MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 31be8265aea2d632bbca6e4d924e9070c87d770ed250c38a1fc4c174d15b5209. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 31be8265aea2d632bbca6e4d924e9070c87d770ed250c38a1fc4c174d15b5209
SHA3-384 hash: efac340c2904eb7e3eabbc847e0a12a12b74f87d61658b2fd22f8c34b4571722c1d00055a64f9a69ba09ee0cb1b68555
SHA1 hash: d6c647341bb81e3ed0dd4c91216879458d232a7e
MD5 hash: 34b884acbca4df0631e99cbdc4530710
humanhash: magnesium-jupiter-april-salami
File name:router.zyxel.sh
Download: download sample
Signature Mirai
File size:1'464 bytes
First seen:2025-08-22 18:51:39 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:nxp4YHPJREY7HbvT7ldvnPt/e3JkPzgIiJSga:xCOxe4bbh15eGiBa
TLSH T115315ACA989DB209B0E9CB02B803D7149F0EC9A3DE801F94978C7CBAD78DD15F46564C
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.69.194/kitty.armv7l80e712507f9e79bfe2b455dc77350d5e4036946a0417225f6f4f3a2ff940d078 Miraielf mirai ua-wget
http://196.251.69.194/kitty.armv6lc1ea896950b50eb46534a8a3aba9c0b6ac50483717822a8bae8eb439b576e94c Miraielf mirai ua-wget
http://196.251.69.194/kitty.armv5l955ff456db1482947fcaa4a2ca57a372e0ea3ab9e92a2c6c34c1a97b85269b50 Miraielf geofenced mirai ua-wget UK
http://196.251.69.194/kitty.mipsn/an/aelf mirai ua-wget
http://196.251.69.194/kitty.mipselcb93ba4bdeca9b98b820e6a54f5ce7259c6dea673d8ee2b92e88d39f70efb8ea Miraielf mirai ua-wget
http://196.251.69.194/kitty.aarch641a930b4aa7c5f6e140466a8309037bf5def5614f7ed514bd9010868b8f51710b Tsunamielf mirai Tsunami ua-wget
http://196.251.69.194/kitty.i6861856f5b82ce74dec870cdc0532a1aafcbb952a73f73268283fee5829ca0843a4 Miraielf mirai ua-wget
http://196.251.69.194/kitty.i486dff8915b9e3eaddfd2383c1b061ab2a0a0272d351a7d9bb8147a2b62b9ed3048 Miraielf geofenced mirai ua-wget UK
http://196.251.69.194/kitty.x86_64n/an/aelf mirai ua-wget
http://196.251.69.194/kitty.powerpc30fcafea6ab423a85ade81a48e89cd23e195ed24c746ed908b68d897b2c88dbc Miraielf mirai ua-wget
http://196.251.69.194/kitty.powerpc641fa67e0be9dac19cd3a37a238f58eb1c0d160352d874bbfc423db7444c5b5ccb Miraielf mirai ua-wget
http://196.251.69.194/kitty.m68kbaf58c8b685e602fc75a3591005d3f9f2bfc5ea0ccce6bf54e542a29fe5cd048 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-08-23T00:53:00Z UTC
Last seen:
2025-08-23T00:53:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=fd77dd10-1900-0000-fb35-649ef6110000 pid=4598 /usr/bin/sudo guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604 /tmp/sample.bin guuid=fd77dd10-1900-0000-fb35-649ef6110000 pid=4598->guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604 execve guuid=c0c5c113-1900-0000-fb35-649efd110000 pid=4605 /usr/bin/busybox net send-data write-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=c0c5c113-1900-0000-fb35-649efd110000 pid=4605 execve guuid=d6b60618-1900-0000-fb35-649e0c120000 pid=4620 /usr/bin/chmod guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=d6b60618-1900-0000-fb35-649e0c120000 pid=4620 execve guuid=68e43f18-1900-0000-fb35-649e0d120000 pid=4621 /usr/bin/dash guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=68e43f18-1900-0000-fb35-649e0d120000 pid=4621 clone guuid=0b088219-1900-0000-fb35-649e0f120000 pid=4623 /usr/bin/rm delete-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=0b088219-1900-0000-fb35-649e0f120000 pid=4623 execve guuid=3557c219-1900-0000-fb35-649e11120000 pid=4625 /usr/bin/busybox net send-data write-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=3557c219-1900-0000-fb35-649e11120000 pid=4625 execve guuid=5b6d101e-1900-0000-fb35-649e25120000 pid=4645 /usr/bin/chmod guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=5b6d101e-1900-0000-fb35-649e25120000 pid=4645 execve guuid=fdaf5e1e-1900-0000-fb35-649e26120000 pid=4646 /usr/bin/dash guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=fdaf5e1e-1900-0000-fb35-649e26120000 pid=4646 clone guuid=a2f8121f-1900-0000-fb35-649e2a120000 pid=4650 /usr/bin/rm delete-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=a2f8121f-1900-0000-fb35-649e2a120000 pid=4650 execve guuid=93db5c1f-1900-0000-fb35-649e2c120000 pid=4652 /usr/bin/busybox net send-data write-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=93db5c1f-1900-0000-fb35-649e2c120000 pid=4652 execve guuid=be5b4823-1900-0000-fb35-649e35120000 pid=4661 /usr/bin/chmod guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=be5b4823-1900-0000-fb35-649e35120000 pid=4661 execve guuid=789ab323-1900-0000-fb35-649e38120000 pid=4664 /usr/bin/dash guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=789ab323-1900-0000-fb35-649e38120000 pid=4664 clone guuid=fdb09b24-1900-0000-fb35-649e3d120000 pid=4669 /usr/bin/rm delete-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=fdb09b24-1900-0000-fb35-649e3d120000 pid=4669 execve guuid=0ec4f324-1900-0000-fb35-649e3f120000 pid=4671 /usr/bin/busybox net send-data write-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=0ec4f324-1900-0000-fb35-649e3f120000 pid=4671 execve guuid=9278432b-1900-0000-fb35-649e55120000 pid=4693 /usr/bin/chmod guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=9278432b-1900-0000-fb35-649e55120000 pid=4693 execve guuid=0a5a9a2b-1900-0000-fb35-649e57120000 pid=4695 /usr/bin/dash guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=0a5a9a2b-1900-0000-fb35-649e57120000 pid=4695 clone guuid=9560602c-1900-0000-fb35-649e5c120000 pid=4700 /usr/bin/rm delete-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=9560602c-1900-0000-fb35-649e5c120000 pid=4700 execve guuid=15f1bc2c-1900-0000-fb35-649e5d120000 pid=4701 /usr/bin/busybox net send-data write-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=15f1bc2c-1900-0000-fb35-649e5d120000 pid=4701 execve guuid=9c057f31-1900-0000-fb35-649e6c120000 pid=4716 /usr/bin/chmod guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=9c057f31-1900-0000-fb35-649e6c120000 pid=4716 execve guuid=1e7fef31-1900-0000-fb35-649e6f120000 pid=4719 /usr/bin/dash guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=1e7fef31-1900-0000-fb35-649e6f120000 pid=4719 clone guuid=06317734-1900-0000-fb35-649e76120000 pid=4726 /usr/bin/rm delete-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=06317734-1900-0000-fb35-649e76120000 pid=4726 execve guuid=ca3af334-1900-0000-fb35-649e7b120000 pid=4731 /usr/bin/busybox net send-data write-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=ca3af334-1900-0000-fb35-649e7b120000 pid=4731 execve guuid=e10cd839-1900-0000-fb35-649e87120000 pid=4743 /usr/bin/chmod guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=e10cd839-1900-0000-fb35-649e87120000 pid=4743 execve guuid=a5c73e3a-1900-0000-fb35-649e89120000 pid=4745 /usr/bin/dash guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=a5c73e3a-1900-0000-fb35-649e89120000 pid=4745 clone guuid=c6e4fe3a-1900-0000-fb35-649e8c120000 pid=4748 /usr/bin/rm delete-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=c6e4fe3a-1900-0000-fb35-649e8c120000 pid=4748 execve guuid=2b88563b-1900-0000-fb35-649e8d120000 pid=4749 /usr/bin/busybox net send-data write-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=2b88563b-1900-0000-fb35-649e8d120000 pid=4749 execve guuid=98a2e93f-1900-0000-fb35-649e91120000 pid=4753 /usr/bin/chmod guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=98a2e93f-1900-0000-fb35-649e91120000 pid=4753 execve guuid=89d86340-1900-0000-fb35-649e92120000 pid=4754 /home/sandbox/kitty.i686 guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=89d86340-1900-0000-fb35-649e92120000 pid=4754 execve guuid=1212b140-1900-0000-fb35-649e95120000 pid=4757 /usr/bin/rm guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=1212b140-1900-0000-fb35-649e95120000 pid=4757 execve guuid=7cf5ec40-1900-0000-fb35-649e98120000 pid=4760 /usr/bin/busybox net send-data write-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=7cf5ec40-1900-0000-fb35-649e98120000 pid=4760 execve guuid=f2896045-1900-0000-fb35-649ea3120000 pid=4771 /usr/bin/chmod guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=f2896045-1900-0000-fb35-649ea3120000 pid=4771 execve guuid=4c091946-1900-0000-fb35-649ea4120000 pid=4772 /home/sandbox/kitty.i486 guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=4c091946-1900-0000-fb35-649ea4120000 pid=4772 execve guuid=2faa5746-1900-0000-fb35-649ea7120000 pid=4775 /usr/bin/rm guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=2faa5746-1900-0000-fb35-649ea7120000 pid=4775 execve guuid=7883c046-1900-0000-fb35-649eaa120000 pid=4778 /usr/bin/busybox net send-data write-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=7883c046-1900-0000-fb35-649eaa120000 pid=4778 execve guuid=0166974b-1900-0000-fb35-649eb5120000 pid=4789 /usr/bin/chmod guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=0166974b-1900-0000-fb35-649eb5120000 pid=4789 execve guuid=25fdf24b-1900-0000-fb35-649eb7120000 pid=4791 /home/sandbox/kitty.x86_64 guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=25fdf24b-1900-0000-fb35-649eb7120000 pid=4791 execve guuid=dd740a4c-1900-0000-fb35-649eba120000 pid=4794 /usr/bin/rm guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=dd740a4c-1900-0000-fb35-649eba120000 pid=4794 execve guuid=3d25764c-1900-0000-fb35-649ebc120000 pid=4796 /usr/bin/busybox net send-data write-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=3d25764c-1900-0000-fb35-649ebc120000 pid=4796 execve guuid=39c84752-1900-0000-fb35-649eca120000 pid=4810 /usr/bin/chmod guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=39c84752-1900-0000-fb35-649eca120000 pid=4810 execve guuid=6523b552-1900-0000-fb35-649ecd120000 pid=4813 /usr/bin/dash guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=6523b552-1900-0000-fb35-649ecd120000 pid=4813 clone guuid=44e7dc53-1900-0000-fb35-649ed2120000 pid=4818 /usr/bin/rm delete-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=44e7dc53-1900-0000-fb35-649ed2120000 pid=4818 execve guuid=41d42c54-1900-0000-fb35-649ed3120000 pid=4819 /usr/bin/busybox net send-data write-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=41d42c54-1900-0000-fb35-649ed3120000 pid=4819 execve guuid=0425fc58-1900-0000-fb35-649edf120000 pid=4831 /usr/bin/chmod guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=0425fc58-1900-0000-fb35-649edf120000 pid=4831 execve guuid=e2307a59-1900-0000-fb35-649ee1120000 pid=4833 /usr/bin/dash guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=e2307a59-1900-0000-fb35-649ee1120000 pid=4833 clone guuid=1724725a-1900-0000-fb35-649ee5120000 pid=4837 /usr/bin/rm delete-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=1724725a-1900-0000-fb35-649ee5120000 pid=4837 execve guuid=72b9d35a-1900-0000-fb35-649ee8120000 pid=4840 /usr/bin/busybox net send-data write-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=72b9d35a-1900-0000-fb35-649ee8120000 pid=4840 execve guuid=5574d55e-1900-0000-fb35-649ef4120000 pid=4852 /usr/bin/chmod guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=5574d55e-1900-0000-fb35-649ef4120000 pid=4852 execve guuid=bc3e275f-1900-0000-fb35-649ef5120000 pid=4853 /usr/bin/dash guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=bc3e275f-1900-0000-fb35-649ef5120000 pid=4853 clone guuid=159d3861-1900-0000-fb35-649efc120000 pid=4860 /usr/bin/rm delete-file guuid=f3667f13-1900-0000-fb35-649efc110000 pid=4604->guuid=159d3861-1900-0000-fb35-649efc120000 pid=4860 execve 2e1ba108-bb79-560a-bab6-417767220e51 196.251.69.194:80 guuid=c0c5c113-1900-0000-fb35-649efd110000 pid=4605->2e1ba108-bb79-560a-bab6-417767220e51 send: 89B guuid=3557c219-1900-0000-fb35-649e11120000 pid=4625->2e1ba108-bb79-560a-bab6-417767220e51 send: 89B guuid=93db5c1f-1900-0000-fb35-649e2c120000 pid=4652->2e1ba108-bb79-560a-bab6-417767220e51 send: 89B guuid=0ec4f324-1900-0000-fb35-649e3f120000 pid=4671->2e1ba108-bb79-560a-bab6-417767220e51 send: 87B guuid=15f1bc2c-1900-0000-fb35-649e5d120000 pid=4701->2e1ba108-bb79-560a-bab6-417767220e51 send: 89B guuid=ca3af334-1900-0000-fb35-649e7b120000 pid=4731->2e1ba108-bb79-560a-bab6-417767220e51 send: 90B guuid=2b88563b-1900-0000-fb35-649e8d120000 pid=4749->2e1ba108-bb79-560a-bab6-417767220e51 send: 87B guuid=95178c40-1900-0000-fb35-649e93120000 pid=4755 /home/sandbox/kitty.i686 guuid=89d86340-1900-0000-fb35-649e92120000 pid=4754->guuid=95178c40-1900-0000-fb35-649e93120000 pid=4755 clone guuid=a7c59a40-1900-0000-fb35-649e94120000 pid=4756 /home/sandbox/kitty.i686 delete-file net send-data zombie guuid=95178c40-1900-0000-fb35-649e93120000 pid=4755->guuid=a7c59a40-1900-0000-fb35-649e94120000 pid=4756 clone eb9dca7b-d301-522e-83c7-8d6f291efc38 66.78.40.221:9080 guuid=a7c59a40-1900-0000-fb35-649e94120000 pid=4756->eb9dca7b-d301-522e-83c7-8d6f291efc38 send: 70B b0abba15-9a34-51cb-a2ff-3008f7e59616 208.67.222.222:53 guuid=a7c59a40-1900-0000-fb35-649e94120000 pid=4756->b0abba15-9a34-51cb-a2ff-3008f7e59616 send: 40B 6a6ce952-23cd-5c51-b461-6ca6a8c64225 1.0.0.1:53 guuid=a7c59a40-1900-0000-fb35-649e94120000 pid=4756->6a6ce952-23cd-5c51-b461-6ca6a8c64225 send: 40B guuid=7cf5ec40-1900-0000-fb35-649e98120000 pid=4760->2e1ba108-bb79-560a-bab6-417767220e51 send: 87B guuid=b1544546-1900-0000-fb35-649ea6120000 pid=4774 /home/sandbox/kitty.i486 guuid=4c091946-1900-0000-fb35-649ea4120000 pid=4772->guuid=b1544546-1900-0000-fb35-649ea6120000 pid=4774 clone guuid=de0e5d46-1900-0000-fb35-649ea8120000 pid=4776 /home/sandbox/kitty.i486 delete-file net send-data zombie guuid=b1544546-1900-0000-fb35-649ea6120000 pid=4774->guuid=de0e5d46-1900-0000-fb35-649ea8120000 pid=4776 clone guuid=de0e5d46-1900-0000-fb35-649ea8120000 pid=4776->eb9dca7b-d301-522e-83c7-8d6f291efc38 send: 35B ac570862-0b5b-558b-b43c-fb15134a62c4 114.114.114.114:53 guuid=de0e5d46-1900-0000-fb35-649ea8120000 pid=4776->ac570862-0b5b-558b-b43c-fb15134a62c4 send: 40B guuid=7883c046-1900-0000-fb35-649eaa120000 pid=4778->2e1ba108-bb79-560a-bab6-417767220e51 send: 89B guuid=39e8024c-1900-0000-fb35-649eb8120000 pid=4792 /home/sandbox/kitty.x86_64 zombie guuid=25fdf24b-1900-0000-fb35-649eb7120000 pid=4791->guuid=39e8024c-1900-0000-fb35-649eb8120000 pid=4792 clone guuid=f92d0a4c-1900-0000-fb35-649eb9120000 pid=4793 /home/sandbox/kitty.x86_64 delete-file net send-data zombie guuid=39e8024c-1900-0000-fb35-649eb8120000 pid=4792->guuid=f92d0a4c-1900-0000-fb35-649eb9120000 pid=4793 clone guuid=f92d0a4c-1900-0000-fb35-649eb9120000 pid=4793->eb9dca7b-d301-522e-83c7-8d6f291efc38 send: 74B guuid=f92d0a4c-1900-0000-fb35-649eb9120000 pid=4793->6a6ce952-23cd-5c51-b461-6ca6a8c64225 send: 80B guuid=3d25764c-1900-0000-fb35-649ebc120000 pid=4796->2e1ba108-bb79-560a-bab6-417767220e51 send: 90B guuid=41d42c54-1900-0000-fb35-649ed3120000 pid=4819->2e1ba108-bb79-560a-bab6-417767220e51 send: 92B guuid=72b9d35a-1900-0000-fb35-649ee8120000 pid=4840->2e1ba108-bb79-560a-bab6-417767220e51 send: 87B
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-08-22 18:52:35 UTC
File Type:
Text (Shell)
AV detection:
15 of 38 (39.47%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 31be8265aea2d632bbca6e4d924e9070c87d770ed250c38a1fc4c174d15b5209

(this sample)

  
Delivery method
Distributed via web download

Comments