MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3e47b3a535f5dca6b395e09cba27452e33e56b2c827eada547c59f8eda9cbe47. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 3e47b3a535f5dca6b395e09cba27452e33e56b2c827eada547c59f8eda9cbe47
SHA3-384 hash: 01df34aafb609c169f066ead72c78d55b8694a653cf91d5fcd32ecca2687a4ba478b52234e33c56be53646665f87b302
SHA1 hash: c182339a5638d0ebd872a103c70043f9d88dd49c
MD5 hash: 76637f958b376a54011476281fe26ce9
humanhash: stream-paris-ink-connecticut
File name:router.zyxel.sh
Download: download sample
Signature Mirai
File size:1'361 bytes
First seen:2025-08-20 05:21:43 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:vx0x4zxHCxJeEzx7HboT0lKvgPt/e3JJPzgIiJjga:50qz9CjXzxbysY4ejiWa
TLSH T1FA214D9A885DB109B0FACB02B81397409F0EC5A3DD945F90A78D7C7ACB8DC04E47568E
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.69.194/kitty.armv7l80e712507f9e79bfe2b455dc77350d5e4036946a0417225f6f4f3a2ff940d078 Miraielf mirai ua-wget
http://196.251.69.194/kitty.armv6lc1ea896950b50eb46534a8a3aba9c0b6ac50483717822a8bae8eb439b576e94c Miraielf mirai ua-wget
http://196.251.69.194/kitty.armv5l955ff456db1482947fcaa4a2ca57a372e0ea3ab9e92a2c6c34c1a97b85269b50 Miraielf geofenced mirai ua-wget UK
http://196.251.69.194/kitty.mipsn/an/aelf mirai ua-wget
http://196.251.69.194/kitty.mipselcb93ba4bdeca9b98b820e6a54f5ce7259c6dea673d8ee2b92e88d39f70efb8ea Miraielf mirai ua-wget
http://196.251.69.194/kitty.aarch641a930b4aa7c5f6e140466a8309037bf5def5614f7ed514bd9010868b8f51710b Tsunamielf mirai Tsunami ua-wget
http://196.251.69.194/kitty.i6861856f5b82ce74dec870cdc0532a1aafcbb952a73f73268283fee5829ca0843a4 Miraielf mirai ua-wget
http://196.251.69.194/kitty.i486dff8915b9e3eaddfd2383c1b061ab2a0a0272d351a7d9bb8147a2b62b9ed3048 Miraielf geofenced mirai ua-wget UK
http://196.251.69.194/kitty.x86_64n/an/aelf mirai ua-wget
http://196.251.69.194/kitty.powerpc30fcafea6ab423a85ade81a48e89cd23e195ed24c746ed908b68d897b2c88dbc Miraielf mirai ua-wget
http://196.251.69.194/kitty.powerpc641fa67e0be9dac19cd3a37a238f58eb1c0d160352d874bbfc423db7444c5b5ccb Miraielf mirai ua-wget
http://196.251.69.194/kitty.m68kbaf58c8b685e602fc75a3591005d3f9f2bfc5ea0ccce6bf54e542a29fe5cd048 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=942c7368-1800-0000-f959-cc8c7b090000 pid=2427 /usr/bin/sudo guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437 /tmp/sample.bin guuid=942c7368-1800-0000-f959-cc8c7b090000 pid=2427->guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437 execve guuid=e009376c-1800-0000-f959-cc8c87090000 pid=2439 /usr/bin/wget net send-data write-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=e009376c-1800-0000-f959-cc8c87090000 pid=2439 execve guuid=d4c7b97c-1800-0000-f959-cc8ca7090000 pid=2471 /usr/bin/chmod guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=d4c7b97c-1800-0000-f959-cc8ca7090000 pid=2471 execve guuid=8732057d-1800-0000-f959-cc8ca9090000 pid=2473 /usr/bin/dash guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=8732057d-1800-0000-f959-cc8ca9090000 pid=2473 clone guuid=6479c87d-1800-0000-f959-cc8cae090000 pid=2478 /usr/bin/rm delete-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=6479c87d-1800-0000-f959-cc8cae090000 pid=2478 execve guuid=0544557e-1800-0000-f959-cc8cb0090000 pid=2480 /usr/bin/wget net send-data write-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=0544557e-1800-0000-f959-cc8cb0090000 pid=2480 execve guuid=02cd95b1-1800-0000-f959-cc8ce2090000 pid=2530 /usr/bin/chmod guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=02cd95b1-1800-0000-f959-cc8ce2090000 pid=2530 execve guuid=eba4fab1-1800-0000-f959-cc8ce3090000 pid=2531 /usr/bin/dash guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=eba4fab1-1800-0000-f959-cc8ce3090000 pid=2531 clone guuid=2631b6b2-1800-0000-f959-cc8ce6090000 pid=2534 /usr/bin/rm delete-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=2631b6b2-1800-0000-f959-cc8ce6090000 pid=2534 execve guuid=9cf905b3-1800-0000-f959-cc8ce7090000 pid=2535 /usr/bin/wget net send-data write-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=9cf905b3-1800-0000-f959-cc8ce7090000 pid=2535 execve guuid=39b804c1-1800-0000-f959-cc8cf2090000 pid=2546 /usr/bin/chmod guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=39b804c1-1800-0000-f959-cc8cf2090000 pid=2546 execve guuid=2b0266c1-1800-0000-f959-cc8cf3090000 pid=2547 /usr/bin/dash guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=2b0266c1-1800-0000-f959-cc8cf3090000 pid=2547 clone guuid=e56526c3-1800-0000-f959-cc8cf7090000 pid=2551 /usr/bin/rm delete-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=e56526c3-1800-0000-f959-cc8cf7090000 pid=2551 execve guuid=330cbcc3-1800-0000-f959-cc8cf9090000 pid=2553 /usr/bin/wget net send-data write-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=330cbcc3-1800-0000-f959-cc8cf9090000 pid=2553 execve guuid=d8b95f1c-1900-0000-f959-cc8ccc0a0000 pid=2764 /usr/bin/chmod guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=d8b95f1c-1900-0000-f959-cc8ccc0a0000 pid=2764 execve guuid=fd7fa31c-1900-0000-f959-cc8cce0a0000 pid=2766 /usr/bin/dash guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=fd7fa31c-1900-0000-f959-cc8cce0a0000 pid=2766 clone guuid=027c221d-1900-0000-f959-cc8cd10a0000 pid=2769 /usr/bin/rm delete-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=027c221d-1900-0000-f959-cc8cd10a0000 pid=2769 execve guuid=b106681d-1900-0000-f959-cc8cd20a0000 pid=2770 /usr/bin/wget net send-data write-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=b106681d-1900-0000-f959-cc8cd20a0000 pid=2770 execve guuid=0f43cd27-1900-0000-f959-cc8cdb0a0000 pid=2779 /usr/bin/chmod guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=0f43cd27-1900-0000-f959-cc8cdb0a0000 pid=2779 execve guuid=d8f11c28-1900-0000-f959-cc8cdd0a0000 pid=2781 /usr/bin/dash guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=d8f11c28-1900-0000-f959-cc8cdd0a0000 pid=2781 clone guuid=d5f0bd28-1900-0000-f959-cc8ce00a0000 pid=2784 /usr/bin/rm delete-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=d5f0bd28-1900-0000-f959-cc8ce00a0000 pid=2784 execve guuid=acd0f928-1900-0000-f959-cc8ce20a0000 pid=2786 /usr/bin/wget net send-data write-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=acd0f928-1900-0000-f959-cc8ce20a0000 pid=2786 execve guuid=b750193d-1900-0000-f959-cc8cfe0a0000 pid=2814 /usr/bin/chmod guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=b750193d-1900-0000-f959-cc8cfe0a0000 pid=2814 execve guuid=8dc0593d-1900-0000-f959-cc8c000b0000 pid=2816 /usr/bin/dash guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=8dc0593d-1900-0000-f959-cc8c000b0000 pid=2816 clone guuid=1e27ec3d-1900-0000-f959-cc8c040b0000 pid=2820 /usr/bin/rm delete-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=1e27ec3d-1900-0000-f959-cc8c040b0000 pid=2820 execve guuid=c4fa423e-1900-0000-f959-cc8c060b0000 pid=2822 /usr/bin/wget net send-data write-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=c4fa423e-1900-0000-f959-cc8c060b0000 pid=2822 execve guuid=c27a9c49-1900-0000-f959-cc8c110b0000 pid=2833 /usr/bin/chmod guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=c27a9c49-1900-0000-f959-cc8c110b0000 pid=2833 execve guuid=ac5ae449-1900-0000-f959-cc8c120b0000 pid=2834 /tmp/kitty.i686 guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=ac5ae449-1900-0000-f959-cc8c120b0000 pid=2834 execve guuid=27d2fe49-1900-0000-f959-cc8c140b0000 pid=2836 /usr/bin/rm guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=27d2fe49-1900-0000-f959-cc8c140b0000 pid=2836 execve guuid=9d416a4a-1900-0000-f959-cc8c170b0000 pid=2839 /usr/bin/wget guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=9d416a4a-1900-0000-f959-cc8c170b0000 pid=2839 execve guuid=49389c4a-1900-0000-f959-cc8c190b0000 pid=2841 /usr/bin/chmod guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=49389c4a-1900-0000-f959-cc8c190b0000 pid=2841 execve guuid=77e0424b-1900-0000-f959-cc8c1c0b0000 pid=2844 /usr/bin/dash guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=77e0424b-1900-0000-f959-cc8c1c0b0000 pid=2844 clone guuid=fed14e4b-1900-0000-f959-cc8c1d0b0000 pid=2845 /usr/bin/rm guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=fed14e4b-1900-0000-f959-cc8c1d0b0000 pid=2845 execve guuid=874a8d4b-1900-0000-f959-cc8c1e0b0000 pid=2846 /usr/bin/wget guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=874a8d4b-1900-0000-f959-cc8c1e0b0000 pid=2846 execve guuid=83b5ac4b-1900-0000-f959-cc8c200b0000 pid=2848 /usr/bin/chmod guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=83b5ac4b-1900-0000-f959-cc8c200b0000 pid=2848 execve guuid=11f3da4b-1900-0000-f959-cc8c220b0000 pid=2850 /usr/bin/dash guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=11f3da4b-1900-0000-f959-cc8c220b0000 pid=2850 clone guuid=697ae94b-1900-0000-f959-cc8c230b0000 pid=2851 /usr/bin/rm guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=697ae94b-1900-0000-f959-cc8c230b0000 pid=2851 execve guuid=5218354c-1900-0000-f959-cc8c250b0000 pid=2853 /usr/bin/wget guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=5218354c-1900-0000-f959-cc8c250b0000 pid=2853 execve guuid=525b5e4c-1900-0000-f959-cc8c260b0000 pid=2854 /usr/bin/chmod guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=525b5e4c-1900-0000-f959-cc8c260b0000 pid=2854 execve guuid=fead974c-1900-0000-f959-cc8c280b0000 pid=2856 /usr/bin/dash guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=fead974c-1900-0000-f959-cc8c280b0000 pid=2856 clone guuid=eda2a14c-1900-0000-f959-cc8c290b0000 pid=2857 /usr/bin/rm guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=eda2a14c-1900-0000-f959-cc8c290b0000 pid=2857 execve guuid=2751df4c-1900-0000-f959-cc8c2a0b0000 pid=2858 /usr/bin/wget net send-data write-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=2751df4c-1900-0000-f959-cc8c2a0b0000 pid=2858 execve guuid=135b6f54-1900-0000-f959-cc8c350b0000 pid=2869 /usr/bin/chmod guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=135b6f54-1900-0000-f959-cc8c350b0000 pid=2869 execve guuid=c488cd54-1900-0000-f959-cc8c360b0000 pid=2870 /usr/bin/dash guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=c488cd54-1900-0000-f959-cc8c360b0000 pid=2870 clone guuid=3c5f7b55-1900-0000-f959-cc8c3a0b0000 pid=2874 /usr/bin/rm delete-file guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=3c5f7b55-1900-0000-f959-cc8c3a0b0000 pid=2874 execve guuid=7046d455-1900-0000-f959-cc8c3c0b0000 pid=2876 /usr/bin/wget guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=7046d455-1900-0000-f959-cc8c3c0b0000 pid=2876 execve guuid=18ca0e56-1900-0000-f959-cc8c3d0b0000 pid=2877 /usr/bin/chmod guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=18ca0e56-1900-0000-f959-cc8c3d0b0000 pid=2877 execve guuid=a0106956-1900-0000-f959-cc8c3f0b0000 pid=2879 /usr/bin/dash guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=a0106956-1900-0000-f959-cc8c3f0b0000 pid=2879 clone guuid=0f5f7456-1900-0000-f959-cc8c400b0000 pid=2880 /usr/bin/rm guuid=ad0ed86b-1800-0000-f959-cc8c85090000 pid=2437->guuid=0f5f7456-1900-0000-f959-cc8c400b0000 pid=2880 execve 2e1ba108-bb79-560a-bab6-417767220e51 196.251.69.194:80 guuid=e009376c-1800-0000-f959-cc8c87090000 pid=2439->2e1ba108-bb79-560a-bab6-417767220e51 send: 141B guuid=0544557e-1800-0000-f959-cc8cb0090000 pid=2480->2e1ba108-bb79-560a-bab6-417767220e51 send: 141B guuid=9cf905b3-1800-0000-f959-cc8ce7090000 pid=2535->2e1ba108-bb79-560a-bab6-417767220e51 send: 141B guuid=330cbcc3-1800-0000-f959-cc8cf9090000 pid=2553->2e1ba108-bb79-560a-bab6-417767220e51 send: 139B guuid=b106681d-1900-0000-f959-cc8cd20a0000 pid=2770->2e1ba108-bb79-560a-bab6-417767220e51 send: 141B guuid=acd0f928-1900-0000-f959-cc8ce20a0000 pid=2786->2e1ba108-bb79-560a-bab6-417767220e51 send: 142B guuid=c4fa423e-1900-0000-f959-cc8c060b0000 pid=2822->2e1ba108-bb79-560a-bab6-417767220e51 send: 139B guuid=9237f849-1900-0000-f959-cc8c130b0000 pid=2835 /tmp/kitty.i686 guuid=ac5ae449-1900-0000-f959-cc8c120b0000 pid=2834->guuid=9237f849-1900-0000-f959-cc8c130b0000 pid=2835 clone guuid=49fe0a4a-1900-0000-f959-cc8c150b0000 pid=2837 /tmp/kitty.i686 delete-file net send-data zombie guuid=9237f849-1900-0000-f959-cc8c130b0000 pid=2835->guuid=49fe0a4a-1900-0000-f959-cc8c150b0000 pid=2837 clone eb9dca7b-d301-522e-83c7-8d6f291efc38 66.78.40.221:9080 guuid=49fe0a4a-1900-0000-f959-cc8c150b0000 pid=2837->eb9dca7b-d301-522e-83c7-8d6f291efc38 send: 70B ac570862-0b5b-558b-b43c-fb15134a62c4 114.114.114.114:53 guuid=49fe0a4a-1900-0000-f959-cc8c150b0000 pid=2837->ac570862-0b5b-558b-b43c-fb15134a62c4 send: 40B b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=49fe0a4a-1900-0000-f959-cc8c150b0000 pid=2837->b4bf20d4-f7c8-5c24-8830-c23364537aa4 send: 40B guuid=49fe0a4a-1900-0000-f959-cc8c150b0000 pid=2838 /tmp/kitty.i686 zombie guuid=49fe0a4a-1900-0000-f959-cc8c150b0000 pid=2837->guuid=49fe0a4a-1900-0000-f959-cc8c150b0000 pid=2838 clone guuid=2751df4c-1900-0000-f959-cc8c2a0b0000 pid=2858->2e1ba108-bb79-560a-bab6-417767220e51 send: 144B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2025-08-18 09:55:48 UTC
File Type:
Text (Shell)
AV detection:
18 of 38 (47.37%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 3e47b3a535f5dca6b395e09cba27452e33e56b2c827eada547c59f8eda9cbe47

(this sample)

  
Delivery method
Distributed via web download

Comments