-2100-0000-db95-92e780070000 pid=1920->guuid=63ee2b0c-2400-0000-db95-92e7da0c0000 pid=3290 execve 3facbf0f-3b96-584f-8c0a-db279242f5a0 103.20.102.84:80 guuid=7e919a58-2100-0000-db95-92e781070000 pid=1921->3facbf0f-3b96-584f-8c0a-db279242f5a0 send: 131B guuid=49256baa-2100-0000-db95-92e7e5070000 pid=2021->3facbf0f-3b96-584f-8c0a-db279242f5a0 send: 132B guuid=32395ad4-2100-0000-db95-92e741080000 pid=2113->3facbf0f-3b96-584f-8c0a-db279242f5a0 send: 132B guuid=f87e8a0b-2200-0000-db95-92e7c6080000 pid=2246->3facbf0f-3b96-584f-8c0a-db279242f5a0 send: 132B guuid=f0701a50-2200-0000-db95-92e73c090000 pid=2364->3facbf0f-3b96-584f-8c0a-db279242f5a0 send: 132B guuid=33811589-2200-0000-db95-92e7bd090000 pid=2493->3facbf0f-3b96-584f-8c0a-db279242f5a0 send: 132B guuid=de6673c0-2200-0000-db95-92e7440a0000 pid=2628->3facbf0f-3b96-584f-8c0a-db279242f5a0 send: 132B guuid=b658cdf5-2200-0000-db95-92e7d50a0000 pid=2773->3facbf0f-3b96-584f-8c0a-db279242f5a0 send: 131B guuid=d3e5822c-2300-0000-db95-92e72f0b0000 pid=2863->3facbf0f-3b96-584f-8c0a-db279242f5a0 send: 131B guuid=402f1c63-2300-0000-db95-92e7b10b0000 pid=2993->3facbf0f-3b96-584f-8c0a-db279242f5a0 send: 131B guuid=9d1dff98-2300-0000-db95-92e73e0c0000 pid=3134->3facbf0f-3b96-584f-8c0a-db279242f5a0 send: 131B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f4fb9ad1-2300-0000-db95-92e7990c0000 pid=3225->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d7b6b8d1-2300-0000-db95-92e79a0c0000 pid=3226 /usr/bin/dash guuid=f4fb9ad1-2300-0000-db95-92e7990c0000 pid=3225->guuid=d7b6b8d1-2300-0000-db95-92e79a0c0000 pid=3226 execve guuid=3ccaf8d1-2300-0000-db95-92e79b0c0000 pid=3227 /home/sandbox/x86 dns net send-data zombie guuid=f4fb9ad1-2300-0000-db95-92e7990c0000 pid=3225->guuid=3ccaf8d1-2300-0000-db95-92e79b0c0000 pid=3227 clone guuid=3ccaf8d1-2300-0000-db95-92e79b0c0000 pid=3227->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 444B 1a64f1e6-9e8d-52cd-a2dc-7a1f1ace627c mdnsucchim.ddns.net:56999 guuid=3ccaf8d1-2300-0000-db95-92e79b0c0000 pid=3227->1a64f1e6-9e8d-52cd-a2dc-7a1f1ace627c send: 11B guuid=c08107d2-2300-0000-db95-92e79d0c0000 pid=3229 /home/sandbox/x86 guuid=3ccaf8d1-2300-0000-db95-92e79b0c0000 pid=3227->guuid=c08107d2-2300-0000-db95-92e79d0c0000 pid=3229 clone guuid=2a8c0bd2-2300-0000-db95-92e79e0c0000 pid=3230 /home/sandbox/x86 net net-scan send-data guuid=3ccaf8d1-2300-0000-db95-92e79b0c0000 pid=3227->guuid=2a8c0bd2-2300-0000-db95-92e79e0c0000 pid=3230 clone e9af3f79-55a9-58a7-a1bf-42292c2705c5 mdnsucchim.ddns.net:80 guuid=367fffd1-2300-0000-db95-92e79c0c0000 pid=3228->e9af3f79-55a9-58a7-a1bf-42292c2705c5 send: 134B guuid=2a8c0bd2-2300-0000-db95-92e79e0c0000 pid=3230->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con db2021a9-0548-501c-8eda-7af402189291 197.51.79.225:37215 guuid=2a8c0bd2-2300-0000-db95-92e79e0c0000 pid=3230->db2021a9-0548-501c-8eda-7af402189291 send: 40B guuid=2a8c0bd2-2300-0000-db95-92e79e0c0000 pid=3230|send-data send-data to 4097 IP addresses review logs to see them all guuid=2a8c0bd2-2300-0000-db95-92e79e0c0000 pid=3230->guuid=2a8c0bd2-2300-0000-db95-92e79e0c0000 pid=3230|send-data send guuid=a158f20a-2400-0000-db95-92e7d00c0000 pid=3280->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b516010b-2400-0000-db95-92e7d10c0000 pid=3281 /usr/bin/dash guuid=a158f20a-2400-0000-db95-92e7d00c0000 pid=3280->guuid=b516010b-2400-0000-db95-92e7d10c0000 pid=3281 execve guuid=4114250c-2400-0000-db95-92e7d90c0000 pid=3289 /home/sandbox/x86_64 dns net send-data zombie guuid=a158f20a-2400-0000-db95-92e7d00c0000 pid=3280->guuid=4114250c-2400-0000-db95-92e7d90c0000 pid=3289 clone guuid=dfa33d0b-2400-0000-db95-92e7d30c0000 pid=3283 /usr/bin/rm guuid=b516010b-2400-0000-db95-92e7d10c0000 pid=3281->guuid=dfa33d0b-2400-0000-db95-92e7d30c0000 pid=3283 execve guuid=c3fc7b0b-2400-0000-db95-92e7d50c0000 pid=3285 /usr/bin/mkdir guuid=b516010b-2400-0000-db95-92e7d10c0000 pid=3281->guuid=c3fc7b0b-2400-0000-db95-92e7d50c0000 pid=3285 execve guuid=33c2db0b-2400-0000-db95-92e7d70c0000 pid=3287 /usr/bin/chmod guuid=b516010b-2400-0000-db95-92e7d10c0000 pid=3281->guuid=33c2db0b-2400-0000-db95-92e7d70c0000 pid=3287 execve guuid=4114250c-2400-0000-db95-92e7d90c0000 pid=3289->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 518B guuid=4114250c-2400-0000-db95-92e7d90c0000 pid=3289->1a64f1e6-9e8d-52cd-a2dc-7a1f1ace627c send: 11B guuid=c490320c-2400-0000-db95-92e7db0c0000 pid=3291 /home/sandbox/x86_64 guuid=4114250c-2400-0000-db95-92e7d90c0000 pid=3289->guuid=c490320c-2400-0000-db95-92e7db0c0000 pid=3291 clone guuid=ef4e380c-2400-0000-db95-92e7dd0c0000 pid=3293 /home/sandbox/x86_64 net net-scan send-data guuid=4114250c-2400-0000-db95-92e7d90c0000 pid=3289->guuid=ef4e380c-2400-0000-db95-92e7dd0c0000 pid=3293 clone guuid=ef4e380c-2400-0000-db95-92e7dd0c0000 pid=3293->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ef4e380c-2400-0000-db95-92e7dd0c0000 pid=3293|send-data send-data to 4097 IP addresses review logs to see them all guuid=ef4e380c-2400-0000-db95-92e7dd0c0000 pid=3293->guuid=ef4e380c-2400-0000-db95-92e7dd0c0000 pid=3293|send-data send
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-06-21 19:39:09 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2edf0a19d074fb88dba301442d78321e59a37a671cd45b7a9c2af216341fc951

(this sample)

  
Delivery method
Distributed via web download

Comments