MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 45b5e91f8a85f5ff1bdd5281f2ebc93d338f6dc82356000af4c5bbc20e1733ac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 45b5e91f8a85f5ff1bdd5281f2ebc93d338f6dc82356000af4c5bbc20e1733ac
SHA3-384 hash: 32d39eb3c26d0c06f4c2e7c277b93fe968a4e62ee56647a1e198b03be4d4c88ecb54916585c3ae3e0e5c20fdda227217
SHA1 hash: 41c85fd450d9be27421afd4529c0bc895e5ae645
MD5 hash: 9f595de31823c87cb9f56b9aef2928ac
humanhash: alaska-wisconsin-iowa-solar
File name:busybox.sh
Download: download sample
Signature Mirai
File size:1'175 bytes
First seen:2025-06-15 21:53:38 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:jcskGDcsl0DcsQGNIxy/DcszXKnDcsy4DcsP8DcsWADcsyyZDcsrQlDcsQKDcsd7:jdkGDdl0DdYwDdzXsDdy4DdP8DdWADdI
TLSH T16A213DFE005CF9044A4D9E59F1256E28BE48CAD470E58A8CF54DD4B2E2AEC28613CE0C
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.149.252.178/skibidi/cutearm1bc137841445a32184b981463f26cf92cd5faee96c6530b71788322f6e02b74c Miraielf mirai ua-wget
http://103.149.252.178/skibidi/cutearm531bd74459680c387a1eb10667a44b7691101778b2eee79dd9e33c27cf18af7eb Miraielf mirai ua-wget
http://103.149.252.178/skibidi/cutearm6e7ed00ebd7a3124bf74c3a1e5de27d55daeba1a6c6dd9b507a5c4435eb87e78c Miraielf mirai ua-wget
http://103.149.252.178/skibidi/cutearm7b2510b90cc924b8bde71cb86f3875a466de3a4dff19efa2cc4d93173f38a3381 Miraielf mirai ua-wget
http://103.149.252.178/skibidi/cutem68kfc1848906eb6cf539a5009dfa5cbd87b822287242ceb9e04e7bd6f747a1f0a6e Miraielf mirai ua-wget
http://103.149.252.178/skibidi/cutemips994d3872166fd7b39d2c05628c86417140f456637e811f9235792c5b667947dd Miraielf mirai ua-wget
http://103.149.252.178/skibidi/cutemipsel88fcbf23a8273804bfb89bd72ef93c0d3d5d899a239cde333396d34184d15293 Miraielf ua-wget
http://103.149.252.178/skibidi/cutepowerpcf9d2eec0a3481cac09af0aa96723e831d4a66af87e48347fde818281d62af70e Miraielf mirai ua-wget
http://103.149.252.178/skibidi/cutesh4245daaf02866c349c32028beeaec0c428a85ad4a0fe3df40449ad0cdd2942db6 Miraielf gafgyt mirai ua-wget
http://103.149.252.178/skibidi/cutex8672f6704fdb711d1ba20c96a7ef73e7ac2cd41943cc4bdd417cab03417be1eb55 Miraielf mirai ua-wget
http://103.149.252.178/skibidi/cutex86_64a6880d908d5fa479ce234db7beed1598d5c8e9304696d3af7dc8cfee07a55e7e Miraielf mirai ua-wget
http://103.149.252.178/skibidi/cutex86_32d2d4f746e5138d2ec2e13b2331be588a2c09b94df979cf30fb128797c5315a64 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=a44f7757-2100-0000-ec40-fdb8b60b0000 pid=2998 /usr/bin/sudo guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005 /tmp/sample.bin guuid=a44f7757-2100-0000-ec40-fdb8b60b0000 pid=2998->guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005 execve guuid=fb6c345a-2100-0000-ec40-fdb8be0b0000 pid=3006 /usr/bin/busybox net send-data write-file guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=fb6c345a-2100-0000-ec40-fdb8be0b0000 pid=3006 execve guuid=ac600590-2100-0000-ec40-fdb8500c0000 pid=3152 /usr/bin/chmod guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=ac600590-2100-0000-ec40-fdb8500c0000 pid=3152 execve guuid=ea424890-2100-0000-ec40-fdb8520c0000 pid=3154 /usr/bin/dash guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=ea424890-2100-0000-ec40-fdb8520c0000 pid=3154 clone guuid=70161c91-2100-0000-ec40-fdb8550c0000 pid=3157 /usr/bin/busybox net send-data write-file guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=70161c91-2100-0000-ec40-fdb8550c0000 pid=3157 execve guuid=0b5698c7-2100-0000-ec40-fdb88f0c0000 pid=3215 /usr/bin/chmod guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=0b5698c7-2100-0000-ec40-fdb88f0c0000 pid=3215 execve guuid=5a064ec8-2100-0000-ec40-fdb8900c0000 pid=3216 /usr/bin/dash guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=5a064ec8-2100-0000-ec40-fdb8900c0000 pid=3216 clone guuid=399c30c9-2100-0000-ec40-fdb8920c0000 pid=3218 /usr/bin/busybox net send-data guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=399c30c9-2100-0000-ec40-fdb8920c0000 pid=3218 execve guuid=8ee1dce5-2100-0000-ec40-fdb8ba0c0000 pid=3258 /usr/bin/chmod guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=8ee1dce5-2100-0000-ec40-fdb8ba0c0000 pid=3258 execve guuid=48e32ee6-2100-0000-ec40-fdb8bc0c0000 pid=3260 /usr/bin/dash guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=48e32ee6-2100-0000-ec40-fdb8bc0c0000 pid=3260 clone guuid=934639e6-2100-0000-ec40-fdb8bd0c0000 pid=3261 /usr/bin/busybox net send-data write-file guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=934639e6-2100-0000-ec40-fdb8bd0c0000 pid=3261 execve guuid=6624b51d-2200-0000-ec40-fdb81a0d0000 pid=3354 /usr/bin/chmod guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=6624b51d-2200-0000-ec40-fdb81a0d0000 pid=3354 execve guuid=ade4f11d-2200-0000-ec40-fdb81c0d0000 pid=3356 /usr/bin/dash guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=ade4f11d-2200-0000-ec40-fdb81c0d0000 pid=3356 clone guuid=add6761e-2200-0000-ec40-fdb8200d0000 pid=3360 /usr/bin/busybox net send-data write-file guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=add6761e-2200-0000-ec40-fdb8200d0000 pid=3360 execve guuid=3765e454-2200-0000-ec40-fdb8ae0d0000 pid=3502 /usr/bin/chmod guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=3765e454-2200-0000-ec40-fdb8ae0d0000 pid=3502 execve guuid=bc044055-2200-0000-ec40-fdb8af0d0000 pid=3503 /usr/bin/dash guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=bc044055-2200-0000-ec40-fdb8af0d0000 pid=3503 clone guuid=6e912f56-2200-0000-ec40-fdb8b10d0000 pid=3505 /usr/bin/busybox net send-data write-file guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=6e912f56-2200-0000-ec40-fdb8b10d0000 pid=3505 execve guuid=c6a6f68d-2200-0000-ec40-fdb8f90d0000 pid=3577 /usr/bin/chmod guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=c6a6f68d-2200-0000-ec40-fdb8f90d0000 pid=3577 execve guuid=e02b7c8e-2200-0000-ec40-fdb8fa0d0000 pid=3578 /usr/bin/dash guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=e02b7c8e-2200-0000-ec40-fdb8fa0d0000 pid=3578 clone guuid=d3ef6090-2200-0000-ec40-fdb8fe0d0000 pid=3582 /usr/bin/busybox net send-data write-file guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=d3ef6090-2200-0000-ec40-fdb8fe0d0000 pid=3582 execve guuid=3c304ec7-2200-0000-ec40-fdb86d0e0000 pid=3693 /usr/bin/chmod guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=3c304ec7-2200-0000-ec40-fdb86d0e0000 pid=3693 execve guuid=651f99c7-2200-0000-ec40-fdb86e0e0000 pid=3694 /usr/bin/dash guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=651f99c7-2200-0000-ec40-fdb86e0e0000 pid=3694 clone guuid=4c55dec8-2200-0000-ec40-fdb8700e0000 pid=3696 /usr/bin/busybox net send-data write-file guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=4c55dec8-2200-0000-ec40-fdb8700e0000 pid=3696 execve guuid=525f34ff-2200-0000-ec40-fdb8280f0000 pid=3880 /usr/bin/chmod guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=525f34ff-2200-0000-ec40-fdb8280f0000 pid=3880 execve guuid=05413500-2300-0000-ec40-fdb82b0f0000 pid=3883 /usr/bin/dash guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=05413500-2300-0000-ec40-fdb82b0f0000 pid=3883 clone guuid=37e3df01-2300-0000-ec40-fdb8310f0000 pid=3889 /usr/bin/busybox net send-data write-file guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=37e3df01-2300-0000-ec40-fdb8310f0000 pid=3889 execve guuid=5a1d562c-2300-0000-ec40-fdb8b50f0000 pid=4021 /usr/bin/chmod guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=5a1d562c-2300-0000-ec40-fdb8b50f0000 pid=4021 execve guuid=f708a02c-2300-0000-ec40-fdb8b90f0000 pid=4025 /usr/bin/dash guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=f708a02c-2300-0000-ec40-fdb8b90f0000 pid=4025 clone guuid=57452d2d-2300-0000-ec40-fdb8bc0f0000 pid=4028 /usr/bin/busybox net send-data guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=57452d2d-2300-0000-ec40-fdb8bc0f0000 pid=4028 execve guuid=3ab3244b-2300-0000-ec40-fdb830100000 pid=4144 /usr/bin/chmod guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=3ab3244b-2300-0000-ec40-fdb830100000 pid=4144 execve guuid=b8cb784b-2300-0000-ec40-fdb831100000 pid=4145 /usr/bin/dash guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=b8cb784b-2300-0000-ec40-fdb831100000 pid=4145 clone guuid=f836814b-2300-0000-ec40-fdb832100000 pid=4146 /usr/bin/busybox net send-data write-file guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=f836814b-2300-0000-ec40-fdb832100000 pid=4146 execve guuid=fb69ac81-2300-0000-ec40-fdb811110000 pid=4369 /usr/bin/chmod guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=fb69ac81-2300-0000-ec40-fdb811110000 pid=4369 execve guuid=5533ed81-2300-0000-ec40-fdb812110000 pid=4370 /home/sandbox/cutex86_64 net guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=5533ed81-2300-0000-ec40-fdb812110000 pid=4370 execve guuid=e2a40882-2300-0000-ec40-fdb815110000 pid=4373 /usr/bin/busybox net send-data write-file guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=e2a40882-2300-0000-ec40-fdb815110000 pid=4373 execve guuid=d0fca8ae-2300-0000-ec40-fdb8b7110000 pid=4535 /usr/bin/chmod guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=d0fca8ae-2300-0000-ec40-fdb8b7110000 pid=4535 execve guuid=60f1ffae-2300-0000-ec40-fdb8b8110000 pid=4536 /home/sandbox/cutex86_32 net guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=60f1ffae-2300-0000-ec40-fdb8b8110000 pid=4536 execve guuid=9b0f3daf-2300-0000-ec40-fdb8bb110000 pid=4539 /usr/bin/rm delete-file guuid=026af159-2100-0000-ec40-fdb8bd0b0000 pid=3005->guuid=9b0f3daf-2300-0000-ec40-fdb8bb110000 pid=4539 execve b95ce511-3591-5114-995b-9ce77bb440cb 103.149.252.178:80 guuid=fb6c345a-2100-0000-ec40-fdb8be0b0000 pid=3006->b95ce511-3591-5114-995b-9ce77bb440cb send: 93B guuid=70161c91-2100-0000-ec40-fdb8550c0000 pid=3157->b95ce511-3591-5114-995b-9ce77bb440cb send: 94B guuid=399c30c9-2100-0000-ec40-fdb8920c0000 pid=3218->b95ce511-3591-5114-995b-9ce77bb440cb send: 94B guuid=934639e6-2100-0000-ec40-fdb8bd0c0000 pid=3261->b95ce511-3591-5114-995b-9ce77bb440cb send: 94B guuid=add6761e-2200-0000-ec40-fdb8200d0000 pid=3360->b95ce511-3591-5114-995b-9ce77bb440cb send: 94B guuid=6e912f56-2200-0000-ec40-fdb8b10d0000 pid=3505->b95ce511-3591-5114-995b-9ce77bb440cb send: 94B guuid=d3ef6090-2200-0000-ec40-fdb8fe0d0000 pid=3582->b95ce511-3591-5114-995b-9ce77bb440cb send: 96B guuid=4c55dec8-2200-0000-ec40-fdb8700e0000 pid=3696->b95ce511-3591-5114-995b-9ce77bb440cb send: 97B guuid=37e3df01-2300-0000-ec40-fdb8310f0000 pid=3889->b95ce511-3591-5114-995b-9ce77bb440cb send: 93B guuid=57452d2d-2300-0000-ec40-fdb8bc0f0000 pid=4028->b95ce511-3591-5114-995b-9ce77bb440cb send: 93B guuid=f836814b-2300-0000-ec40-fdb832100000 pid=4146->b95ce511-3591-5114-995b-9ce77bb440cb send: 96B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=5533ed81-2300-0000-ec40-fdb812110000 pid=4370->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e5150382-2300-0000-ec40-fdb814110000 pid=4372 /home/sandbox/cutex86_64 zombie guuid=5533ed81-2300-0000-ec40-fdb812110000 pid=4370->guuid=e5150382-2300-0000-ec40-fdb814110000 pid=4372 clone guuid=789f0a82-2300-0000-ec40-fdb816110000 pid=4374 /home/sandbox/cutex86_64 net send-data zombie guuid=e5150382-2300-0000-ec40-fdb814110000 pid=4372->guuid=789f0a82-2300-0000-ec40-fdb816110000 pid=4374 clone guuid=e2a40882-2300-0000-ec40-fdb815110000 pid=4373->b95ce511-3591-5114-995b-9ce77bb440cb send: 96B fbf34c2e-28ca-512d-9b01-9151dfcb2221 103.149.252.178:5683 guuid=789f0a82-2300-0000-ec40-fdb816110000 pid=4374->fbf34c2e-28ca-512d-9b01-9151dfcb2221 send: 3198B guuid=dec31182-2300-0000-ec40-fdb817110000 pid=4375 /usr/bin/dash guuid=789f0a82-2300-0000-ec40-fdb816110000 pid=4374->guuid=dec31182-2300-0000-ec40-fdb817110000 pid=4375 execve guuid=f08dd582-2300-0000-ec40-fdb81d110000 pid=4381 /usr/bin/dash guuid=789f0a82-2300-0000-ec40-fdb816110000 pid=4374->guuid=f08dd582-2300-0000-ec40-fdb81d110000 pid=4381 execve guuid=0f574c82-2300-0000-ec40-fdb818110000 pid=4376 /usr/bin/mkdir guuid=dec31182-2300-0000-ec40-fdb817110000 pid=4375->guuid=0f574c82-2300-0000-ec40-fdb818110000 pid=4376 execve guuid=92f50283-2300-0000-ec40-fdb81e110000 pid=4382 /usr/bin/mv guuid=f08dd582-2300-0000-ec40-fdb81d110000 pid=4381->guuid=92f50283-2300-0000-ec40-fdb81e110000 pid=4382 execve guuid=60027983-2300-0000-ec40-fdb822110000 pid=4386 /usr/bin/chmod guuid=f08dd582-2300-0000-ec40-fdb81d110000 pid=4381->guuid=60027983-2300-0000-ec40-fdb822110000 pid=4386 execve guuid=60f1ffae-2300-0000-ec40-fdb8b8110000 pid=4536->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6a712daf-2300-0000-ec40-fdb8b9110000 pid=4537 /home/sandbox/cutex86_32 guuid=60f1ffae-2300-0000-ec40-fdb8b8110000 pid=4536->guuid=6a712daf-2300-0000-ec40-fdb8b9110000 pid=4537 clone guuid=ef2639af-2300-0000-ec40-fdb8ba110000 pid=4538 /home/sandbox/cutex86_32 net zombie guuid=6a712daf-2300-0000-ec40-fdb8b9110000 pid=4537->guuid=ef2639af-2300-0000-ec40-fdb8ba110000 pid=4538 clone guuid=ef2639af-2300-0000-ec40-fdb8ba110000 pid=4538->fbf34c2e-28ca-512d-9b01-9151dfcb2221 con guuid=1db258af-2300-0000-ec40-fdb8bc110000 pid=4540 /usr/bin/dash guuid=ef2639af-2300-0000-ec40-fdb8ba110000 pid=4538->guuid=1db258af-2300-0000-ec40-fdb8bc110000 pid=4540 execve guuid=ac683cb0-2300-0000-ec40-fdb8be110000 pid=4542 /usr/bin/dash guuid=ef2639af-2300-0000-ec40-fdb8ba110000 pid=4538->guuid=ac683cb0-2300-0000-ec40-fdb8be110000 pid=4542 execve guuid=44349daf-2300-0000-ec40-fdb8bd110000 pid=4541 /usr/bin/mkdir guuid=1db258af-2300-0000-ec40-fdb8bc110000 pid=4540->guuid=44349daf-2300-0000-ec40-fdb8bd110000 pid=4541 execve guuid=abf579b0-2300-0000-ec40-fdb8bf110000 pid=4543 /usr/bin/mv guuid=ac683cb0-2300-0000-ec40-fdb8be110000 pid=4542->guuid=abf579b0-2300-0000-ec40-fdb8bf110000 pid=4543 execve guuid=7c369de4-2300-0000-ec40-fdb8c0110000 pid=4544 /usr/bin/chmod guuid=ac683cb0-2300-0000-ec40-fdb8be110000 pid=4542->guuid=7c369de4-2300-0000-ec40-fdb8c0110000 pid=4544 execve
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-06-15 21:27:14 UTC
File Type:
Text (Shell)
AV detection:
15 of 37 (40.54%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 45b5e91f8a85f5ff1bdd5281f2ebc93d338f6dc82356000af4c5bbc20e1733ac

(this sample)

  
Delivery method
Distributed via web download

Comments