MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5bfd06796042180974d845a4f02101dedbb2649af20493895f6d48c010d6291c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 5bfd06796042180974d845a4f02101dedbb2649af20493895f6d48c010d6291c
SHA3-384 hash: f291e45c6776a52bedb69e1149ef6f9da74da5116af8ebea58e72059c3daa6d88d8567179e16280ede4ddbc1f9a10f7c
SHA1 hash: 8f185439ff0a9d4fb13ffd4e01d25f7f76268378
MD5 hash: f6eadf5b3abf558056c1093669983b2a
humanhash: vegan-fifteen-lithium-floor
File name:wget.sh
Download: download sample
Signature Mirai
File size:822 bytes
First seen:2025-11-23 10:10:29 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:yhGYrNIl5Z0LKB+OF+jMuTtjiSOZsteA7Vn:bYrNI7wKB+I+jzT5il6teA5n
TLSH T1740133DEF27162A206848DA5B0694864A534F3D833704B1ADCD604FAC4E574831B7E6F
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.107.233.38/systemcl/arm3e98eef752fb14582bfd0f70e00ae5f1b2e7ccb06b32597053c6ad8f0e591dae Miraiarm elf geofenced mirai ua-wget USA
http://38.107.233.38/systemcl/arm515c555f6d2014a41eb89f2779f43d1fc11677f501a3219cd3aa72bd0619a2849 Miraiarm elf geofenced mirai ua-wget USA
http://38.107.233.38/systemcl/arm6dfd02ed59c95575642af97a5a34c18ec7be4a61872e339720bba3286d6dbc80d Miraiarm elf geofenced mirai ua-wget USA
http://38.107.233.38/systemcl/arm776f40915e3bbfcd021903f45af774295d1781c327addbcabb3b5bd35da28ecb6 Miraiarm elf geofenced mirai ua-wget USA
http://38.107.233.38/systemcl/m68k452a0c93f439b4eeb230d8a3b2b01934b286283bdcc509cc56f09734f1b667ed Miraielf geofenced m68k mirai ua-wget USA
http://38.107.233.38/systemcl/mipsa5357cb8f6566613be9393a2def399b617ef91c2bc5ead8b8c1ff0f50d3f8dd5 Miraielf geofenced mips mirai ua-wget USA
http://38.107.233.38/systemcl/mpsla8e6f02362f973adda0cf4dcbc1c5c3809ee7477a7967287893457b8c5eb02b1 Miraielf geofenced mips mirai ua-wget USA
http://38.107.233.38/systemcl/ppcc3f7cf4b69be7bcc3f70465622a093198c73174902d8dd8dfde516f161ba4569 Miraielf geofenced mirai PowerPC ua-wget USA
http://38.107.233.38/systemcl/sh4n/an/aelf ua-wget
http://38.107.233.38/systemcl/spcn/an/aelf ua-wget
http://38.107.233.38/systemcl/x866f83f9621bd8b0e62a71359b184969f147b0046328455d84a8f20aa1a7ad0fae Miraielf geofenced mirai ua-wget USA x86
http://38.107.233.38/systemcl/x86_646f83f9621bd8b0e62a71359b184969f147b0046328455d84a8f20aa1a7ad0fae Miraielf geofenced mirai ua-wget USA x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-11-23T00:34:00Z UTC
Last seen:
2025-11-23T06:18:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=71de1932-1f00-0000-dcb1-9286650a0000 pid=2661 /usr/bin/sudo guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669 /tmp/sample.bin guuid=71de1932-1f00-0000-dcb1-9286650a0000 pid=2661->guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669 execve guuid=114f2f34-1f00-0000-dcb1-92866f0a0000 pid=2671 /usr/bin/wget net send-data write-file guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=114f2f34-1f00-0000-dcb1-92866f0a0000 pid=2671 execve guuid=a0e6f64d-1f00-0000-dcb1-9286ac0a0000 pid=2732 /usr/bin/chmod guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=a0e6f64d-1f00-0000-dcb1-9286ac0a0000 pid=2732 execve guuid=697c384e-1f00-0000-dcb1-9286ae0a0000 pid=2734 /usr/bin/dash guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=697c384e-1f00-0000-dcb1-9286ae0a0000 pid=2734 clone guuid=9d85d64e-1f00-0000-dcb1-9286b20a0000 pid=2738 /usr/bin/wget net send-data write-file guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=9d85d64e-1f00-0000-dcb1-9286b20a0000 pid=2738 execve guuid=771f9165-1f00-0000-dcb1-9286d60a0000 pid=2774 /usr/bin/chmod guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=771f9165-1f00-0000-dcb1-9286d60a0000 pid=2774 execve guuid=58c0eb65-1f00-0000-dcb1-9286d80a0000 pid=2776 /usr/bin/dash guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=58c0eb65-1f00-0000-dcb1-9286d80a0000 pid=2776 clone guuid=c326ec66-1f00-0000-dcb1-9286da0a0000 pid=2778 /usr/bin/wget net send-data write-file guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=c326ec66-1f00-0000-dcb1-9286da0a0000 pid=2778 execve guuid=b3204186-1f00-0000-dcb1-92860b0b0000 pid=2827 /usr/bin/chmod guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=b3204186-1f00-0000-dcb1-92860b0b0000 pid=2827 execve guuid=09348e86-1f00-0000-dcb1-92860c0b0000 pid=2828 /usr/bin/dash guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=09348e86-1f00-0000-dcb1-92860c0b0000 pid=2828 clone guuid=28615387-1f00-0000-dcb1-92860f0b0000 pid=2831 /usr/bin/wget net send-data write-file guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=28615387-1f00-0000-dcb1-92860f0b0000 pid=2831 execve guuid=cf05c3a5-1f00-0000-dcb1-9286590b0000 pid=2905 /usr/bin/chmod guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=cf05c3a5-1f00-0000-dcb1-9286590b0000 pid=2905 execve guuid=078201a6-1f00-0000-dcb1-92865a0b0000 pid=2906 /usr/bin/dash guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=078201a6-1f00-0000-dcb1-92865a0b0000 pid=2906 clone guuid=f4599da6-1f00-0000-dcb1-92865c0b0000 pid=2908 /usr/bin/wget net send-data write-file guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=f4599da6-1f00-0000-dcb1-92865c0b0000 pid=2908 execve guuid=55e49ec5-1f00-0000-dcb1-92868b0b0000 pid=2955 /usr/bin/chmod guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=55e49ec5-1f00-0000-dcb1-92868b0b0000 pid=2955 execve guuid=becdefc5-1f00-0000-dcb1-92868c0b0000 pid=2956 /usr/bin/dash guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=becdefc5-1f00-0000-dcb1-92868c0b0000 pid=2956 clone guuid=41b6dac6-1f00-0000-dcb1-92868e0b0000 pid=2958 /usr/bin/wget net send-data write-file guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=41b6dac6-1f00-0000-dcb1-92868e0b0000 pid=2958 execve guuid=db0a6ae6-1f00-0000-dcb1-9286d30b0000 pid=3027 /usr/bin/chmod guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=db0a6ae6-1f00-0000-dcb1-9286d30b0000 pid=3027 execve guuid=0719c1e6-1f00-0000-dcb1-9286d40b0000 pid=3028 /usr/bin/dash guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=0719c1e6-1f00-0000-dcb1-9286d40b0000 pid=3028 clone guuid=7b5195e7-1f00-0000-dcb1-9286d60b0000 pid=3030 /usr/bin/wget net send-data write-file guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=7b5195e7-1f00-0000-dcb1-9286d60b0000 pid=3030 execve guuid=c7fa2f08-2000-0000-dcb1-9286260c0000 pid=3110 /usr/bin/chmod guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=c7fa2f08-2000-0000-dcb1-9286260c0000 pid=3110 execve guuid=ed977c08-2000-0000-dcb1-9286280c0000 pid=3112 /usr/bin/dash guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=ed977c08-2000-0000-dcb1-9286280c0000 pid=3112 clone guuid=ff5f5409-2000-0000-dcb1-92862c0c0000 pid=3116 /usr/bin/wget net send-data write-file guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=ff5f5409-2000-0000-dcb1-92862c0c0000 pid=3116 execve guuid=c598ce20-2000-0000-dcb1-9286630c0000 pid=3171 /usr/bin/chmod guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=c598ce20-2000-0000-dcb1-9286630c0000 pid=3171 execve guuid=b9ba0f21-2000-0000-dcb1-9286640c0000 pid=3172 /usr/bin/dash guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=b9ba0f21-2000-0000-dcb1-9286640c0000 pid=3172 clone guuid=81b4df21-2000-0000-dcb1-9286670c0000 pid=3175 /usr/bin/wget net send-data guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=81b4df21-2000-0000-dcb1-9286670c0000 pid=3175 execve guuid=ff788831-2000-0000-dcb1-9286860c0000 pid=3206 /usr/bin/chmod guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=ff788831-2000-0000-dcb1-9286860c0000 pid=3206 execve guuid=4395ea31-2000-0000-dcb1-9286870c0000 pid=3207 /usr/bin/dash guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=4395ea31-2000-0000-dcb1-9286870c0000 pid=3207 clone guuid=76fff531-2000-0000-dcb1-9286880c0000 pid=3208 /usr/bin/wget net send-data guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=76fff531-2000-0000-dcb1-9286880c0000 pid=3208 execve guuid=2412d841-2000-0000-dcb1-9286890c0000 pid=3209 /usr/bin/chmod guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=2412d841-2000-0000-dcb1-9286890c0000 pid=3209 execve guuid=e1733042-2000-0000-dcb1-92868b0c0000 pid=3211 /usr/bin/dash guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=e1733042-2000-0000-dcb1-92868b0c0000 pid=3211 clone guuid=a30e3f42-2000-0000-dcb1-92868c0c0000 pid=3212 /usr/bin/wget net send-data write-file guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=a30e3f42-2000-0000-dcb1-92868c0c0000 pid=3212 execve guuid=df1d1c5a-2000-0000-dcb1-9286b00c0000 pid=3248 /usr/bin/chmod guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=df1d1c5a-2000-0000-dcb1-9286b00c0000 pid=3248 execve guuid=67e6715a-2000-0000-dcb1-9286b10c0000 pid=3249 /home/sandbox/x86 net guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=67e6715a-2000-0000-dcb1-9286b10c0000 pid=3249 execve guuid=8eb1e778-2000-0000-dcb1-9286b40c0000 pid=3252 /usr/bin/wget net send-data write-file guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=8eb1e778-2000-0000-dcb1-9286b40c0000 pid=3252 execve guuid=1076678f-2000-0000-dcb1-9286d20c0000 pid=3282 /usr/bin/chmod guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=1076678f-2000-0000-dcb1-9286d20c0000 pid=3282 execve guuid=53dfac8f-2000-0000-dcb1-9286d30c0000 pid=3283 /home/sandbox/x86_64 net guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=53dfac8f-2000-0000-dcb1-9286d30c0000 pid=3283 execve guuid=833158b1-2000-0000-dcb1-9286140d0000 pid=3348 /usr/bin/rm delete-file guuid=7150f133-1f00-0000-dcb1-92866d0a0000 pid=2669->guuid=833158b1-2000-0000-dcb1-9286140d0000 pid=3348 execve 9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 38.107.233.38:80 guuid=114f2f34-1f00-0000-dcb1-92866f0a0000 pid=2671->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 140B guuid=9d85d64e-1f00-0000-dcb1-9286b20a0000 pid=2738->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 141B guuid=c326ec66-1f00-0000-dcb1-9286da0a0000 pid=2778->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 141B guuid=28615387-1f00-0000-dcb1-92860f0b0000 pid=2831->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 141B guuid=f4599da6-1f00-0000-dcb1-92865c0b0000 pid=2908->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 141B guuid=41b6dac6-1f00-0000-dcb1-92868e0b0000 pid=2958->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 141B guuid=7b5195e7-1f00-0000-dcb1-9286d60b0000 pid=3030->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 141B guuid=ff5f5409-2000-0000-dcb1-92862c0c0000 pid=3116->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 140B guuid=81b4df21-2000-0000-dcb1-9286670c0000 pid=3175->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 140B guuid=76fff531-2000-0000-dcb1-9286880c0000 pid=3208->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 140B guuid=a30e3f42-2000-0000-dcb1-92868c0c0000 pid=3212->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 140B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=67e6715a-2000-0000-dcb1-9286b10c0000 pid=3249->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f7e5d678-2000-0000-dcb1-9286b20c0000 pid=3250 /home/sandbox/x86 guuid=67e6715a-2000-0000-dcb1-9286b10c0000 pid=3249->guuid=f7e5d678-2000-0000-dcb1-9286b20c0000 pid=3250 clone guuid=fcf7dc78-2000-0000-dcb1-9286b30c0000 pid=3251 /home/sandbox/x86 dns net send-data zombie guuid=67e6715a-2000-0000-dcb1-9286b10c0000 pid=3249->guuid=fcf7dc78-2000-0000-dcb1-9286b30c0000 pid=3251 clone guuid=fcf7dc78-2000-0000-dcb1-9286b30c0000 pid=3251->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 42B 92baddd7-8a81-534e-9407-4c1f931774f6 ahahahahahajs.unproxy.st:9772 guuid=fcf7dc78-2000-0000-dcb1-9286b30c0000 pid=3251->92baddd7-8a81-534e-9407-4c1f931774f6 send: 41B guuid=8eb1e778-2000-0000-dcb1-9286b40c0000 pid=3252->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 143B guuid=53dfac8f-2000-0000-dcb1-9286d30c0000 pid=3283->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d0f64bb1-2000-0000-dcb1-9286120d0000 pid=3346 /home/sandbox/x86_64 zombie guuid=53dfac8f-2000-0000-dcb1-9286d30c0000 pid=3283->guuid=d0f64bb1-2000-0000-dcb1-9286120d0000 pid=3346 clone guuid=e30551b1-2000-0000-dcb1-9286130d0000 pid=3347 /home/sandbox/x86_64 dns net send-data zombie guuid=53dfac8f-2000-0000-dcb1-9286d30c0000 pid=3283->guuid=e30551b1-2000-0000-dcb1-9286130d0000 pid=3347 clone guuid=e30551b1-2000-0000-dcb1-9286130d0000 pid=3347->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 42B guuid=e30551b1-2000-0000-dcb1-9286130d0000 pid=3347->92baddd7-8a81-534e-9407-4c1f931774f6 send: 46B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-11-23 05:29:03 UTC
File Type:
Text (Shell)
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5bfd06796042180974d845a4f02101dedbb2649af20493895f6d48c010d6291c

(this sample)

  
Delivery method
Distributed via web download

Comments