MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4bd82202aa1dc7bf3605e7951c113089fdee4e5fb0a29b1ae1207114ed998b53. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 4bd82202aa1dc7bf3605e7951c113089fdee4e5fb0a29b1ae1207114ed998b53
SHA3-384 hash: e9a78dfc4c24530df34b66bcf019e18d963ae2afb53673f0ca3fb947e3cb67c89819e76a354a3601ac5121f49885f59d
SHA1 hash: 7db6d520a0beb142769c8798ede3b8f517d8d321
MD5 hash: 29df943fc53464dd769350c8803e33a1
humanhash: london-william-monkey-arizona
File name:c.sh
Download: download sample
Signature Mirai
File size:671 bytes
First seen:2026-01-01 10:02:52 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3UUlxqQUUneKlCEQUUTiKl2EQUU7dKAQUU5QUUm9qQUUzFG10qQUUw1QUUk7IG:3J3Vx/lCaKl/7cRHR
TLSH T1AA01ECEE45BAE993DB1C8E4CB0AA842CA581D1C57EB3DE84E83C44705CC71063065FB7
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.94.208.27/parm9a9f7624b0dad8817e70e72a007686c91f1a53d2dc254817f9ee6fd19eed0ce6 Miraielf mirai ua-wget
http://158.94.208.27/parmsn/an/aelf
http://158.94.208.27/parm78027c6f089be296b3961b35fd9f4dc03edd64d05288e5e51ded9a3a25c0ab6b3 Miraielf mirai ua-wget
http://158.94.208.27/psh44e49fbeee717728935e64e493d8b0685c0da63b15b10c5c8875f1499e8a89a92 Miraielf mirai ua-wget
http://158.94.208.27/pnpcn/an/aelf
http://158.94.208.27/pmips648a1ad85e1ef2c1306e922cb9fee502490224f527dfbcbd9397c11a1db03cb1 Miraielf mirai ua-wget
http://158.94.208.27/pmpsl46280c6dceff8fe250699ec09396d2170a5ef12e74ffcca4a3c4ccbb839cc1d3 Miraielf mirai ua-wget
http://158.94.208.27/pm68k72bf7021a323e4f8668499f2c124973c6d4744abddab61449824d7b5334249f6 Miraielf mirai ua-wget
http://158.94.208.27/px8681aa3a1cec78008abbe0506a44c20fc80efe006f5c4d84fdec6c8ed9d84521d6 Miraielf mirai ua-wget
http://158.94.208.27/px86_64113bc2274f429d9cd5cb64c14738556807e72c051f5409a5be4857ed5480fb84 Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
text
First seen:
2026-01-01T07:09:00Z UTC
Last seen:
2026-01-02T02:59:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=abe79c4b-1900-0000-7fac-ee8b650f0000 pid=3941 /usr/bin/sudo guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945 /tmp/sample.bin guuid=abe79c4b-1900-0000-7fac-ee8b650f0000 pid=3941->guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945 execve guuid=2331cc4d-1900-0000-7fac-ee8b6a0f0000 pid=3946 /usr/bin/curl net send-data guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=2331cc4d-1900-0000-7fac-ee8b6a0f0000 pid=3946 execve guuid=937dfe5c-1900-0000-7fac-ee8baa0f0000 pid=4010 /usr/bin/chmod guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=937dfe5c-1900-0000-7fac-ee8baa0f0000 pid=4010 execve guuid=d732375d-1900-0000-7fac-ee8bac0f0000 pid=4012 /usr/bin/dash guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=d732375d-1900-0000-7fac-ee8bac0f0000 pid=4012 clone guuid=00cb3e5d-1900-0000-7fac-ee8bad0f0000 pid=4013 /usr/bin/curl net send-data guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=00cb3e5d-1900-0000-7fac-ee8bad0f0000 pid=4013 execve guuid=b63c6164-1900-0000-7fac-ee8bd00f0000 pid=4048 /usr/bin/chmod guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=b63c6164-1900-0000-7fac-ee8bd00f0000 pid=4048 execve guuid=19cfa464-1900-0000-7fac-ee8bd20f0000 pid=4050 /usr/bin/dash guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=19cfa464-1900-0000-7fac-ee8bd20f0000 pid=4050 clone guuid=b389ad64-1900-0000-7fac-ee8bd40f0000 pid=4052 /usr/bin/curl net send-data guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=b389ad64-1900-0000-7fac-ee8bd40f0000 pid=4052 execve guuid=b5c29171-1900-0000-7fac-ee8b0b100000 pid=4107 /usr/bin/chmod guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=b5c29171-1900-0000-7fac-ee8b0b100000 pid=4107 execve guuid=a517cc71-1900-0000-7fac-ee8b0d100000 pid=4109 /usr/bin/dash guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=a517cc71-1900-0000-7fac-ee8b0d100000 pid=4109 clone guuid=852adb71-1900-0000-7fac-ee8b0e100000 pid=4110 /usr/bin/curl net send-data guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=852adb71-1900-0000-7fac-ee8b0e100000 pid=4110 execve guuid=e8a83e7f-1900-0000-7fac-ee8b3f100000 pid=4159 /usr/bin/chmod guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=e8a83e7f-1900-0000-7fac-ee8b3f100000 pid=4159 execve guuid=38f3897f-1900-0000-7fac-ee8b41100000 pid=4161 /usr/bin/dash guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=38f3897f-1900-0000-7fac-ee8b41100000 pid=4161 clone guuid=d538977f-1900-0000-7fac-ee8b42100000 pid=4162 /usr/bin/curl net send-data guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=d538977f-1900-0000-7fac-ee8b42100000 pid=4162 execve guuid=7659e586-1900-0000-7fac-ee8b52100000 pid=4178 /usr/bin/chmod guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=7659e586-1900-0000-7fac-ee8b52100000 pid=4178 execve guuid=d1061a87-1900-0000-7fac-ee8b53100000 pid=4179 /usr/bin/dash guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=d1061a87-1900-0000-7fac-ee8b53100000 pid=4179 clone guuid=3a262487-1900-0000-7fac-ee8b56100000 pid=4182 /usr/bin/curl net send-data guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=3a262487-1900-0000-7fac-ee8b56100000 pid=4182 execve guuid=61810094-1900-0000-7fac-ee8b87100000 pid=4231 /usr/bin/chmod guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=61810094-1900-0000-7fac-ee8b87100000 pid=4231 execve guuid=c38d5094-1900-0000-7fac-ee8b8b100000 pid=4235 /usr/bin/dash guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=c38d5094-1900-0000-7fac-ee8b8b100000 pid=4235 clone guuid=15c46094-1900-0000-7fac-ee8b8c100000 pid=4236 /usr/bin/curl net send-data guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=15c46094-1900-0000-7fac-ee8b8c100000 pid=4236 execve guuid=689651a2-1900-0000-7fac-ee8bbf100000 pid=4287 /usr/bin/chmod guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=689651a2-1900-0000-7fac-ee8bbf100000 pid=4287 execve guuid=d4dd93a2-1900-0000-7fac-ee8bc1100000 pid=4289 /usr/bin/dash guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=d4dd93a2-1900-0000-7fac-ee8bc1100000 pid=4289 clone guuid=6fb69da2-1900-0000-7fac-ee8bc2100000 pid=4290 /usr/bin/curl net send-data guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=6fb69da2-1900-0000-7fac-ee8bc2100000 pid=4290 execve guuid=2a82cfb2-1900-0000-7fac-ee8bf2100000 pid=4338 /usr/bin/chmod guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=2a82cfb2-1900-0000-7fac-ee8bf2100000 pid=4338 execve guuid=925539b3-1900-0000-7fac-ee8bf3100000 pid=4339 /usr/bin/dash guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=925539b3-1900-0000-7fac-ee8bf3100000 pid=4339 clone guuid=93be4ab3-1900-0000-7fac-ee8bf5100000 pid=4341 /usr/bin/curl net send-data guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=93be4ab3-1900-0000-7fac-ee8bf5100000 pid=4341 execve guuid=45667bbf-1900-0000-7fac-ee8b17110000 pid=4375 /usr/bin/chmod guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=45667bbf-1900-0000-7fac-ee8b17110000 pid=4375 execve guuid=914126c0-1900-0000-7fac-ee8b1a110000 pid=4378 /usr/bin/dash guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=914126c0-1900-0000-7fac-ee8b1a110000 pid=4378 clone guuid=5c5338c0-1900-0000-7fac-ee8b1b110000 pid=4379 /usr/bin/curl net send-data guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=5c5338c0-1900-0000-7fac-ee8b1b110000 pid=4379 execve guuid=71cc23cc-1900-0000-7fac-ee8b49110000 pid=4425 /usr/bin/chmod guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=71cc23cc-1900-0000-7fac-ee8b49110000 pid=4425 execve guuid=483166cc-1900-0000-7fac-ee8b4a110000 pid=4426 /usr/bin/dash guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=483166cc-1900-0000-7fac-ee8b4a110000 pid=4426 clone guuid=744e75cc-1900-0000-7fac-ee8b4b110000 pid=4427 /usr/bin/rm delete-file guuid=13d28d4d-1900-0000-7fac-ee8b690f0000 pid=3945->guuid=744e75cc-1900-0000-7fac-ee8b4b110000 pid=4427 execve b8c32f6f-e0ff-5b69-a443-652e84386a76 158.94.208.27:80 guuid=2331cc4d-1900-0000-7fac-ee8b6a0f0000 pid=3946->b8c32f6f-e0ff-5b69-a443-652e84386a76 send: 81B guuid=00cb3e5d-1900-0000-7fac-ee8bad0f0000 pid=4013->b8c32f6f-e0ff-5b69-a443-652e84386a76 send: 82B guuid=b389ad64-1900-0000-7fac-ee8bd40f0000 pid=4052->b8c32f6f-e0ff-5b69-a443-652e84386a76 send: 82B guuid=852adb71-1900-0000-7fac-ee8b0e100000 pid=4110->b8c32f6f-e0ff-5b69-a443-652e84386a76 send: 81B guuid=d538977f-1900-0000-7fac-ee8b42100000 pid=4162->b8c32f6f-e0ff-5b69-a443-652e84386a76 send: 81B guuid=3a262487-1900-0000-7fac-ee8b56100000 pid=4182->b8c32f6f-e0ff-5b69-a443-652e84386a76 send: 82B guuid=15c46094-1900-0000-7fac-ee8b8c100000 pid=4236->b8c32f6f-e0ff-5b69-a443-652e84386a76 send: 82B guuid=6fb69da2-1900-0000-7fac-ee8bc2100000 pid=4290->b8c32f6f-e0ff-5b69-a443-652e84386a76 send: 82B guuid=93be4ab3-1900-0000-7fac-ee8bf5100000 pid=4341->b8c32f6f-e0ff-5b69-a443-652e84386a76 send: 81B guuid=5c5338c0-1900-0000-7fac-ee8b1b110000 pid=4379->b8c32f6f-e0ff-5b69-a443-652e84386a76 send: 84B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-01-01 10:03:14 UTC
File Type:
Text (Shell)
AV detection:
10 of 23 (43.48%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4bd82202aa1dc7bf3605e7951c113089fdee4e5fb0a29b1ae1207114ed998b53

(this sample)

  
Delivery method
Distributed via web download

Comments