MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 489e2e274923863955068bf07d9050ef9da2fc70918cd64a1b2380ef28dbfa22. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 489e2e274923863955068bf07d9050ef9da2fc70918cd64a1b2380ef28dbfa22
SHA3-384 hash: d7c00ee2aa4e91c3984c08ce6818505e9d28673430aea71b5ae3a4873f29a688e993f09bb33de60b0ff1a8a0744f16e1
SHA1 hash: 6ebf68b96d3e9ca79d06388b496552d1bc15daf1
MD5 hash: 4cafe7b810f4bc18a3bdfb7a9fbd0852
humanhash: artist-lion-delta-london
File name:wget.sh
Download: download sample
Signature Mirai
File size:1'026 bytes
First seen:2025-10-25 13:48:17 UTC
Last seen:2025-10-25 23:18:22 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:ywQwJlPhKYhA+lk19NIl5d1Ca0LKNMNgOFx4JMJ6O7tjQ/SOZ7eNt2KJlf2G9kCo:EwPgalsNI76KjIGK5MlsNtVnO0vf8jn
TLSH T15E11E4DF35911FF28E4C9F0CFE7114665406B3D4F9130E745583187A8DE6788BA28E96
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.156.152.237/bins/arm8dc7ed0c0eb3a98210823b48a59180a41c881cdba6570d76bb542cc2f0cd7fb9 Miraiarm elf geofenced mirai opendir ua-wget USA
http://94.156.152.237/bins/arm5fd60d6b5596fac5d5e86b209a594861131202d04b43cc8d70e71f07465b381b3 Miraiarm elf geofenced mirai opendir ua-wget USA
http://94.156.152.237/bins/arm69a761ce53d6e9a4c2cdd70fe66abbc6dfc87d79334f09d289b25d5515ddafe26 Miraiarm elf geofenced mirai opendir ua-wget USA
http://94.156.152.237/bins/arm7ac3bc92e6f0a7dd9c82a4e8e4d6145f086895b1717d7432fbd203471836374c4 Miraiarm elf geofenced mirai opendir ua-wget USA
http://94.156.152.237/bins/m68k06cee20c7375828a3819a0c5163fab524d61aea85f1b11a8a6a1651775353000 Miraielf geofenced m68k mirai opendir ua-wget USA
http://94.156.152.237/bins/mips1f619b2d63bf46e759181edafab3743171ac4fa54308451a6318f6a5424275fd Miraielf geofenced mips mirai opendir ua-wget USA
http://94.156.152.237/bins/mpsln/an/aelf ua-wget
http://94.156.152.237/bins/ppc467aba87dd511756b865bd480c1caa85a759fb625a582e0b3745daf2eb03842e Miraielf geofenced mirai opendir PowerPC ua-wget USA
http://94.156.152.237/bins/sh4bc2b9ff74cbe81585f1badb17d6555e23c214305a121b3f4ec02d249c632b8a5 Miraielf geofenced mirai opendir SuperH ua-wget USA
http://94.156.152.237/bins/spc01eb5884ecf3d7e9615a4694fe4c0477e444054c0941503d1ff467e8dd2f7ff8 Miraielf geofenced mirai opendir sparc ua-wget USA
http://94.156.152.237/bins/x86f7181a9e714a5d2858399b75ab327b17ec0c48c0d4809c49af7d6bfb99c237c8 Miraielf geofenced mirai opendir ua-wget USA x86
http://94.156.152.237/bins/x86_644cbb02a607e7e41985733d4ebcd9881da78c1d6ed68e6781c4dcaca0befa7470 Miraielf geofenced mirai opendir ua-wget USA x86

Intelligence


File Origin
# of uploads :
3
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-25T11:02:00Z UTC
Last seen:
2025-10-26T10:14:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=45d99052-1900-0000-2bb8-77e667140000 pid=5223 /usr/bin/sudo guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224 /tmp/sample.bin guuid=45d99052-1900-0000-2bb8-77e667140000 pid=5223->guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224 execve guuid=5d991655-1900-0000-2bb8-77e669140000 pid=5225 /usr/bin/wget net send-data write-file guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=5d991655-1900-0000-2bb8-77e669140000 pid=5225 execve guuid=ce57bf6c-1900-0000-2bb8-77e66a140000 pid=5226 /usr/bin/chmod guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=ce57bf6c-1900-0000-2bb8-77e66a140000 pid=5226 execve guuid=6e06116d-1900-0000-2bb8-77e66b140000 pid=5227 /usr/bin/bash guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=6e06116d-1900-0000-2bb8-77e66b140000 pid=5227 clone guuid=ccfebd6d-1900-0000-2bb8-77e66d140000 pid=5229 /usr/bin/wget net send-data write-file guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=ccfebd6d-1900-0000-2bb8-77e66d140000 pid=5229 execve guuid=120c04b7-1900-0000-2bb8-77e66e140000 pid=5230 /usr/bin/chmod guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=120c04b7-1900-0000-2bb8-77e66e140000 pid=5230 execve guuid=f4f7e8b7-1900-0000-2bb8-77e66f140000 pid=5231 /usr/bin/bash guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=f4f7e8b7-1900-0000-2bb8-77e66f140000 pid=5231 clone guuid=a7a526bb-1900-0000-2bb8-77e671140000 pid=5233 /usr/bin/wget net send-data write-file guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=a7a526bb-1900-0000-2bb8-77e671140000 pid=5233 execve guuid=a40631c8-1900-0000-2bb8-77e673140000 pid=5235 /usr/bin/chmod guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=a40631c8-1900-0000-2bb8-77e673140000 pid=5235 execve guuid=b39a9cc8-1900-0000-2bb8-77e674140000 pid=5236 /usr/bin/bash guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=b39a9cc8-1900-0000-2bb8-77e674140000 pid=5236 clone guuid=0eb492c9-1900-0000-2bb8-77e679140000 pid=5241 /usr/bin/wget net send-data write-file guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=0eb492c9-1900-0000-2bb8-77e679140000 pid=5241 execve guuid=1c7aeed3-1900-0000-2bb8-77e67d140000 pid=5245 /usr/bin/chmod guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=1c7aeed3-1900-0000-2bb8-77e67d140000 pid=5245 execve guuid=55a473d4-1900-0000-2bb8-77e67e140000 pid=5246 /usr/bin/bash guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=55a473d4-1900-0000-2bb8-77e67e140000 pid=5246 clone guuid=55ef19d6-1900-0000-2bb8-77e680140000 pid=5248 /usr/bin/wget net send-data write-file guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=55ef19d6-1900-0000-2bb8-77e680140000 pid=5248 execve guuid=ea3dc7e2-1900-0000-2bb8-77e681140000 pid=5249 /usr/bin/chmod guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=ea3dc7e2-1900-0000-2bb8-77e681140000 pid=5249 execve guuid=1096b9e3-1900-0000-2bb8-77e682140000 pid=5250 /usr/bin/bash guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=1096b9e3-1900-0000-2bb8-77e682140000 pid=5250 clone guuid=495b92e5-1900-0000-2bb8-77e684140000 pid=5252 /usr/bin/wget net send-data write-file guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=495b92e5-1900-0000-2bb8-77e684140000 pid=5252 execve guuid=5ae915f3-1900-0000-2bb8-77e685140000 pid=5253 /usr/bin/chmod guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=5ae915f3-1900-0000-2bb8-77e685140000 pid=5253 execve guuid=825835f4-1900-0000-2bb8-77e686140000 pid=5254 /usr/bin/bash guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=825835f4-1900-0000-2bb8-77e686140000 pid=5254 clone guuid=013306f5-1900-0000-2bb8-77e688140000 pid=5256 /usr/bin/wget net send-data guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=013306f5-1900-0000-2bb8-77e688140000 pid=5256 execve guuid=b49ffbfc-1900-0000-2bb8-77e689140000 pid=5257 /usr/bin/chmod guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=b49ffbfc-1900-0000-2bb8-77e689140000 pid=5257 execve guuid=4e600dfe-1900-0000-2bb8-77e68a140000 pid=5258 /usr/bin/bash guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=4e600dfe-1900-0000-2bb8-77e68a140000 pid=5258 clone guuid=b009cbfe-1900-0000-2bb8-77e68c140000 pid=5260 /usr/bin/wget net send-data write-file guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=b009cbfe-1900-0000-2bb8-77e68c140000 pid=5260 execve guuid=2776cb09-1a00-0000-2bb8-77e68d140000 pid=5261 /usr/bin/chmod guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=2776cb09-1a00-0000-2bb8-77e68d140000 pid=5261 execve guuid=50632d0a-1a00-0000-2bb8-77e68e140000 pid=5262 /usr/bin/bash guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=50632d0a-1a00-0000-2bb8-77e68e140000 pid=5262 clone guuid=3c656a0b-1a00-0000-2bb8-77e690140000 pid=5264 /usr/bin/wget net send-data write-file guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=3c656a0b-1a00-0000-2bb8-77e690140000 pid=5264 execve guuid=43a87b1a-1a00-0000-2bb8-77e691140000 pid=5265 /usr/bin/chmod guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=43a87b1a-1a00-0000-2bb8-77e691140000 pid=5265 execve guuid=90d2081b-1a00-0000-2bb8-77e692140000 pid=5266 /usr/bin/bash guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=90d2081b-1a00-0000-2bb8-77e692140000 pid=5266 clone guuid=5cf07d1d-1a00-0000-2bb8-77e694140000 pid=5268 /usr/bin/wget net send-data write-file guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=5cf07d1d-1a00-0000-2bb8-77e694140000 pid=5268 execve guuid=cbcef83b-1a00-0000-2bb8-77e695140000 pid=5269 /usr/bin/chmod guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=cbcef83b-1a00-0000-2bb8-77e695140000 pid=5269 execve guuid=b62cfe3c-1a00-0000-2bb8-77e696140000 pid=5270 /usr/bin/bash guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=b62cfe3c-1a00-0000-2bb8-77e696140000 pid=5270 clone guuid=79a45149-1a00-0000-2bb8-77e698140000 pid=5272 /usr/bin/wget net send-data write-file guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=79a45149-1a00-0000-2bb8-77e698140000 pid=5272 execve guuid=49bc0956-1a00-0000-2bb8-77e699140000 pid=5273 /usr/bin/chmod guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=49bc0956-1a00-0000-2bb8-77e699140000 pid=5273 execve guuid=530fbe56-1a00-0000-2bb8-77e69a140000 pid=5274 /home/sandbox/x86 net guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=530fbe56-1a00-0000-2bb8-77e69a140000 pid=5274 execve guuid=76d9fcce-1a00-0000-2bb8-77e6a6140000 pid=5286 /usr/bin/wget net send-data write-file guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=76d9fcce-1a00-0000-2bb8-77e6a6140000 pid=5286 execve guuid=5cd7e0dd-1a00-0000-2bb8-77e6ad140000 pid=5293 /usr/bin/chmod guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=5cd7e0dd-1a00-0000-2bb8-77e6ad140000 pid=5293 execve guuid=fcc390de-1a00-0000-2bb8-77e6af140000 pid=5295 /home/sandbox/x86_64 net guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=fcc390de-1a00-0000-2bb8-77e6af140000 pid=5295 execve guuid=986d3256-1b00-0000-2bb8-77e6ca140000 pid=5322 /usr/bin/rm delete-file guuid=5a8d7a54-1900-0000-2bb8-77e668140000 pid=5224->guuid=986d3256-1b00-0000-2bb8-77e6ca140000 pid=5322 execve ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 94.156.152.237:80 guuid=5d991655-1900-0000-2bb8-77e669140000 pid=5225->ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 send: 137B guuid=ccfebd6d-1900-0000-2bb8-77e66d140000 pid=5229->ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 send: 276B guuid=a7a526bb-1900-0000-2bb8-77e671140000 pid=5233->ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 send: 138B guuid=0eb492c9-1900-0000-2bb8-77e679140000 pid=5241->ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 send: 138B guuid=55ef19d6-1900-0000-2bb8-77e680140000 pid=5248->ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 send: 138B guuid=495b92e5-1900-0000-2bb8-77e684140000 pid=5252->ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 send: 138B guuid=013306f5-1900-0000-2bb8-77e688140000 pid=5256->ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 send: 138B guuid=b009cbfe-1900-0000-2bb8-77e68c140000 pid=5260->ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 send: 137B guuid=3c656a0b-1a00-0000-2bb8-77e690140000 pid=5264->ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 send: 137B guuid=5cf07d1d-1a00-0000-2bb8-77e694140000 pid=5268->ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 send: 137B guuid=79a45149-1a00-0000-2bb8-77e698140000 pid=5272->ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 send: 137B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=530fbe56-1a00-0000-2bb8-77e69a140000 pid=5274->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ac767657-1a00-0000-2bb8-77e69b140000 pid=5275 /home/sandbox/x86 guuid=530fbe56-1a00-0000-2bb8-77e69a140000 pid=5274->guuid=ac767657-1a00-0000-2bb8-77e69b140000 pid=5275 clone guuid=81d21e93-1a00-0000-2bb8-77e69c140000 pid=5276 /home/sandbox/x86 guuid=530fbe56-1a00-0000-2bb8-77e69a140000 pid=5274->guuid=81d21e93-1a00-0000-2bb8-77e69c140000 pid=5276 clone guuid=ba8accce-1a00-0000-2bb8-77e6a3140000 pid=5283 /home/sandbox/x86 guuid=530fbe56-1a00-0000-2bb8-77e69a140000 pid=5274->guuid=ba8accce-1a00-0000-2bb8-77e6a3140000 pid=5283 clone guuid=8045dace-1a00-0000-2bb8-77e6a4140000 pid=5284 /home/sandbox/x86 net send-data zombie guuid=530fbe56-1a00-0000-2bb8-77e69a140000 pid=5274->guuid=8045dace-1a00-0000-2bb8-77e6a4140000 pid=5284 clone guuid=8045dace-1a00-0000-2bb8-77e6a4140000 pid=5284->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 171898fd-768b-54b9-9f46-d9d4720accd5 94.156.152.237:1999 guuid=8045dace-1a00-0000-2bb8-77e6a4140000 pid=5284->171898fd-768b-54b9-9f46-d9d4720accd5 send: 352B guuid=5d1dfbce-1a00-0000-2bb8-77e6a5140000 pid=5285 /home/sandbox/x86 guuid=8045dace-1a00-0000-2bb8-77e6a4140000 pid=5284->guuid=5d1dfbce-1a00-0000-2bb8-77e6a5140000 pid=5285 clone guuid=2bc4a60a-1b00-0000-2bb8-77e6b4140000 pid=5300 /home/sandbox/x86 guuid=8045dace-1a00-0000-2bb8-77e6a4140000 pid=5284->guuid=2bc4a60a-1b00-0000-2bb8-77e6b4140000 pid=5300 clone guuid=0ebf5d46-1b00-0000-2bb8-77e6c6140000 pid=5318 /home/sandbox/x86 guuid=8045dace-1a00-0000-2bb8-77e6a4140000 pid=5284->guuid=0ebf5d46-1b00-0000-2bb8-77e6c6140000 pid=5318 clone guuid=76d9fcce-1a00-0000-2bb8-77e6a6140000 pid=5286->ffbcc0cf-d585-53c7-be85-934ca2c1c2b7 send: 140B guuid=fcc390de-1a00-0000-2bb8-77e6af140000 pid=5295->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2528b0de-1a00-0000-2bb8-77e6b0140000 pid=5296 /home/sandbox/x86_64 guuid=fcc390de-1a00-0000-2bb8-77e6af140000 pid=5295->guuid=2528b0de-1a00-0000-2bb8-77e6b0140000 pid=5296 clone guuid=ba23541a-1b00-0000-2bb8-77e6bb140000 pid=5307 /home/sandbox/x86_64 guuid=fcc390de-1a00-0000-2bb8-77e6af140000 pid=5295->guuid=ba23541a-1b00-0000-2bb8-77e6bb140000 pid=5307 clone guuid=db3f0156-1b00-0000-2bb8-77e6c7140000 pid=5319 /home/sandbox/x86_64 guuid=fcc390de-1a00-0000-2bb8-77e6af140000 pid=5295->guuid=db3f0156-1b00-0000-2bb8-77e6c7140000 pid=5319 clone guuid=64400956-1b00-0000-2bb8-77e6c8140000 pid=5320 /home/sandbox/x86_64 net send-data zombie guuid=fcc390de-1a00-0000-2bb8-77e6af140000 pid=5295->guuid=64400956-1b00-0000-2bb8-77e6c8140000 pid=5320 clone guuid=64400956-1b00-0000-2bb8-77e6c8140000 pid=5320->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=64400956-1b00-0000-2bb8-77e6c8140000 pid=5320->171898fd-768b-54b9-9f46-d9d4720accd5 send: 506B guuid=09f01a56-1b00-0000-2bb8-77e6c9140000 pid=5321 /home/sandbox/x86_64 guuid=64400956-1b00-0000-2bb8-77e6c8140000 pid=5320->guuid=09f01a56-1b00-0000-2bb8-77e6c9140000 pid=5321 clone guuid=c22acc91-1b00-0000-2bb8-77e6cb140000 pid=5323 /home/sandbox/x86_64 guuid=64400956-1b00-0000-2bb8-77e6c8140000 pid=5320->guuid=c22acc91-1b00-0000-2bb8-77e6cb140000 pid=5323 clone guuid=51da7ccd-1b00-0000-2bb8-77e6cc140000 pid=5324 /home/sandbox/x86_64 guuid=64400956-1b00-0000-2bb8-77e6c8140000 pid=5320->guuid=51da7ccd-1b00-0000-2bb8-77e6cc140000 pid=5324 clone
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2025-10-25 13:49:30 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 489e2e274923863955068bf07d9050ef9da2fc70918cd64a1b2380ef28dbfa22

(this sample)

  
Delivery method
Distributed via web download

Comments