MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 52c94e3c75efa93f2d32a2ed2ab1c45da74b5ce058701aa98a60a56556529b20. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 52c94e3c75efa93f2d32a2ed2ab1c45da74b5ce058701aa98a60a56556529b20
SHA3-384 hash: c5b8c0ebf257573d766011cb1790247e540072518e0889c1d829f04e59b560b1addd51fbe3c95d26d478740be9fa53ce
SHA1 hash: 2884f66dfbf5d67a7fb6c6ccb8147ca8e417ec12
MD5 hash: 7e239fafc9bc700fa24932885d4e9384
humanhash: uncle-gee-snake-muppet
File name:li
Download: download sample
Signature Mirai
File size:3'053 bytes
First seen:2025-09-12 10:18:23 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:pPZkCpxFFlCpxFF9CpxFFpCpxFFbCpxFFtCpxFF9CpxFFdMZqgBlWxb7wtJk/Wht:vEMQW8slMAAolnWgZo9
TLSH T1E15184AFF4429EF20DEC9A551C9AC5297917C0D38460CD8AEC7F0DA0A969E14B4F06DF
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.250.134.51/mips7cd5fb5b6d94ac2acf16f8904f6f307f47710df1d51129d55e70590a52dcf823 Mirai32-bit elf gafgyt mirai Mozi
http://160.250.134.51/arm8a235a9336092da5a5fd75dc7c04bf109a796cab8cbe52666f972c2c5f3ff285 Mirai32-bit elf mirai Mozi
http://160.250.134.51/arm516877e8cab68f6d6a557b0bee1e41a6d938997cb31a62cfe017ed21867b41801 Miraielf mirai ua-wget
http://160.250.134.51/arm70fd1878b69312fbf748d3be8ba65b3431083985fcfe65a3b32a74a8ef69cdf89 Miraielf mirai ua-wget
http://160.250.134.51/mpsle4acbf0a1448e928ea7714cf90692001c454b37d78b13a955f475568b36bbaec Miraielf mirai ua-wget
http://160.250.134.51/arca7ce2785a746d714cd6407d2a8ef07c9d510e10b46f0f8d0d4a266cc16774a57 Miraielf mirai ua-wget
http://160.250.134.51/aarch646c7cb03cbd896b51cfe7c3aecba63ab659daaa0fb6e2e05be43f3726aef61d57 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-09-12T08:22:00Z UTC
Last seen:
2025-09-12T08:22:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=c10eb7ae-1a00-0000-4cc7-ad9f730b0000 pid=2931 /usr/bin/sudo guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938 /tmp/sample.bin guuid=c10eb7ae-1a00-0000-4cc7-ad9f730b0000 pid=2931->guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938 execve guuid=389392b2-1a00-0000-4cc7-ad9f7c0b0000 pid=2940 /usr/bin/cp guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=389392b2-1a00-0000-4cc7-ad9f7c0b0000 pid=2940 execve guuid=5e7db3b8-1a00-0000-4cc7-ad9f880b0000 pid=2952 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=5e7db3b8-1a00-0000-4cc7-ad9f880b0000 pid=2952 clone guuid=85bde909-1b00-0000-4cc7-ad9f4a0c0000 pid=3146 /usr/bin/chmod guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=85bde909-1b00-0000-4cc7-ad9f4a0c0000 pid=3146 execve guuid=3c5f390a-1b00-0000-4cc7-ad9f4c0c0000 pid=3148 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=3c5f390a-1b00-0000-4cc7-ad9f4c0c0000 pid=3148 clone guuid=08ee070b-1b00-0000-4cc7-ad9f4f0c0000 pid=3151 /usr/bin/rm delete-file guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=08ee070b-1b00-0000-4cc7-ad9f4f0c0000 pid=3151 execve guuid=ef24640b-1b00-0000-4cc7-ad9f510c0000 pid=3153 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=ef24640b-1b00-0000-4cc7-ad9f510c0000 pid=3153 clone guuid=51163253-1b00-0000-4cc7-ad9f9a0c0000 pid=3226 /usr/bin/chmod guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=51163253-1b00-0000-4cc7-ad9f9a0c0000 pid=3226 execve guuid=9507c253-1b00-0000-4cc7-ad9f9b0c0000 pid=3227 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=9507c253-1b00-0000-4cc7-ad9f9b0c0000 pid=3227 clone guuid=1e2edf55-1b00-0000-4cc7-ad9f9d0c0000 pid=3229 /usr/bin/rm delete-file guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=1e2edf55-1b00-0000-4cc7-ad9f9d0c0000 pid=3229 execve guuid=f2146956-1b00-0000-4cc7-ad9f9e0c0000 pid=3230 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=f2146956-1b00-0000-4cc7-ad9f9e0c0000 pid=3230 clone guuid=c77a31a2-1b00-0000-4cc7-ad9ff70c0000 pid=3319 /usr/bin/chmod guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=c77a31a2-1b00-0000-4cc7-ad9ff70c0000 pid=3319 execve guuid=1054a1a2-1b00-0000-4cc7-ad9ff80c0000 pid=3320 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=1054a1a2-1b00-0000-4cc7-ad9ff80c0000 pid=3320 clone guuid=b39d4aa3-1b00-0000-4cc7-ad9ffa0c0000 pid=3322 /usr/bin/rm delete-file guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=b39d4aa3-1b00-0000-4cc7-ad9ffa0c0000 pid=3322 execve guuid=9f6896a3-1b00-0000-4cc7-ad9ffb0c0000 pid=3323 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=9f6896a3-1b00-0000-4cc7-ad9ffb0c0000 pid=3323 clone guuid=b1cd73ec-1b00-0000-4cc7-ad9f540d0000 pid=3412 /usr/bin/chmod guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=b1cd73ec-1b00-0000-4cc7-ad9f540d0000 pid=3412 execve guuid=b00ed4ec-1b00-0000-4cc7-ad9f560d0000 pid=3414 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=b00ed4ec-1b00-0000-4cc7-ad9f560d0000 pid=3414 clone guuid=e69f80ed-1b00-0000-4cc7-ad9f590d0000 pid=3417 /usr/bin/rm delete-file guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=e69f80ed-1b00-0000-4cc7-ad9f590d0000 pid=3417 execve guuid=7940dbed-1b00-0000-4cc7-ad9f5b0d0000 pid=3419 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=7940dbed-1b00-0000-4cc7-ad9f5b0d0000 pid=3419 clone guuid=af445945-1c00-0000-4cc7-ad9f230e0000 pid=3619 /usr/bin/chmod guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=af445945-1c00-0000-4cc7-ad9f230e0000 pid=3619 execve guuid=56c9a645-1c00-0000-4cc7-ad9f240e0000 pid=3620 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=56c9a645-1c00-0000-4cc7-ad9f240e0000 pid=3620 clone guuid=94f85346-1c00-0000-4cc7-ad9f270e0000 pid=3623 /usr/bin/rm delete-file guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=94f85346-1c00-0000-4cc7-ad9f270e0000 pid=3623 execve guuid=f5a19b46-1c00-0000-4cc7-ad9f290e0000 pid=3625 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=f5a19b46-1c00-0000-4cc7-ad9f290e0000 pid=3625 clone guuid=7a7e2f96-1c00-0000-4cc7-ad9f090f0000 pid=3849 /usr/bin/chmod guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=7a7e2f96-1c00-0000-4cc7-ad9f090f0000 pid=3849 execve guuid=5f1e2d97-1c00-0000-4cc7-ad9f0e0f0000 pid=3854 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=5f1e2d97-1c00-0000-4cc7-ad9f0e0f0000 pid=3854 clone guuid=05ef6999-1c00-0000-4cc7-ad9f100f0000 pid=3856 /usr/bin/rm delete-file guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=05ef6999-1c00-0000-4cc7-ad9f100f0000 pid=3856 execve guuid=bf86c399-1c00-0000-4cc7-ad9f110f0000 pid=3857 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=bf86c399-1c00-0000-4cc7-ad9f110f0000 pid=3857 clone guuid=a79304e2-1c00-0000-4cc7-ad9fd00f0000 pid=4048 /usr/bin/chmod guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=a79304e2-1c00-0000-4cc7-ad9fd00f0000 pid=4048 execve guuid=37964ae2-1c00-0000-4cc7-ad9fd20f0000 pid=4050 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=37964ae2-1c00-0000-4cc7-ad9fd20f0000 pid=4050 clone guuid=f80738e5-1c00-0000-4cc7-ad9fdc0f0000 pid=4060 /usr/bin/rm delete-file guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=f80738e5-1c00-0000-4cc7-ad9fdc0f0000 pid=4060 execve guuid=ebca94e5-1c00-0000-4cc7-ad9fde0f0000 pid=4062 /usr/bin/busybox send-data guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=ebca94e5-1c00-0000-4cc7-ad9fde0f0000 pid=4062 execve guuid=72a77ce8-1f00-0000-4cc7-ad9fa0140000 pid=5280 /usr/bin/chmod guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=72a77ce8-1f00-0000-4cc7-ad9fa0140000 pid=5280 execve guuid=0943f2e9-1f00-0000-4cc7-ad9fa1140000 pid=5281 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=0943f2e9-1f00-0000-4cc7-ad9fa1140000 pid=5281 clone guuid=f19e2eea-1f00-0000-4cc7-ad9fa2140000 pid=5282 /usr/bin/rm guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=f19e2eea-1f00-0000-4cc7-ad9fa2140000 pid=5282 execve guuid=3d38a1ea-1f00-0000-4cc7-ad9fa3140000 pid=5283 /usr/bin/busybox send-data guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=3d38a1ea-1f00-0000-4cc7-ad9fa3140000 pid=5283 execve guuid=05ab2cee-2200-0000-4cc7-ad9fc4140000 pid=5316 /usr/bin/chmod guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=05ab2cee-2200-0000-4cc7-ad9fc4140000 pid=5316 execve guuid=ed48a7ee-2200-0000-4cc7-ad9fc5140000 pid=5317 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=ed48a7ee-2200-0000-4cc7-ad9fc5140000 pid=5317 clone guuid=6c65c2ee-2200-0000-4cc7-ad9fc6140000 pid=5318 /usr/bin/rm guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=6c65c2ee-2200-0000-4cc7-ad9fc6140000 pid=5318 execve guuid=8faf5aef-2200-0000-4cc7-ad9fc7140000 pid=5319 /usr/bin/busybox send-data guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=8faf5aef-2200-0000-4cc7-ad9fc7140000 pid=5319 execve guuid=523837f3-2500-0000-4cc7-ad9fc8140000 pid=5320 /usr/bin/chmod guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=523837f3-2500-0000-4cc7-ad9fc8140000 pid=5320 execve guuid=264e14f4-2500-0000-4cc7-ad9fc9140000 pid=5321 /usr/bin/dash guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=264e14f4-2500-0000-4cc7-ad9fc9140000 pid=5321 clone guuid=f4db32f4-2500-0000-4cc7-ad9fca140000 pid=5322 /usr/bin/rm guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=f4db32f4-2500-0000-4cc7-ad9fca140000 pid=5322 execve guuid=3186cff4-2500-0000-4cc7-ad9fcb140000 pid=5323 /usr/bin/busybox send-data guuid=9307ddb1-1a00-0000-4cc7-ad9f7a0b0000 pid=2938->guuid=3186cff4-2500-0000-4cc7-ad9fcb140000 pid=5323 execve guuid=f047c0b8-1a00-0000-4cc7-ad9f8a0b0000 pid=2954 /usr/bin/busybox net send-data write-file guuid=5e7db3b8-1a00-0000-4cc7-ad9f880b0000 pid=2952->guuid=f047c0b8-1a00-0000-4cc7-ad9f8a0b0000 pid=2954 execve 1d308332-b4a8-571e-bb87-6027ccfc29b6 160.250.134.51:80 guuid=f047c0b8-1a00-0000-4cc7-ad9f8a0b0000 pid=2954->1d308332-b4a8-571e-bb87-6027ccfc29b6 send: 81B guuid=aa127c0b-1b00-0000-4cc7-ad9f520c0000 pid=3154 /usr/bin/busybox net send-data write-file guuid=ef24640b-1b00-0000-4cc7-ad9f510c0000 pid=3153->guuid=aa127c0b-1b00-0000-4cc7-ad9f520c0000 pid=3154 execve guuid=aa127c0b-1b00-0000-4cc7-ad9f520c0000 pid=3154->1d308332-b4a8-571e-bb87-6027ccfc29b6 send: 80B guuid=b7328656-1b00-0000-4cc7-ad9f9f0c0000 pid=3231 /usr/bin/busybox net send-data write-file guuid=f2146956-1b00-0000-4cc7-ad9f9e0c0000 pid=3230->guuid=b7328656-1b00-0000-4cc7-ad9f9f0c0000 pid=3231 execve guuid=b7328656-1b00-0000-4cc7-ad9f9f0c0000 pid=3231->1d308332-b4a8-571e-bb87-6027ccfc29b6 send: 81B guuid=6472a1a3-1b00-0000-4cc7-ad9ffc0c0000 pid=3324 /usr/bin/busybox net send-data write-file guuid=9f6896a3-1b00-0000-4cc7-ad9ffb0c0000 pid=3323->guuid=6472a1a3-1b00-0000-4cc7-ad9ffc0c0000 pid=3324 execve guuid=6472a1a3-1b00-0000-4cc7-ad9ffc0c0000 pid=3324->1d308332-b4a8-571e-bb87-6027ccfc29b6 send: 81B guuid=c4d4e8ed-1b00-0000-4cc7-ad9f5c0d0000 pid=3420 /usr/bin/busybox net send-data write-file guuid=7940dbed-1b00-0000-4cc7-ad9f5b0d0000 pid=3419->guuid=c4d4e8ed-1b00-0000-4cc7-ad9f5c0d0000 pid=3420 execve guuid=c4d4e8ed-1b00-0000-4cc7-ad9f5c0d0000 pid=3420->1d308332-b4a8-571e-bb87-6027ccfc29b6 send: 81B guuid=17a7a846-1c00-0000-4cc7-ad9f2a0e0000 pid=3626 /usr/bin/busybox net send-data write-file guuid=f5a19b46-1c00-0000-4cc7-ad9f290e0000 pid=3625->guuid=17a7a846-1c00-0000-4cc7-ad9f2a0e0000 pid=3626 execve guuid=17a7a846-1c00-0000-4cc7-ad9f2a0e0000 pid=3626->1d308332-b4a8-571e-bb87-6027ccfc29b6 send: 80B guuid=8ddccf99-1c00-0000-4cc7-ad9f120f0000 pid=3858 /usr/bin/busybox net send-data write-file guuid=bf86c399-1c00-0000-4cc7-ad9f110f0000 pid=3857->guuid=8ddccf99-1c00-0000-4cc7-ad9f120f0000 pid=3858 execve guuid=8ddccf99-1c00-0000-4cc7-ad9f120f0000 pid=3858->1d308332-b4a8-571e-bb87-6027ccfc29b6 send: 84B cdcd4234-bb67-5bc1-81e0-1f73fd0058b9 160.250.134.51:69 guuid=ebca94e5-1c00-0000-4cc7-ad9fde0f0000 pid=4062->cdcd4234-bb67-5bc1-81e0-1f73fd0058b9 send: 252B guuid=3d38a1ea-1f00-0000-4cc7-ad9fa3140000 pid=5283->cdcd4234-bb67-5bc1-81e0-1f73fd0058b9 send: 252B guuid=8faf5aef-2200-0000-4cc7-ad9fc7140000 pid=5319->cdcd4234-bb67-5bc1-81e0-1f73fd0058b9 send: 252B guuid=3186cff4-2500-0000-4cc7-ad9fcb140000 pid=5323->cdcd4234-bb67-5bc1-81e0-1f73fd0058b9 send: 240B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-09-12 09:07:02 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 52c94e3c75efa93f2d32a2ed2ab1c45da74b5ce058701aa98a60a56556529b20

(this sample)

  
Delivery method
Distributed via web download

Comments