MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 42f1363b224766f655f7ef1e7f37de1c8a33ac172a2ebcbfd401cab88643d12c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 42f1363b224766f655f7ef1e7f37de1c8a33ac172a2ebcbfd401cab88643d12c
SHA3-384 hash: f0b486e084560f70d00b32aa468f92f896cd67a43127df5912577b9de37ee812de4fd26d0915f9122389962224bcac2a
SHA1 hash: cfa797ef62eb83ed013bf1e1e3f02984ebb651af
MD5 hash: 84fe7284dc5276fe00c3b1c3cc66d6f7
humanhash: football-tango-angel-november
File name:b.sh
Download: download sample
Signature Mirai
File size:640 bytes
First seen:2026-08-19 16:35:22 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:l4k7JIuWvGSqxSZo0nO8WT01kuzVfzi6ssb/AFRENlMfx4CJFrFWZ9uOG0Lmz:lX7OuWvGzxmHDC07zVfzx/0MlMfx4CHV
TLSH T12EF07D137C83F033D18BD6B4EF1BF588A49324BBC424D814766D8566EF7A8697881241
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter skocherhan
Tags:sh wer-ldr-duckdns-org wereng-duckdns-org

Intelligence


File Origin
# of uploads :
1
# of downloads :
48
Origin country :
GB GB
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
downloader
Status:
terminated
Behavior Graph:
%3 guuid=bc205b42-1a00-0000-10dd-50ff300c0000 pid=3120 /usr/bin/sudo guuid=f8cfdc44-1a00-0000-10dd-50ff350c0000 pid=3125 /tmp/sample.bin guuid=bc205b42-1a00-0000-10dd-50ff300c0000 pid=3120->guuid=f8cfdc44-1a00-0000-10dd-50ff350c0000 pid=3125 execve guuid=ff851e45-1a00-0000-10dd-50ff370c0000 pid=3127 /usr/bin/uname guuid=f8cfdc44-1a00-0000-10dd-50ff350c0000 pid=3125->guuid=ff851e45-1a00-0000-10dd-50ff370c0000 pid=3127 execve guuid=9f169845-1a00-0000-10dd-50ff3a0c0000 pid=3130 /usr/bin/wget dns net send-data write-file guuid=f8cfdc44-1a00-0000-10dd-50ff350c0000 pid=3125->guuid=9f169845-1a00-0000-10dd-50ff3a0c0000 pid=3130 execve guuid=2a01be7a-1a00-0000-10dd-50ff980c0000 pid=3224 /usr/bin/chmod guuid=f8cfdc44-1a00-0000-10dd-50ff350c0000 pid=3125->guuid=2a01be7a-1a00-0000-10dd-50ff980c0000 pid=3224 execve guuid=67dd077b-1a00-0000-10dd-50ff9a0c0000 pid=3226 /tmp/.b delete-file net zombie guuid=f8cfdc44-1a00-0000-10dd-50ff350c0000 pid=3125->guuid=67dd077b-1a00-0000-10dd-50ff9a0c0000 pid=3226 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=9f169845-1a00-0000-10dd-50ff3a0c0000 pid=3130->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 74B 9445d95e-13f6-5fd7-92e4-18f2b1d81c02 wer-ldr.duckdns.org:80 guuid=9f169845-1a00-0000-10dd-50ff3a0c0000 pid=3130->9445d95e-13f6-5fd7-92e4-18f2b1d81c02 send: 149B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=67dd077b-1a00-0000-10dd-50ff9a0c0000 pid=3226->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm command_and_control defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Modifies init.d
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Outbound SSH connection to public host
Traces itself
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Mirai

sh 42f1363b224766f655f7ef1e7f37de1c8a33ac172a2ebcbfd401cab88643d12c

(this sample)

Comments