MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5deab45dd3bb8b7db10e85e7a941b428edeb251f204be584992d14a245ff43d2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 5deab45dd3bb8b7db10e85e7a941b428edeb251f204be584992d14a245ff43d2
SHA3-384 hash: 25a2c162f12794bb8ddd0a3cd00fe53ae18138b0419a9ff47e069ff0c6822169722c4026cbd55f1c3ee5e6099e648a90
SHA1 hash: 9d046f42fb14be440a561827e8f3c87d716b37da
MD5 hash: 0599f734ecc5d30b8c22285722fae4e5
humanhash: saturn-oven-early-cold
File name:bins.sh
Download: download sample
Signature Mirai
File size:1'034 bytes
First seen:2025-10-19 20:41:17 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:nvoNQZNC4ifN+q+D+4+Etk+kl+/J3+C/+S+Vz+c+r/X:64E+q+D+4+E++kl+/h+E+S+N+c+L
TLSH T1A211E7CD1020A33A0C8CED6EB57242252553D5E666620B39B7C428325684A5CFCF8F8D
Magika shell
Reporter juroots
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://192.142.10.111/d/xd.x861565b1d1021e463b4405a5a73408f52039651c0b8ff17a6ded591aad2012e5ef Miraielf geofenced mirai opendir ua-wget USA x86
http://192.142.10.111/d/xd.mips1450edb85addb9d3b48f93b5350bf2fb22f980a569bf2400e6d1f0ed6125d790 Miraimirai opendir
http://192.142.10.111/d/xd.mpsla2d1925fc5c2e1c28ad5940c6ba68b8998cd4481c1ab909b29a4466333f7d974 Miraimirai opendir
http://192.142.10.111/d/xd.arm435ca810ac4e8c89c3f15e4ce14025bc8016ec51e651cefd837bd57dcedcec4c Miraimirai opendir
http://192.142.10.111/d/xd.arm5n/an/aopendir
http://192.142.10.111/d/xd.arm6668903f42b20252c70ffab1c3c4888af899b2fb1548e1ac0f8d4b66e5a8b249a Miraiarm elf geofenced mirai opendir ua-wget USA
http://192.142.10.111/d/xd.arm786dddfce5fd50817a1057781d87bfe7883978a06b4dd9b9e67e5559db253b358 Miraiarm elf geofenced mirai opendir ua-wget USA
http://192.142.10.111/d/xd.ppc0813a3d8b8a7697e751e2d42e35738ca7b37311f36439371547f8d5eeb4853b8 Miraielf geofenced mirai opendir PowerPC ua-wget USA
http://192.142.10.111/d/xd.m68ke6d33ead4aaa2a2bc31956b4a121b9ce3aaf81599528416d514a749ee2d9dd04 Miraielf geofenced m68k mirai opendir ua-wget USA
http://192.142.10.111/d/xd.sh4n/an/aopendir
http://192.142.10.111/d/xd.spcn/an/aopendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
CH CH
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-19T18:49:00Z UTC
Last seen:
2025-10-19T21:39:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=b697f20f-1b00-0000-34c8-39d5a50c0000 pid=3237 /usr/bin/sudo guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239 /tmp/sample.bin guuid=b697f20f-1b00-0000-34c8-39d5a50c0000 pid=3237->guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239 execve guuid=8c4a3914-1b00-0000-34c8-39d5aa0c0000 pid=3242 /usr/bin/rm guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=8c4a3914-1b00-0000-34c8-39d5aa0c0000 pid=3242 execve guuid=1d9aa414-1b00-0000-34c8-39d5ab0c0000 pid=3243 /usr/bin/killall guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=1d9aa414-1b00-0000-34c8-39d5ab0c0000 pid=3243 execve guuid=84bf3416-1b00-0000-34c8-39d5ae0c0000 pid=3246 /usr/bin/wget net send-data write-file guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=84bf3416-1b00-0000-34c8-39d5ae0c0000 pid=3246 execve guuid=ebddb41c-1b00-0000-34c8-39d5b80c0000 pid=3256 /usr/bin/chmod guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=ebddb41c-1b00-0000-34c8-39d5b80c0000 pid=3256 execve guuid=e1f4751d-1b00-0000-34c8-39d5b90c0000 pid=3257 /tmp/.x net guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=e1f4751d-1b00-0000-34c8-39d5b90c0000 pid=3257 execve guuid=c874aa1d-1b00-0000-34c8-39d5bb0c0000 pid=3259 /usr/bin/wget net send-data write-file guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=c874aa1d-1b00-0000-34c8-39d5bb0c0000 pid=3259 execve guuid=18364c25-1b00-0000-34c8-39d5c80c0000 pid=3272 /usr/bin/chmod guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=18364c25-1b00-0000-34c8-39d5c80c0000 pid=3272 execve guuid=5046f229-1b00-0000-34c8-39d5c90c0000 pid=3273 /usr/bin/bash guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=5046f229-1b00-0000-34c8-39d5c90c0000 pid=3273 clone guuid=9916072a-1b00-0000-34c8-39d5ca0c0000 pid=3274 /usr/bin/wget net send-data write-file guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=9916072a-1b00-0000-34c8-39d5ca0c0000 pid=3274 execve guuid=b1c4a632-1b00-0000-34c8-39d5dc0c0000 pid=3292 /usr/bin/chmod guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=b1c4a632-1b00-0000-34c8-39d5dc0c0000 pid=3292 execve guuid=feb4f132-1b00-0000-34c8-39d5dd0c0000 pid=3293 /usr/bin/bash guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=feb4f132-1b00-0000-34c8-39d5dd0c0000 pid=3293 clone guuid=0fe7fd32-1b00-0000-34c8-39d5df0c0000 pid=3295 /usr/bin/wget net send-data write-file guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=0fe7fd32-1b00-0000-34c8-39d5df0c0000 pid=3295 execve guuid=f1bf5339-1b00-0000-34c8-39d5ef0c0000 pid=3311 /usr/bin/chmod guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=f1bf5339-1b00-0000-34c8-39d5ef0c0000 pid=3311 execve guuid=4ec9a439-1b00-0000-34c8-39d5f10c0000 pid=3313 /usr/bin/bash guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=4ec9a439-1b00-0000-34c8-39d5f10c0000 pid=3313 clone guuid=f8a3ac39-1b00-0000-34c8-39d5f20c0000 pid=3314 /usr/bin/wget net send-data write-file guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=f8a3ac39-1b00-0000-34c8-39d5f20c0000 pid=3314 execve guuid=c5512c3f-1b00-0000-34c8-39d5030d0000 pid=3331 /usr/bin/chmod guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=c5512c3f-1b00-0000-34c8-39d5030d0000 pid=3331 execve guuid=779e7e3f-1b00-0000-34c8-39d5040d0000 pid=3332 /usr/bin/bash guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=779e7e3f-1b00-0000-34c8-39d5040d0000 pid=3332 clone guuid=28d8853f-1b00-0000-34c8-39d5050d0000 pid=3333 /usr/bin/wget net send-data write-file guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=28d8853f-1b00-0000-34c8-39d5050d0000 pid=3333 execve guuid=30315744-1b00-0000-34c8-39d5100d0000 pid=3344 /usr/bin/chmod guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=30315744-1b00-0000-34c8-39d5100d0000 pid=3344 execve guuid=34feae44-1b00-0000-34c8-39d5120d0000 pid=3346 /usr/bin/bash guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=34feae44-1b00-0000-34c8-39d5120d0000 pid=3346 clone guuid=6ff4b544-1b00-0000-34c8-39d5130d0000 pid=3347 /usr/bin/wget net send-data write-file guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=6ff4b544-1b00-0000-34c8-39d5130d0000 pid=3347 execve guuid=d3322a4a-1b00-0000-34c8-39d5210d0000 pid=3361 /usr/bin/chmod guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=d3322a4a-1b00-0000-34c8-39d5210d0000 pid=3361 execve guuid=9b1b8a4a-1b00-0000-34c8-39d5230d0000 pid=3363 /usr/bin/bash guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=9b1b8a4a-1b00-0000-34c8-39d5230d0000 pid=3363 clone guuid=44a99a4a-1b00-0000-34c8-39d5250d0000 pid=3365 /usr/bin/wget net send-data write-file guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=44a99a4a-1b00-0000-34c8-39d5250d0000 pid=3365 execve guuid=30565350-1b00-0000-34c8-39d5290d0000 pid=3369 /usr/bin/chmod guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=30565350-1b00-0000-34c8-39d5290d0000 pid=3369 execve guuid=1bbead50-1b00-0000-34c8-39d52a0d0000 pid=3370 /usr/bin/bash guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=1bbead50-1b00-0000-34c8-39d52a0d0000 pid=3370 clone guuid=fba9b650-1b00-0000-34c8-39d52b0d0000 pid=3371 /usr/bin/wget net send-data write-file guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=fba9b650-1b00-0000-34c8-39d52b0d0000 pid=3371 execve guuid=20cd8957-1b00-0000-34c8-39d52d0d0000 pid=3373 /usr/bin/chmod guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=20cd8957-1b00-0000-34c8-39d52d0d0000 pid=3373 execve guuid=a62d5658-1b00-0000-34c8-39d52e0d0000 pid=3374 /usr/bin/bash guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=a62d5658-1b00-0000-34c8-39d52e0d0000 pid=3374 clone guuid=24d06658-1b00-0000-34c8-39d52f0d0000 pid=3375 /usr/bin/wget net send-data write-file guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=24d06658-1b00-0000-34c8-39d52f0d0000 pid=3375 execve guuid=dc8c9860-1b00-0000-34c8-39d5320d0000 pid=3378 /usr/bin/chmod guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=dc8c9860-1b00-0000-34c8-39d5320d0000 pid=3378 execve guuid=d5382661-1b00-0000-34c8-39d5330d0000 pid=3379 /usr/bin/bash guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=d5382661-1b00-0000-34c8-39d5330d0000 pid=3379 clone guuid=724c3561-1b00-0000-34c8-39d5340d0000 pid=3380 /usr/bin/wget net send-data write-file guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=724c3561-1b00-0000-34c8-39d5340d0000 pid=3380 execve guuid=d3a12068-1b00-0000-34c8-39d5430d0000 pid=3395 /usr/bin/chmod guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=d3a12068-1b00-0000-34c8-39d5430d0000 pid=3395 execve guuid=5677a568-1b00-0000-34c8-39d5450d0000 pid=3397 /usr/bin/bash zombie guuid=8b7c5513-1b00-0000-34c8-39d5a70c0000 pid=3239->guuid=5677a568-1b00-0000-34c8-39d5450d0000 pid=3397 clone 731c8512-fd62-5662-bb47-58a1813c31ee 192.142.10.111:80 guuid=84bf3416-1b00-0000-34c8-39d5ae0c0000 pid=3246->731c8512-fd62-5662-bb47-58a1813c31ee send: 137B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e1f4751d-1b00-0000-34c8-39d5b90c0000 pid=3257->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=27ce701e-1b00-0000-34c8-39d5bc0c0000 pid=3260 /tmp/.x zombie guuid=e1f4751d-1b00-0000-34c8-39d5b90c0000 pid=3257->guuid=27ce701e-1b00-0000-34c8-39d5bc0c0000 pid=3260 clone guuid=0598751e-1b00-0000-34c8-39d5bd0c0000 pid=3261 /tmp/.x guuid=e1f4751d-1b00-0000-34c8-39d5b90c0000 pid=3257->guuid=0598751e-1b00-0000-34c8-39d5bd0c0000 pid=3261 clone guuid=f479791e-1b00-0000-34c8-39d5be0c0000 pid=3262 /tmp/.x net send-data zombie guuid=e1f4751d-1b00-0000-34c8-39d5b90c0000 pid=3257->guuid=f479791e-1b00-0000-34c8-39d5be0c0000 pid=3262 clone guuid=c874aa1d-1b00-0000-34c8-39d5bb0c0000 pid=3259->731c8512-fd62-5662-bb47-58a1813c31ee send: 138B guuid=f479791e-1b00-0000-34c8-39d5be0c0000 pid=3262->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con ef1f1ab0-3133-5707-94b0-7c71c9786164 192.142.10.111:9506 guuid=f479791e-1b00-0000-34c8-39d5be0c0000 pid=3262->ef1f1ab0-3133-5707-94b0-7c71c9786164 send: 9B guuid=2b09981e-1b00-0000-34c8-39d5bf0c0000 pid=3263 /tmp/.x guuid=f479791e-1b00-0000-34c8-39d5be0c0000 pid=3262->guuid=2b09981e-1b00-0000-34c8-39d5bf0c0000 pid=3263 clone guuid=8c359d1e-1b00-0000-34c8-39d5c00c0000 pid=3264 /tmp/.x guuid=f479791e-1b00-0000-34c8-39d5be0c0000 pid=3262->guuid=8c359d1e-1b00-0000-34c8-39d5c00c0000 pid=3264 clone guuid=167fa61e-1b00-0000-34c8-39d5c10c0000 pid=3265 /tmp/.x net net-scan send-data guuid=f479791e-1b00-0000-34c8-39d5be0c0000 pid=3262->guuid=167fa61e-1b00-0000-34c8-39d5c10c0000 pid=3265 clone guuid=167fa61e-1b00-0000-34c8-39d5c10c0000 pid=3265->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 576348a7-6ac6-549b-bba3-f5bc6680035d 94.120.212.251:23 guuid=167fa61e-1b00-0000-34c8-39d5c10c0000 pid=3265->576348a7-6ac6-549b-bba3-f5bc6680035d send: 40B dc6f1a03-4247-5484-8914-ac1364df755a 147.127.159.237:23 guuid=167fa61e-1b00-0000-34c8-39d5c10c0000 pid=3265->dc6f1a03-4247-5484-8914-ac1364df755a send: 40B guuid=167fa61e-1b00-0000-34c8-39d5c10c0000 pid=3265|send-data send-data to 4097 IP addresses review logs to see them all guuid=167fa61e-1b00-0000-34c8-39d5c10c0000 pid=3265->guuid=167fa61e-1b00-0000-34c8-39d5c10c0000 pid=3265|send-data send guuid=9916072a-1b00-0000-34c8-39d5ca0c0000 pid=3274->731c8512-fd62-5662-bb47-58a1813c31ee send: 138B guuid=0fe7fd32-1b00-0000-34c8-39d5df0c0000 pid=3295->731c8512-fd62-5662-bb47-58a1813c31ee send: 137B guuid=f8a3ac39-1b00-0000-34c8-39d5f20c0000 pid=3314->731c8512-fd62-5662-bb47-58a1813c31ee send: 138B guuid=28d8853f-1b00-0000-34c8-39d5050d0000 pid=3333->731c8512-fd62-5662-bb47-58a1813c31ee send: 138B guuid=6ff4b544-1b00-0000-34c8-39d5130d0000 pid=3347->731c8512-fd62-5662-bb47-58a1813c31ee send: 138B guuid=44a99a4a-1b00-0000-34c8-39d5250d0000 pid=3365->731c8512-fd62-5662-bb47-58a1813c31ee send: 137B guuid=fba9b650-1b00-0000-34c8-39d52b0d0000 pid=3371->731c8512-fd62-5662-bb47-58a1813c31ee send: 138B guuid=24d06658-1b00-0000-34c8-39d52f0d0000 pid=3375->731c8512-fd62-5662-bb47-58a1813c31ee send: 137B guuid=724c3561-1b00-0000-34c8-39d5340d0000 pid=3380->731c8512-fd62-5662-bb47-58a1813c31ee send: 137B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-10-19 20:45:54 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Reads system network configuration
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (20294) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Mirai

sh 5deab45dd3bb8b7db10e85e7a941b428edeb251f204be584992d14a245ff43d2

(this sample)

Comments