MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46a36628dc6cc3fcdf22a8b4a9e464694dde769942bd0511fa5ac67aac6b4040. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 46a36628dc6cc3fcdf22a8b4a9e464694dde769942bd0511fa5ac67aac6b4040
SHA3-384 hash: 2cc9372c1b3d7ea921400d3bf0e0cdfbe5c43e39844b3ee5b7eebdb3ef947eff4f67b6df14411bd45ff1d951dcaa104c
SHA1 hash: ead6df0dc57174ab8fb63191f67a4a063a1e0680
MD5 hash: 22dab73fe1b6c229e4be6048b33b53a3
humanhash: ceiling-october-nebraska-tennessee
File name:faith.sh
Download: download sample
Signature Mirai
File size:2'417 bytes
First seen:2025-10-13 20:30:34 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ScFYA6Hk+hS5kmcwzHIzEprIzKlPNeFx4T9Dn49XcNAE6x4T6:ScFYrHkm8kmcwbIzEtIzYVeFx4T9U9X7
TLSH T1C741E4CF7522462A554F8E0BB3F6A4E87033C4DB20518B29FECD78A9F398C5A7044A35
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.125.66.56/arm1c6ad7da3701f41af453d1701d5656e256a6dcf08023270b2926685b82a19d07 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm5ff2d4387cb624cfb0eb01dfe59d09c8acc09eec41873016cc1590b6cffdd10c7 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm65e29e6ac19c524f249a4e5800d6458735f5d131a6d9d59ea37dc716f7215dc31 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm7b772d55640399dee9b277a0ffd7ef8f65bb87363dbfdd0634cb88328528f369d Mirai404 censys DEU elf geofenced mirai ua-wget
http://45.125.66.56/i486d1d4d3b6ffb937a022a8978c4d01811ab7c5ddd912e0e94c4cd7a025d73a3843 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/i6866509dcd8caa3035a09bbb926b0f93a63c80a76ecd9e8f5c6e74e0811fe3e200c MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/m68k7db99f0dd794e8e049d0d0d4fa86f3c2c3b95f2e9bc24e623ca11c1bcb02bf80 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/mips6d8b92be20e13565fd61d105c44acadca0a7dac38eca5bc5693c5867b84fe62f Miraiddos DEU elf geofenced mirai
http://45.125.66.56/mpsl3c2e72b972e03e620def95ca99d0af072db842dd0d016891fc30527770190a92 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/ppcfd07238570884beaa7f26c644408b18524fd2cc7c3b765ec24a0e9a36069d45a MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/sh4ac4a61edcb0c971f8f6b4b13f51e4105b4c838a344022091f1dcf351240a80b5 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/spc39fae3e0e9e2ba27ffa0eb62a244b16552abc21083dfceeb66dfc080c316696c MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/x86b137e7049facd81bf0e15a0bb6b0135732a43e126b799e903798f05ef87ca98e Miraiddos DEU elf gafgyt geofenced mirai
http://45.125.66.56/x86_64c39196e5ab865850c997492cc40ea9e9533ce1bcf915b255647f4ad82418be25 MiraiDEU elf geofenced mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=70f3e2fc-1d00-0000-7688-20ec140d0000 pid=3348 /usr/bin/sudo guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354 /tmp/sample.bin guuid=70f3e2fc-1d00-0000-7688-20ec140d0000 pid=3348->guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354 execve guuid=09dad0fe-1d00-0000-7688-20ec1c0d0000 pid=3356 /usr/bin/cp guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=09dad0fe-1d00-0000-7688-20ec1c0d0000 pid=3356 execve guuid=a1269005-1e00-0000-7688-20ec2b0d0000 pid=3371 /usr/bin/wget net guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=a1269005-1e00-0000-7688-20ec2b0d0000 pid=3371 execve guuid=32dd9ec3-1e00-0000-7688-20ecb40e0000 pid=3764 /usr/bin/curl net guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=32dd9ec3-1e00-0000-7688-20ecb40e0000 pid=3764 execve guuid=d813ae04-1f00-0000-7688-20ecad0f0000 pid=4013 /usr/bin/bash guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=d813ae04-1f00-0000-7688-20ecad0f0000 pid=4013 clone guuid=21afd804-1f00-0000-7688-20ecae0f0000 pid=4014 /usr/bin/chmod guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=21afd804-1f00-0000-7688-20ecae0f0000 pid=4014 execve guuid=d2ed4205-1f00-0000-7688-20ecb00f0000 pid=4016 /usr/bin/bash guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=d2ed4205-1f00-0000-7688-20ecb00f0000 pid=4016 clone guuid=0c166805-1f00-0000-7688-20ecb20f0000 pid=4018 /usr/bin/rm guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=0c166805-1f00-0000-7688-20ecb20f0000 pid=4018 execve guuid=31bdd805-1f00-0000-7688-20ecb40f0000 pid=4020 /usr/bin/wget net guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=31bdd805-1f00-0000-7688-20ecb40f0000 pid=4020 execve guuid=bd305a45-1f00-0000-7688-20ec60100000 pid=4192 /usr/bin/curl net guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=bd305a45-1f00-0000-7688-20ec60100000 pid=4192 execve guuid=5a8f73c9-2300-0000-7688-20ec97140000 pid=5271 /usr/bin/bash guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=5a8f73c9-2300-0000-7688-20ec97140000 pid=5271 clone guuid=e37cabc9-2300-0000-7688-20ec98140000 pid=5272 /usr/bin/chmod guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=e37cabc9-2300-0000-7688-20ec98140000 pid=5272 execve guuid=a9c244ca-2300-0000-7688-20ec99140000 pid=5273 /usr/bin/bash guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=a9c244ca-2300-0000-7688-20ec99140000 pid=5273 clone guuid=dbd17eca-2300-0000-7688-20ec9a140000 pid=5274 /usr/bin/rm guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=dbd17eca-2300-0000-7688-20ec9a140000 pid=5274 execve guuid=029404cb-2300-0000-7688-20ec9b140000 pid=5275 /usr/bin/wget net guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=029404cb-2300-0000-7688-20ec9b140000 pid=5275 execve guuid=5367f050-2800-0000-7688-20ec9c140000 pid=5276 /usr/bin/curl net guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=5367f050-2800-0000-7688-20ec9c140000 pid=5276 execve guuid=654dd991-2800-0000-7688-20ec9d140000 pid=5277 /usr/bin/bash guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=654dd991-2800-0000-7688-20ec9d140000 pid=5277 clone guuid=992df991-2800-0000-7688-20ec9e140000 pid=5278 /usr/bin/chmod guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=992df991-2800-0000-7688-20ec9e140000 pid=5278 execve guuid=10808692-2800-0000-7688-20ec9f140000 pid=5279 /usr/bin/bash guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=10808692-2800-0000-7688-20ec9f140000 pid=5279 clone guuid=2010a592-2800-0000-7688-20eca0140000 pid=5280 /usr/bin/rm guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=2010a592-2800-0000-7688-20eca0140000 pid=5280 execve guuid=de432793-2800-0000-7688-20eca1140000 pid=5281 /usr/bin/wget net guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=de432793-2800-0000-7688-20eca1140000 pid=5281 execve guuid=f01e87d2-2800-0000-7688-20eca2140000 pid=5282 /usr/bin/curl net guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=f01e87d2-2800-0000-7688-20eca2140000 pid=5282 execve guuid=fb39bf8d-2900-0000-7688-20eca3140000 pid=5283 /usr/bin/bash guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=fb39bf8d-2900-0000-7688-20eca3140000 pid=5283 clone guuid=4b9de38d-2900-0000-7688-20eca4140000 pid=5284 /usr/bin/chmod guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=4b9de38d-2900-0000-7688-20eca4140000 pid=5284 execve guuid=fe80598e-2900-0000-7688-20eca5140000 pid=5285 /usr/bin/bash guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=fe80598e-2900-0000-7688-20eca5140000 pid=5285 clone guuid=499f8f8e-2900-0000-7688-20eca6140000 pid=5286 /usr/bin/rm guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=499f8f8e-2900-0000-7688-20eca6140000 pid=5286 execve guuid=b4b20b8f-2900-0000-7688-20eca7140000 pid=5287 /usr/bin/wget net guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=b4b20b8f-2900-0000-7688-20eca7140000 pid=5287 execve guuid=289d200f-2a00-0000-7688-20eca8140000 pid=5288 /usr/bin/curl net guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=289d200f-2a00-0000-7688-20eca8140000 pid=5288 execve guuid=45212350-2a00-0000-7688-20eca9140000 pid=5289 /usr/bin/bash guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=45212350-2a00-0000-7688-20eca9140000 pid=5289 clone guuid=7c4a4550-2a00-0000-7688-20ecaa140000 pid=5290 /usr/bin/chmod guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=7c4a4550-2a00-0000-7688-20ecaa140000 pid=5290 execve guuid=266a9f50-2a00-0000-7688-20ecab140000 pid=5291 /usr/bin/bash guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=266a9f50-2a00-0000-7688-20ecab140000 pid=5291 clone guuid=0f31c850-2a00-0000-7688-20ecac140000 pid=5292 /usr/bin/rm guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=0f31c850-2a00-0000-7688-20ecac140000 pid=5292 execve guuid=4ea72251-2a00-0000-7688-20ecad140000 pid=5293 /usr/bin/wget net guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=4ea72251-2a00-0000-7688-20ecad140000 pid=5293 execve guuid=84d81b85-2b00-0000-7688-20ecae140000 pid=5294 /usr/bin/curl net guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=84d81b85-2b00-0000-7688-20ecae140000 pid=5294 execve guuid=4b3cf202-2c00-0000-7688-20ecb9140000 pid=5305 /usr/bin/bash guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=4b3cf202-2c00-0000-7688-20ecb9140000 pid=5305 clone guuid=d6d50a03-2c00-0000-7688-20ecba140000 pid=5306 /usr/bin/chmod guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=d6d50a03-2c00-0000-7688-20ecba140000 pid=5306 execve guuid=c3364d03-2c00-0000-7688-20ecbb140000 pid=5307 /usr/bin/bash guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=c3364d03-2c00-0000-7688-20ecbb140000 pid=5307 clone guuid=24536103-2c00-0000-7688-20ecbc140000 pid=5308 /usr/bin/rm guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=24536103-2c00-0000-7688-20ecbc140000 pid=5308 execve guuid=5697a503-2c00-0000-7688-20ecbd140000 pid=5309 /usr/bin/wget guuid=1c9386fe-1d00-0000-7688-20ec1a0d0000 pid=3354->guuid=5697a503-2c00-0000-7688-20ecbd140000 pid=5309 execve 28318de2-8d63-5b31-be23-c532c58983b9 45.125.66.56:80 guuid=a1269005-1e00-0000-7688-20ec2b0d0000 pid=3371->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=32dd9ec3-1e00-0000-7688-20ecb40e0000 pid=3764->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=31bdd805-1f00-0000-7688-20ecb40f0000 pid=4020->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=bd305a45-1f00-0000-7688-20ec60100000 pid=4192->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=029404cb-2300-0000-7688-20ec9b140000 pid=5275->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=5367f050-2800-0000-7688-20ec9c140000 pid=5276->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=de432793-2800-0000-7688-20eca1140000 pid=5281->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=f01e87d2-2800-0000-7688-20eca2140000 pid=5282->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=b4b20b8f-2900-0000-7688-20eca7140000 pid=5287->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=289d200f-2a00-0000-7688-20eca8140000 pid=5288->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=4ea72251-2a00-0000-7688-20ecad140000 pid=5293->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=84d81b85-2b00-0000-7688-20ecae140000 pid=5294->28318de2-8d63-5b31-be23-c532c58983b9 con
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-10-13 19:37:03 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 46a36628dc6cc3fcdf22a8b4a9e464694dde769942bd0511fa5ac67aac6b4040

(this sample)

  
Delivery method
Distributed via web download

Comments