MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 63fc686a2c9ebb524c0fa6c10a6266741b8dbbd219afd6b551f5cfa6fd01e3d2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 63fc686a2c9ebb524c0fa6c10a6266741b8dbbd219afd6b551f5cfa6fd01e3d2
SHA3-384 hash: b0034472523b4ea3b796ec641705b5f84fb722c0433ab026fbc080900ff345a57eb901e85981d15a736117f9999b2e8b
SHA1 hash: 62cd788732b5ac3ecbe9a3610366c3791ecc7fd4
MD5 hash: 1c9dbb9d00a37397e292ad86de0e8000
humanhash: single-hot-colorado-ack
File name:w.sh
Download: download sample
Signature Mirai
File size:1'374 bytes
First seen:2025-10-04 13:41:17 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:qUvD6xUKUvDucArEUKUvDoNI+3BEAUKUvDxTKRiHUKUvDGNZIqUKUvDpQiUKUvD2:X2ENI6mpKVqN+7F2KcKBMJwalFk3guHR
TLSH T1CD2160FF03558153885DCFC1306A8614A28986E3645C4BF9ABDE8C767E84ED9EC42E1D
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.70.174/00101010101001/morte.arm92018fdead346046615dfc992fb7c6c84340f9f05f4c2a98906879ba19d9d404 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.arm5c89794c5ab693e93db164f0d4523b13934216038cd19ca0365a728ad62d5e3b1 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.arm65803b854959a53e11c8674e88f4922c99549406f23268af4a9c019dfd7d7423f Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.arm7bf45d7db954ae16aa60b9dc7a99341525c9ef9afe154eb7f433ca4a37e1c5e13 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.m68k2f3fbe56d018982fc668c68142ba7c6543650b0269e99384ae6b2ee6bf6d61de Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.mips01bcf55b2cdb1b8242e2aee4223d8b7796f388bf866a54cb554732b89497b15c Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.mpsle8360f4a9be84d5c3c03c774b785e3f9e66a5354dc4b002bf337c2f4f5e4d593 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.ppc22a4b8f57d576892149e04092dfe249438d28a952a7a697030361d94d0a038a5 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.sh4608c89ba1d6caa1cdf1f2fa75d6a6ca259da286bb268495121f8e25d7c9ceef4 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.spc617fc91098b7ff2ed40cfc855ef7cdb9679472a4732601455110e0e62b51a23d Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.x8673d3e88abf499c1f5c15baee9d2a3e79c58a76cec9ce41b379552964270cc787 Miraielf mirai ua-wget
http://196.251.70.174/00101010101001/morte.x86_64a9607723c7ee84e7ad4f75738141c805f73783c72b670da534cb74072911783f Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
text
First seen:
2025-10-04T13:10:00Z UTC
Last seen:
2025-10-04T15:50:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=5b96bbf9-1c00-0000-7e42-9fe1f40b0000 pid=3060 /usr/bin/sudo guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064 /tmp/sample.bin guuid=5b96bbf9-1c00-0000-7e42-9fe1f40b0000 pid=3060->guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064 execve guuid=aef8dafb-1c00-0000-7e42-9fe1f90b0000 pid=3065 /usr/bin/busybox net send-data write-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=aef8dafb-1c00-0000-7e42-9fe1f90b0000 pid=3065 execve guuid=b01f2dff-1c00-0000-7e42-9fe1fa0b0000 pid=3066 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=b01f2dff-1c00-0000-7e42-9fe1fa0b0000 pid=3066 execve guuid=021782ff-1c00-0000-7e42-9fe1fb0b0000 pid=3067 /usr/bin/dash guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=021782ff-1c00-0000-7e42-9fe1fb0b0000 pid=3067 clone guuid=0ab82f00-1d00-0000-7e42-9fe1fd0b0000 pid=3069 /usr/bin/busybox net send-data write-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=0ab82f00-1d00-0000-7e42-9fe1fd0b0000 pid=3069 execve guuid=2b202603-1d00-0000-7e42-9fe1fe0b0000 pid=3070 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=2b202603-1d00-0000-7e42-9fe1fe0b0000 pid=3070 execve guuid=ff79bc03-1d00-0000-7e42-9fe1ff0b0000 pid=3071 /usr/bin/dash guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=ff79bc03-1d00-0000-7e42-9fe1ff0b0000 pid=3071 clone guuid=87be3f04-1d00-0000-7e42-9fe1010c0000 pid=3073 /usr/bin/busybox net send-data write-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=87be3f04-1d00-0000-7e42-9fe1010c0000 pid=3073 execve guuid=9b8e9407-1d00-0000-7e42-9fe1060c0000 pid=3078 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=9b8e9407-1d00-0000-7e42-9fe1060c0000 pid=3078 execve guuid=59daf807-1d00-0000-7e42-9fe1080c0000 pid=3080 /usr/bin/dash guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=59daf807-1d00-0000-7e42-9fe1080c0000 pid=3080 clone guuid=08f1ac08-1d00-0000-7e42-9fe10b0c0000 pid=3083 /usr/bin/busybox net send-data write-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=08f1ac08-1d00-0000-7e42-9fe10b0c0000 pid=3083 execve guuid=b444130c-1d00-0000-7e42-9fe10f0c0000 pid=3087 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=b444130c-1d00-0000-7e42-9fe10f0c0000 pid=3087 execve guuid=9a1e5e0c-1d00-0000-7e42-9fe1100c0000 pid=3088 /usr/bin/dash guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=9a1e5e0c-1d00-0000-7e42-9fe1100c0000 pid=3088 clone guuid=6600160d-1d00-0000-7e42-9fe1120c0000 pid=3090 /usr/bin/busybox net send-data write-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=6600160d-1d00-0000-7e42-9fe1120c0000 pid=3090 execve guuid=c8066915-1d00-0000-7e42-9fe1190c0000 pid=3097 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=c8066915-1d00-0000-7e42-9fe1190c0000 pid=3097 execve guuid=4606bc15-1d00-0000-7e42-9fe11a0c0000 pid=3098 /usr/bin/dash guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=4606bc15-1d00-0000-7e42-9fe11a0c0000 pid=3098 clone guuid=36a69e16-1d00-0000-7e42-9fe11c0c0000 pid=3100 /usr/bin/busybox net send-data write-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=36a69e16-1d00-0000-7e42-9fe11c0c0000 pid=3100 execve guuid=e266d119-1d00-0000-7e42-9fe1230c0000 pid=3107 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=e266d119-1d00-0000-7e42-9fe1230c0000 pid=3107 execve guuid=8da0111a-1d00-0000-7e42-9fe1250c0000 pid=3109 /usr/bin/dash guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=8da0111a-1d00-0000-7e42-9fe1250c0000 pid=3109 clone guuid=431c9c1a-1d00-0000-7e42-9fe1280c0000 pid=3112 /usr/bin/busybox net send-data write-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=431c9c1a-1d00-0000-7e42-9fe1280c0000 pid=3112 execve guuid=cfb7dd1d-1d00-0000-7e42-9fe12f0c0000 pid=3119 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=cfb7dd1d-1d00-0000-7e42-9fe12f0c0000 pid=3119 execve guuid=16fd4f1e-1d00-0000-7e42-9fe1310c0000 pid=3121 /usr/bin/dash guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=16fd4f1e-1d00-0000-7e42-9fe1310c0000 pid=3121 clone guuid=23bc251f-1d00-0000-7e42-9fe1340c0000 pid=3124 /usr/bin/busybox net send-data guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=23bc251f-1d00-0000-7e42-9fe1340c0000 pid=3124 execve guuid=45c8f120-1d00-0000-7e42-9fe13a0c0000 pid=3130 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=45c8f120-1d00-0000-7e42-9fe13a0c0000 pid=3130 execve guuid=c5e85721-1d00-0000-7e42-9fe13c0c0000 pid=3132 /usr/bin/dash guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=c5e85721-1d00-0000-7e42-9fe13c0c0000 pid=3132 clone guuid=3a7cec21-1d00-0000-7e42-9fe13f0c0000 pid=3135 /usr/bin/busybox net send-data write-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=3a7cec21-1d00-0000-7e42-9fe13f0c0000 pid=3135 execve guuid=7cf97e24-1d00-0000-7e42-9fe1440c0000 pid=3140 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=7cf97e24-1d00-0000-7e42-9fe1440c0000 pid=3140 execve guuid=61a4d124-1d00-0000-7e42-9fe1460c0000 pid=3142 /usr/bin/dash guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=61a4d124-1d00-0000-7e42-9fe1460c0000 pid=3142 clone guuid=8a68e224-1d00-0000-7e42-9fe1470c0000 pid=3143 /usr/bin/busybox net send-data write-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=8a68e224-1d00-0000-7e42-9fe1470c0000 pid=3143 execve guuid=cc73a328-1d00-0000-7e42-9fe1540c0000 pid=3156 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=cc73a328-1d00-0000-7e42-9fe1540c0000 pid=3156 execve guuid=6baa1429-1d00-0000-7e42-9fe1570c0000 pid=3159 /usr/bin/dash guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=6baa1429-1d00-0000-7e42-9fe1570c0000 pid=3159 clone guuid=b74fd129-1d00-0000-7e42-9fe15b0c0000 pid=3163 /usr/bin/busybox net send-data write-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=b74fd129-1d00-0000-7e42-9fe15b0c0000 pid=3163 execve guuid=b3d0682e-1d00-0000-7e42-9fe1690c0000 pid=3177 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=b3d0682e-1d00-0000-7e42-9fe1690c0000 pid=3177 execve guuid=d233a72e-1d00-0000-7e42-9fe16b0c0000 pid=3179 /usr/bin/dash guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=d233a72e-1d00-0000-7e42-9fe16b0c0000 pid=3179 clone guuid=933d5f2f-1d00-0000-7e42-9fe16f0c0000 pid=3183 /usr/bin/busybox net send-data write-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=933d5f2f-1d00-0000-7e42-9fe16f0c0000 pid=3183 execve guuid=39a72d32-1d00-0000-7e42-9fe1790c0000 pid=3193 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=39a72d32-1d00-0000-7e42-9fe1790c0000 pid=3193 execve guuid=9c738f32-1d00-0000-7e42-9fe17b0c0000 pid=3195 /home/sandbox/morte.x86 net guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=9c738f32-1d00-0000-7e42-9fe17b0c0000 pid=3195 execve guuid=a8dc8860-1e00-0000-7e42-9fe18b0e0000 pid=3723 /usr/bin/busybox net send-data write-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=a8dc8860-1e00-0000-7e42-9fe18b0e0000 pid=3723 execve guuid=57021b68-1e00-0000-7e42-9fe19c0e0000 pid=3740 /usr/bin/chmod guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=57021b68-1e00-0000-7e42-9fe19c0e0000 pid=3740 execve guuid=05686568-1e00-0000-7e42-9fe19e0e0000 pid=3742 /home/sandbox/morte.x86_64 mprotect-exec net guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=05686568-1e00-0000-7e42-9fe19e0e0000 pid=3742 execve guuid=6bf864e0-1e00-0000-7e42-9fe12d100000 pid=4141 /usr/bin/rm delete-file guuid=2f897dfb-1c00-0000-7e42-9fe1f80b0000 pid=3064->guuid=6bf864e0-1e00-0000-7e42-9fe12d100000 pid=4141 execve 351b6f95-01a4-5d80-a90f-080c92984efa 196.251.70.174:80 guuid=aef8dafb-1c00-0000-7e42-9fe1f90b0000 pid=3065->351b6f95-01a4-5d80-a90f-080c92984efa send: 101B guuid=0ab82f00-1d00-0000-7e42-9fe1fd0b0000 pid=3069->351b6f95-01a4-5d80-a90f-080c92984efa send: 102B guuid=87be3f04-1d00-0000-7e42-9fe1010c0000 pid=3073->351b6f95-01a4-5d80-a90f-080c92984efa send: 102B guuid=08f1ac08-1d00-0000-7e42-9fe10b0c0000 pid=3083->351b6f95-01a4-5d80-a90f-080c92984efa send: 102B guuid=6600160d-1d00-0000-7e42-9fe1120c0000 pid=3090->351b6f95-01a4-5d80-a90f-080c92984efa send: 102B guuid=36a69e16-1d00-0000-7e42-9fe11c0c0000 pid=3100->351b6f95-01a4-5d80-a90f-080c92984efa send: 102B guuid=431c9c1a-1d00-0000-7e42-9fe1280c0000 pid=3112->351b6f95-01a4-5d80-a90f-080c92984efa send: 102B guuid=23bc251f-1d00-0000-7e42-9fe1340c0000 pid=3124->351b6f95-01a4-5d80-a90f-080c92984efa send: 102B guuid=3a7cec21-1d00-0000-7e42-9fe13f0c0000 pid=3135->351b6f95-01a4-5d80-a90f-080c92984efa send: 101B guuid=8a68e224-1d00-0000-7e42-9fe1470c0000 pid=3143->351b6f95-01a4-5d80-a90f-080c92984efa send: 101B guuid=b74fd129-1d00-0000-7e42-9fe15b0c0000 pid=3163->351b6f95-01a4-5d80-a90f-080c92984efa send: 101B guuid=933d5f2f-1d00-0000-7e42-9fe16f0c0000 pid=3183->351b6f95-01a4-5d80-a90f-080c92984efa send: 101B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=9c738f32-1d00-0000-7e42-9fe17b0c0000 pid=3195->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6e314633-1d00-0000-7e42-9fe17e0c0000 pid=3198 /home/sandbox/morte.x86 guuid=9c738f32-1d00-0000-7e42-9fe17b0c0000 pid=3195->guuid=6e314633-1d00-0000-7e42-9fe17e0c0000 pid=3198 clone guuid=7c294d60-1e00-0000-7e42-9fe1890e0000 pid=3721 /home/sandbox/morte.x86 guuid=9c738f32-1d00-0000-7e42-9fe17b0c0000 pid=3195->guuid=7c294d60-1e00-0000-7e42-9fe1890e0000 pid=3721 clone guuid=b38e5260-1e00-0000-7e42-9fe18a0e0000 pid=3722 /home/sandbox/morte.x86 net send-data zombie guuid=9c738f32-1d00-0000-7e42-9fe17b0c0000 pid=3195->guuid=b38e5260-1e00-0000-7e42-9fe18a0e0000 pid=3722 clone guuid=f4884b33-1d00-0000-7e42-9fe17f0c0000 pid=3199 /home/sandbox/morte.x86 guuid=6e314633-1d00-0000-7e42-9fe17e0c0000 pid=3198->guuid=f4884b33-1d00-0000-7e42-9fe17f0c0000 pid=3199 clone guuid=eab34e33-1d00-0000-7e42-9fe1800c0000 pid=3200 /home/sandbox/morte.x86 dns net send-data zombie guuid=6e314633-1d00-0000-7e42-9fe17e0c0000 pid=3198->guuid=eab34e33-1d00-0000-7e42-9fe1800c0000 pid=3200 clone guuid=eab34e33-1d00-0000-7e42-9fe1800c0000 pid=3200->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 41B e353146a-5285-5f32-a809-01b9d4b5f0e8 draft247.redirectme.net:3778 guuid=eab34e33-1d00-0000-7e42-9fe1800c0000 pid=3200->e353146a-5285-5f32-a809-01b9d4b5f0e8 send: 14B guuid=b38e5260-1e00-0000-7e42-9fe18a0e0000 pid=3722->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1230B 8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 103.77.241.144:80 guuid=b38e5260-1e00-0000-7e42-9fe18a0e0000 pid=3722->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 4B d308db0e-95e7-5190-8562-6f6532001047 draft247.redirectme.net:80 guuid=a8dc8860-1e00-0000-7e42-9fe18b0e0000 pid=3723->d308db0e-95e7-5190-8562-6f6532001047 send: 104B guuid=05686568-1e00-0000-7e42-9fe19e0e0000 pid=3742->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 51f90012-4021-58ad-8b9d-c1c2f6ed80cd 0.0.0.0:3778 guuid=05686568-1e00-0000-7e42-9fe19e0e0000 pid=3742->51f90012-4021-58ad-8b9d-c1c2f6ed80cd con
Threat name:
Linux.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-10-04 13:23:11 UTC
File Type:
Text (Shell)
AV detection:
17 of 38 (44.74%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 63fc686a2c9ebb524c0fa6c10a6266741b8dbbd219afd6b551f5cfa6fd01e3d2

(this sample)

  
Delivery method
Distributed via web download

Comments