MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 560ff3969aaeb7bd6d66c5adde827c20a1ae1745be67d570e2ed3b78ccb7d76f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 560ff3969aaeb7bd6d66c5adde827c20a1ae1745be67d570e2ed3b78ccb7d76f
SHA3-384 hash: 05ab5660bc6a9ddb7af490bb5b694db1fe724ce0713c9882dcedbf1126781280b84830b2b99ee1fcdc6eddcd3ede5dee
SHA1 hash: 089a7b300c150138a53fa4e6fe9eb24b6d865e9d
MD5 hash: f4218aca95bcf230ea18bc25c1bde5f8
humanhash: alanine-india-carolina-mobile
File name:c.sh
Download: download sample
Signature Mirai
File size:835 bytes
First seen:2025-11-21 22:14:48 UTC
Last seen:2025-12-08 01:55:31 UTC
File type: sh
MIME type:text/plain
ssdeep 12:3J3L4yXBJL4y2YVL4y3NIl5EL4yc0LKmpL4ym+OQJL4yjjMVSL4y9T535L4yCSOi:3J3eYJNI7kKt+XNjFT1Ylut4ErRR
TLSH T14E01CCCD66B57263B644CF38B06680AC9275FAD0B27C8B16F9D40CB6C4D9311322AB7D
Magika batch
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://31.97.147.189/systemcl/armbe58a44667b375703a76ad0c6ddca15d16aee9717d125919f20dce30763cc00e Mirai32-bit elf mirai Mozi
http://31.97.147.189/systemcl/arm558979f8f088f4a7ccb290972f63908b9f2aed2745965edec68713c3cd48288dd Miraiarm elf geofenced mirai ua-wget USA
http://31.97.147.189/systemcl/arm6cda60790407bccd1f7e11f6b1ec2f299a5348392a1abfdfddaeae28e42bd284f Miraiarm elf geofenced mirai ua-wget USA
http://31.97.147.189/systemcl/arm77dd8c3fe8594bd26a06d0df7438b4c06356b02767c5f246bcca9380549452261 Miraiarm elf geofenced mirai ua-wget USA
http://31.97.147.189/systemcl/m68kee69d2f047fb8bd98d96d1ff4fb41f5dbea8aa91d81b60819542c8de7eb80a62 Miraielf geofenced m68k mirai ua-wget USA
http://31.97.147.189/systemcl/mipsb38cac7dcd0b2f68f15499113658d15987de22ba225cea00a14e95a885adec75 Mirai32-bit elf mirai Mozi
http://31.97.147.189/systemcl/mpsl6bcd18e09bdddc9823c1ebc6090640ed723eddb8d214958ee99d607da2e6d86b Miraielf geofenced mips mirai ua-wget USA
http://31.97.147.189/systemcl/ppc55bdaa3a8a9608985b07865783259092d37736f52066f94df42f2a4c9820b026 Miraielf geofenced mirai PowerPC ua-wget USA
http://31.97.147.189/systemcl/sh46d1e8f244ece4575dd4fa0e405b758ba2bf4b265cdf25eda7084d2d7bd3d1a83 Miraielf mirai ua-wget
http://31.97.147.189/systemcl/spcab43916d8e693e404bcb5f0c732139dfae5b3e122a4ad12b6b97d35639cb7749 Miraielf mirai ua-wget
http://31.97.147.189/systemcl/x865b1f2a4aae9074691cb6f36abffe7c155844f670b8fcf1c9106ca60201217bf3 Mirai32-bit elf mirai Mozi
http://31.97.147.189/systemcl/x86_64970d48b9edbe3f7877701b695eec9e47f7f64409a951de973b4e40e72e0da785 Miraielf geofenced mirai ua-wget USA x86

Intelligence


File Origin
# of uploads :
2
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-11-21T18:03:00Z UTC
Last seen:
2025-11-22T00:46:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=d09af0c0-1900-0000-08fd-d12d080b0000 pid=2824 /usr/bin/sudo guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828 /tmp/sample.bin guuid=d09af0c0-1900-0000-08fd-d12d080b0000 pid=2824->guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828 execve guuid=a318ecc2-1900-0000-08fd-d12d0d0b0000 pid=2829 /usr/bin/curl net send-data guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=a318ecc2-1900-0000-08fd-d12d0d0b0000 pid=2829 execve guuid=0956afd7-1900-0000-08fd-d12d3f0b0000 pid=2879 /usr/bin/chmod guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=0956afd7-1900-0000-08fd-d12d3f0b0000 pid=2879 execve guuid=3eda07d8-1900-0000-08fd-d12d420b0000 pid=2882 /usr/bin/dash guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=3eda07d8-1900-0000-08fd-d12d420b0000 pid=2882 clone guuid=8ce913d8-1900-0000-08fd-d12d430b0000 pid=2883 /usr/bin/curl net send-data guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=8ce913d8-1900-0000-08fd-d12d430b0000 pid=2883 execve guuid=6cb68bec-1900-0000-08fd-d12d700b0000 pid=2928 /usr/bin/chmod guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=6cb68bec-1900-0000-08fd-d12d700b0000 pid=2928 execve guuid=8decd1ec-1900-0000-08fd-d12d720b0000 pid=2930 /usr/bin/dash guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=8decd1ec-1900-0000-08fd-d12d720b0000 pid=2930 clone guuid=4250e0ec-1900-0000-08fd-d12d730b0000 pid=2931 /usr/bin/curl net send-data guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=4250e0ec-1900-0000-08fd-d12d730b0000 pid=2931 execve guuid=3d262005-1a00-0000-08fd-d12da20b0000 pid=2978 /usr/bin/chmod guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=3d262005-1a00-0000-08fd-d12da20b0000 pid=2978 execve guuid=65ba7305-1a00-0000-08fd-d12da40b0000 pid=2980 /usr/bin/dash guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=65ba7305-1a00-0000-08fd-d12da40b0000 pid=2980 clone guuid=89897f05-1a00-0000-08fd-d12da60b0000 pid=2982 /usr/bin/curl net send-data guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=89897f05-1a00-0000-08fd-d12da60b0000 pid=2982 execve guuid=fe98621e-1a00-0000-08fd-d12dde0b0000 pid=3038 /usr/bin/chmod guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=fe98621e-1a00-0000-08fd-d12dde0b0000 pid=3038 execve guuid=dd24aa1e-1a00-0000-08fd-d12de00b0000 pid=3040 /usr/bin/dash guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=dd24aa1e-1a00-0000-08fd-d12de00b0000 pid=3040 clone guuid=7432c31e-1a00-0000-08fd-d12de10b0000 pid=3041 /usr/bin/curl net send-data guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=7432c31e-1a00-0000-08fd-d12de10b0000 pid=3041 execve guuid=c0ed1e38-1a00-0000-08fd-d12d1e0c0000 pid=3102 /usr/bin/chmod guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=c0ed1e38-1a00-0000-08fd-d12d1e0c0000 pid=3102 execve guuid=cf829238-1a00-0000-08fd-d12d1f0c0000 pid=3103 /usr/bin/dash guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=cf829238-1a00-0000-08fd-d12d1f0c0000 pid=3103 clone guuid=c2f19e38-1a00-0000-08fd-d12d200c0000 pid=3104 /usr/bin/curl net send-data guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=c2f19e38-1a00-0000-08fd-d12d200c0000 pid=3104 execve guuid=eef3fb4f-1a00-0000-08fd-d12d520c0000 pid=3154 /usr/bin/chmod guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=eef3fb4f-1a00-0000-08fd-d12d520c0000 pid=3154 execve guuid=68c94e50-1a00-0000-08fd-d12d540c0000 pid=3156 /usr/bin/dash guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=68c94e50-1a00-0000-08fd-d12d540c0000 pid=3156 clone guuid=360f5850-1a00-0000-08fd-d12d550c0000 pid=3157 /usr/bin/curl net send-data guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=360f5850-1a00-0000-08fd-d12d550c0000 pid=3157 execve guuid=ac974466-1a00-0000-08fd-d12d7c0c0000 pid=3196 /usr/bin/chmod guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=ac974466-1a00-0000-08fd-d12d7c0c0000 pid=3196 execve guuid=afacae66-1a00-0000-08fd-d12d7d0c0000 pid=3197 /usr/bin/dash guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=afacae66-1a00-0000-08fd-d12d7d0c0000 pid=3197 clone guuid=dc73ca66-1a00-0000-08fd-d12d7e0c0000 pid=3198 /usr/bin/curl net send-data guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=dc73ca66-1a00-0000-08fd-d12d7e0c0000 pid=3198 execve guuid=066f2e7d-1a00-0000-08fd-d12d990c0000 pid=3225 /usr/bin/chmod guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=066f2e7d-1a00-0000-08fd-d12d990c0000 pid=3225 execve guuid=2fbc787d-1a00-0000-08fd-d12d9a0c0000 pid=3226 /usr/bin/dash guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=2fbc787d-1a00-0000-08fd-d12d9a0c0000 pid=3226 clone guuid=8bf47e7d-1a00-0000-08fd-d12d9b0c0000 pid=3227 /usr/bin/curl net send-data guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=8bf47e7d-1a00-0000-08fd-d12d9b0c0000 pid=3227 execve guuid=41d3dc89-1a00-0000-08fd-d12da60c0000 pid=3238 /usr/bin/chmod guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=41d3dc89-1a00-0000-08fd-d12da60c0000 pid=3238 execve guuid=d0e36c8a-1a00-0000-08fd-d12da70c0000 pid=3239 /usr/bin/dash guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=d0e36c8a-1a00-0000-08fd-d12da70c0000 pid=3239 clone guuid=77bc7e8a-1a00-0000-08fd-d12da80c0000 pid=3240 /usr/bin/curl net send-data guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=77bc7e8a-1a00-0000-08fd-d12da80c0000 pid=3240 execve guuid=4d55d89a-1a00-0000-08fd-d12dbe0c0000 pid=3262 /usr/bin/chmod guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=4d55d89a-1a00-0000-08fd-d12dbe0c0000 pid=3262 execve guuid=0195479b-1a00-0000-08fd-d12dbf0c0000 pid=3263 /usr/bin/dash guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=0195479b-1a00-0000-08fd-d12dbf0c0000 pid=3263 clone guuid=5fcd569b-1a00-0000-08fd-d12dc00c0000 pid=3264 /usr/bin/curl net send-data guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=5fcd569b-1a00-0000-08fd-d12dc00c0000 pid=3264 execve guuid=e1741cae-1a00-0000-08fd-d12dd60c0000 pid=3286 /usr/bin/chmod guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=e1741cae-1a00-0000-08fd-d12dd60c0000 pid=3286 execve guuid=bb56c5ae-1a00-0000-08fd-d12dd70c0000 pid=3287 /usr/bin/dash guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=bb56c5ae-1a00-0000-08fd-d12dd70c0000 pid=3287 clone guuid=2fa3d1ae-1a00-0000-08fd-d12dd80c0000 pid=3288 /usr/bin/curl net send-data guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=2fa3d1ae-1a00-0000-08fd-d12dd80c0000 pid=3288 execve guuid=812e22c3-1a00-0000-08fd-d12d070d0000 pid=3335 /usr/bin/chmod guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=812e22c3-1a00-0000-08fd-d12d070d0000 pid=3335 execve guuid=6e6381c3-1a00-0000-08fd-d12d080d0000 pid=3336 /usr/bin/dash guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=6e6381c3-1a00-0000-08fd-d12d080d0000 pid=3336 clone guuid=cd238dc3-1a00-0000-08fd-d12d090d0000 pid=3337 /usr/bin/rm delete-file guuid=e6a89ec2-1900-0000-08fd-d12d0c0b0000 pid=2828->guuid=cd238dc3-1a00-0000-08fd-d12d090d0000 pid=3337 execve f1c78202-5927-5cc6-bd07-437634c15960 31.97.147.189:80 guuid=a318ecc2-1900-0000-08fd-d12d0d0b0000 pid=2829->f1c78202-5927-5cc6-bd07-437634c15960 send: 89B guuid=8ce913d8-1900-0000-08fd-d12d430b0000 pid=2883->f1c78202-5927-5cc6-bd07-437634c15960 send: 90B guuid=4250e0ec-1900-0000-08fd-d12d730b0000 pid=2931->f1c78202-5927-5cc6-bd07-437634c15960 send: 90B guuid=89897f05-1a00-0000-08fd-d12da60b0000 pid=2982->f1c78202-5927-5cc6-bd07-437634c15960 send: 90B guuid=7432c31e-1a00-0000-08fd-d12de10b0000 pid=3041->f1c78202-5927-5cc6-bd07-437634c15960 send: 90B guuid=c2f19e38-1a00-0000-08fd-d12d200c0000 pid=3104->f1c78202-5927-5cc6-bd07-437634c15960 send: 90B guuid=360f5850-1a00-0000-08fd-d12d550c0000 pid=3157->f1c78202-5927-5cc6-bd07-437634c15960 send: 90B guuid=dc73ca66-1a00-0000-08fd-d12d7e0c0000 pid=3198->f1c78202-5927-5cc6-bd07-437634c15960 send: 89B guuid=8bf47e7d-1a00-0000-08fd-d12d9b0c0000 pid=3227->f1c78202-5927-5cc6-bd07-437634c15960 send: 89B guuid=77bc7e8a-1a00-0000-08fd-d12da80c0000 pid=3240->f1c78202-5927-5cc6-bd07-437634c15960 send: 89B guuid=5fcd569b-1a00-0000-08fd-d12dc00c0000 pid=3264->f1c78202-5927-5cc6-bd07-437634c15960 send: 89B guuid=2fa3d1ae-1a00-0000-08fd-d12dd80c0000 pid=3288->f1c78202-5927-5cc6-bd07-437634c15960 send: 92B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-11-21 13:28:27 UTC
File Type:
Text (Shell)
AV detection:
16 of 38 (42.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 560ff3969aaeb7bd6d66c5adde827c20a1ae1745be67d570e2ed3b78ccb7d76f

(this sample)

  
Delivery method
Distributed via web download

Comments