MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 59b532d83e376155728094967532f0e9ed02cf39f107b706fa4a9887c337adc4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 59b532d83e376155728094967532f0e9ed02cf39f107b706fa4a9887c337adc4
SHA3-384 hash: d205f5e3c18cc53c5843b6c699e19d03d62427a4f1345e02c2f62eb8467f63cff1f8acc29a560bdfc28af8bcbde9fed6
SHA1 hash: c998f5b41f80d7c8295b22bb4b04f342c1bf20b3
MD5 hash: 7e8cbf7be9c6933d0bf02e7f0c07b447
humanhash: eight-pennsylvania-hot-delta
File name:cn
Download: download sample
Signature Mirai
File size:540 bytes
First seen:2025-08-01 12:39:55 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:XVTNX1cm2Xhe/LeXC/pXL/6NIbMXve/H7XI:XVTF1cjhe/LIC/5L/6NIbWve/zI
TLSH T103F0C28AA122788242ACED7D733765CCA412C3CC682F67DCEEC188798158D65F05CA24
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://66.63.187.141/mips7124a65bf24f9edba23f44feeace7c17c40c84a3977c2220d6742e188928612e Mirai32-bit elf gafgyt mirai Mozi
http://66.63.187.141/mpsl2d1cf20f3c60d797308489012c7552b1db022dfbfcf8bb1c71fe360290f597f2 Miraielf mirai ua-wget
http://66.63.187.141/armc7ce30048cff8cd281aae097b739ac1ec446aaa0eb48a746a6f03420e4b28076 Gafgyt32-bit elf gafgyt Mozi
http://66.63.187.141/arm52153f7f0232ac7e9fb23ee4c50aabb18c7f32ff2653f213796fb55b3229aabf4 Miraielf gafgyt mirai ua-wget
http://66.63.187.141/arm66062592a30f707d9cc1d5ba80dd76140736d28829df170f53a710bf182b83ce9 Miraielf mirai ua-wget
http://66.63.187.141/arm78caac9e05312ee38e05a89b23e920a5901c4c88736db0b345e5184dbef7ce50b Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
25
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=d21e4271-1900-0000-cc0e-15f5f4060000 pid=1780 /usr/bin/sudo guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784 /tmp/sample.bin guuid=d21e4271-1900-0000-cc0e-15f5f4060000 pid=1780->guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784 execve guuid=344dcf73-1900-0000-cc0e-15f5fa060000 pid=1786 /usr/bin/wget net send-data write-file guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=344dcf73-1900-0000-cc0e-15f5fa060000 pid=1786 execve guuid=7be2f682-1900-0000-cc0e-15f518070000 pid=1816 /usr/bin/chmod guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=7be2f682-1900-0000-cc0e-15f518070000 pid=1816 execve guuid=40d45983-1900-0000-cc0e-15f51a070000 pid=1818 /usr/bin/dash guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=40d45983-1900-0000-cc0e-15f51a070000 pid=1818 clone guuid=53191184-1900-0000-cc0e-15f51d070000 pid=1821 /usr/bin/rm delete-file guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=53191184-1900-0000-cc0e-15f51d070000 pid=1821 execve guuid=f2b85384-1900-0000-cc0e-15f51e070000 pid=1822 /usr/bin/rm guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=f2b85384-1900-0000-cc0e-15f51e070000 pid=1822 execve guuid=33db8f84-1900-0000-cc0e-15f51f070000 pid=1823 /usr/bin/wget net send-data write-file guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=33db8f84-1900-0000-cc0e-15f51f070000 pid=1823 execve guuid=17356191-1900-0000-cc0e-15f538070000 pid=1848 /usr/bin/chmod guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=17356191-1900-0000-cc0e-15f538070000 pid=1848 execve guuid=5234a191-1900-0000-cc0e-15f53a070000 pid=1850 /usr/bin/dash guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=5234a191-1900-0000-cc0e-15f53a070000 pid=1850 clone guuid=03362192-1900-0000-cc0e-15f53e070000 pid=1854 /usr/bin/rm delete-file guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=03362192-1900-0000-cc0e-15f53e070000 pid=1854 execve guuid=16da6092-1900-0000-cc0e-15f540070000 pid=1856 /usr/bin/rm guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=16da6092-1900-0000-cc0e-15f540070000 pid=1856 execve guuid=08419b92-1900-0000-cc0e-15f542070000 pid=1858 /usr/bin/wget net send-data write-file guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=08419b92-1900-0000-cc0e-15f542070000 pid=1858 execve guuid=87f0c39e-1900-0000-cc0e-15f559070000 pid=1881 /usr/bin/chmod guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=87f0c39e-1900-0000-cc0e-15f559070000 pid=1881 execve guuid=a1f3129f-1900-0000-cc0e-15f55a070000 pid=1882 /usr/bin/dash guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=a1f3129f-1900-0000-cc0e-15f55a070000 pid=1882 clone guuid=d1fbb49f-1900-0000-cc0e-15f55d070000 pid=1885 /usr/bin/rm delete-file guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=d1fbb49f-1900-0000-cc0e-15f55d070000 pid=1885 execve guuid=6b1e07a0-1900-0000-cc0e-15f55f070000 pid=1887 /usr/bin/rm guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=6b1e07a0-1900-0000-cc0e-15f55f070000 pid=1887 execve guuid=bd0d62a0-1900-0000-cc0e-15f561070000 pid=1889 /usr/bin/wget net send-data write-file guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=bd0d62a0-1900-0000-cc0e-15f561070000 pid=1889 execve guuid=4ed5b5ac-1900-0000-cc0e-15f57b070000 pid=1915 /usr/bin/chmod guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=4ed5b5ac-1900-0000-cc0e-15f57b070000 pid=1915 execve guuid=5d30f3ac-1900-0000-cc0e-15f57c070000 pid=1916 /usr/bin/dash guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=5d30f3ac-1900-0000-cc0e-15f57c070000 pid=1916 clone guuid=108da7ad-1900-0000-cc0e-15f580070000 pid=1920 /usr/bin/rm delete-file guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=108da7ad-1900-0000-cc0e-15f580070000 pid=1920 execve guuid=81131dae-1900-0000-cc0e-15f582070000 pid=1922 /usr/bin/rm guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=81131dae-1900-0000-cc0e-15f582070000 pid=1922 execve guuid=820962ae-1900-0000-cc0e-15f584070000 pid=1924 /usr/bin/wget net send-data write-file guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=820962ae-1900-0000-cc0e-15f584070000 pid=1924 execve guuid=ab8fedba-1900-0000-cc0e-15f59f070000 pid=1951 /usr/bin/chmod guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=ab8fedba-1900-0000-cc0e-15f59f070000 pid=1951 execve guuid=d87b48bb-1900-0000-cc0e-15f5a1070000 pid=1953 /usr/bin/dash guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=d87b48bb-1900-0000-cc0e-15f5a1070000 pid=1953 clone guuid=8f1cf1bb-1900-0000-cc0e-15f5a4070000 pid=1956 /usr/bin/rm delete-file guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=8f1cf1bb-1900-0000-cc0e-15f5a4070000 pid=1956 execve guuid=cb6a47bc-1900-0000-cc0e-15f5a7070000 pid=1959 /usr/bin/rm guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=cb6a47bc-1900-0000-cc0e-15f5a7070000 pid=1959 execve guuid=882ca0bc-1900-0000-cc0e-15f5a9070000 pid=1961 /usr/bin/wget net send-data write-file guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=882ca0bc-1900-0000-cc0e-15f5a9070000 pid=1961 execve guuid=21479eca-1900-0000-cc0e-15f5c1070000 pid=1985 /usr/bin/chmod guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=21479eca-1900-0000-cc0e-15f5c1070000 pid=1985 execve guuid=f124d7ca-1900-0000-cc0e-15f5c3070000 pid=1987 /usr/bin/dash guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=f124d7ca-1900-0000-cc0e-15f5c3070000 pid=1987 clone guuid=388e3ecc-1900-0000-cc0e-15f5ca070000 pid=1994 /usr/bin/rm delete-file guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=388e3ecc-1900-0000-cc0e-15f5ca070000 pid=1994 execve guuid=a30e82cc-1900-0000-cc0e-15f5cb070000 pid=1995 /usr/bin/rm guuid=7f306673-1900-0000-cc0e-15f5f8060000 pid=1784->guuid=a30e82cc-1900-0000-cc0e-15f5cb070000 pid=1995 execve a4f1e28a-5799-5623-8429-fc4b4fdc9ca8 66.63.187.141:80 guuid=344dcf73-1900-0000-cc0e-15f5fa060000 pid=1786->a4f1e28a-5799-5623-8429-fc4b4fdc9ca8 send: 132B guuid=33db8f84-1900-0000-cc0e-15f51f070000 pid=1823->a4f1e28a-5799-5623-8429-fc4b4fdc9ca8 send: 132B guuid=08419b92-1900-0000-cc0e-15f542070000 pid=1858->a4f1e28a-5799-5623-8429-fc4b4fdc9ca8 send: 131B guuid=bd0d62a0-1900-0000-cc0e-15f561070000 pid=1889->a4f1e28a-5799-5623-8429-fc4b4fdc9ca8 send: 132B guuid=820962ae-1900-0000-cc0e-15f584070000 pid=1924->a4f1e28a-5799-5623-8429-fc4b4fdc9ca8 send: 132B guuid=882ca0bc-1900-0000-cc0e-15f5a9070000 pid=1961->a4f1e28a-5799-5623-8429-fc4b4fdc9ca8 send: 132B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-08-01 12:32:18 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 59b532d83e376155728094967532f0e9ed02cf39f107b706fa4a9887c337adc4

(this sample)

  
Delivery method
Distributed via web download

Comments