MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 68f75588bb196e1c62cd7d8d05b3ed50e0c9e446b684e65ebd1511379a0573c8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 68f75588bb196e1c62cd7d8d05b3ed50e0c9e446b684e65ebd1511379a0573c8
SHA3-384 hash: 97e8e1ba84e4871c9feff865abbb40ee71659cbb694e6904398f2c5f5e06e415673c529a63d331512ecf28ffddd3b46a
SHA1 hash: f7cabfa47d96dcae210a5460ffa9212d75a0c316
MD5 hash: 35cb4a27477cedd8d9368a617b6deabd
humanhash: montana-glucose-alabama-oxygen
File name:c.sh
Download: download sample
Signature Mirai
File size:994 bytes
First seen:2025-08-26 05:31:09 UTC
Last seen:2025-08-26 13:53:47 UTC
File type: sh
MIME type:text/plain
ssdeep 24:3J3KQVNQVsQVFNI50QVFKnQVmOQVKQVzrQV4QVR6QVffQV2EbQVJHR:oQVNQVsQV9QVFwQVbQVKQVzrQV4QVR6U
TLSH T1DE115E8DE5D7F14A19488FD6B06DC42FFBDAD3ECB4B02610E0B6E4A194889076054BBA
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://36.50.54.209/d/akido.armb00ea781da9e92698db57dc1ddf77d4d1028f822937ab46165bb49a26a2a7648 Miraiarm elf geofenced mirai ua-wget USA
http://36.50.54.209/d/akido.arm571ef3570913b3239a9b2eec2446b6d209c7655ea85016cda3c39a2fe58e9c0f2 Miraiarm elf geofenced mirai ua-wget USA
http://36.50.54.209/d/akido.arm6d7e5b1bee072ebdf6f4b872bc7ce695276f20fad7eba6a0ed119c52d921025f9 Miraiarm elf geofenced mirai ua-wget USA
http://36.50.54.209/d/akido.arm7n/an/aelf ua-wget
http://36.50.54.209/d/akido.m68k2da39cdbbdb6cc055347a9398eabca08740479d27e83cefe672cb2fa70319e66 Miraielf geofenced m68k mirai ua-wget USA
http://36.50.54.209/d/akido.mipsbfeef780df60fac30bbbb4be6d96165eca29bc3bd75cde002ac090db76be9ac9 Miraielf geofenced mips mirai ua-wget USA
http://36.50.54.209/d/akido.mpsl53bcbffaef64fa91f47a276d35ea98b0e3316a4f6127aa56e18a8ecd60f4f869 Miraielf geofenced mips mirai ua-wget USA
http://36.50.54.209/d/akido.ppcdc6339e709d7209eb306f5b6a0b12c03609c25f932bb5a9eae931542ac5e7ffe Miraielf geofenced mirai PowerPC ua-wget USA
http://36.50.54.209/d/akido.sh4e03b4ce9aee4810a2c8f53cb8a2314ef87366a2f024b892408b8da2c196a1e53 Miraielf geofenced mirai SuperH ua-wget USA
http://36.50.54.209/d/akido.spcbf08e107644e274b1ee846360dd1e6d9a90f26842d871ff36f07cd178437dd81 Miraielf geofenced mirai sparc ua-wget USA
http://36.50.54.209/d/akido.x86c939bcb600ac81a2a12fb4d15a3d2fd2d676c618e3c935d842181fd2d0fb8fec Miraielf geofenced mirai ua-wget USA x86
http://36.50.54.209/d/akido.x86_64n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
Txt
First seen:
2025-08-26T15:00:00Z UTC
Last seen:
2025-08-26T15:00:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=0f4d3421-1900-0000-bdfb-95b0cb0a0000 pid=2763 /usr/bin/sudo guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770 /tmp/sample.bin guuid=0f4d3421-1900-0000-bdfb-95b0cb0a0000 pid=2763->guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770 execve guuid=11c2f023-1900-0000-bdfb-95b0d40a0000 pid=2772 /usr/bin/curl net send-data guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=11c2f023-1900-0000-bdfb-95b0d40a0000 pid=2772 execve guuid=652b6655-1900-0000-bdfb-95b01a0b0000 pid=2842 /usr/bin/chmod guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=652b6655-1900-0000-bdfb-95b01a0b0000 pid=2842 execve guuid=8c5fb855-1900-0000-bdfb-95b01c0b0000 pid=2844 /usr/bin/dash guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=8c5fb855-1900-0000-bdfb-95b01c0b0000 pid=2844 clone guuid=ed18bf55-1900-0000-bdfb-95b01d0b0000 pid=2845 /usr/bin/curl net send-data guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=ed18bf55-1900-0000-bdfb-95b01d0b0000 pid=2845 execve guuid=90064981-1900-0000-bdfb-95b07c0b0000 pid=2940 /usr/bin/chmod guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=90064981-1900-0000-bdfb-95b07c0b0000 pid=2940 execve guuid=b0050582-1900-0000-bdfb-95b07f0b0000 pid=2943 /usr/bin/dash guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=b0050582-1900-0000-bdfb-95b07f0b0000 pid=2943 clone guuid=77c50f82-1900-0000-bdfb-95b0810b0000 pid=2945 /usr/bin/curl net send-data guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=77c50f82-1900-0000-bdfb-95b0810b0000 pid=2945 execve guuid=704f00ae-1900-0000-bdfb-95b0db0b0000 pid=3035 /usr/bin/chmod guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=704f00ae-1900-0000-bdfb-95b0db0b0000 pid=3035 execve guuid=0b4754ae-1900-0000-bdfb-95b0dd0b0000 pid=3037 /usr/bin/dash guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=0b4754ae-1900-0000-bdfb-95b0dd0b0000 pid=3037 clone guuid=01a861ae-1900-0000-bdfb-95b0de0b0000 pid=3038 /usr/bin/curl net send-data guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=01a861ae-1900-0000-bdfb-95b0de0b0000 pid=3038 execve guuid=525de6cb-1900-0000-bdfb-95b0140c0000 pid=3092 /usr/bin/chmod guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=525de6cb-1900-0000-bdfb-95b0140c0000 pid=3092 execve guuid=1d4345cc-1900-0000-bdfb-95b0160c0000 pid=3094 /usr/bin/dash guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=1d4345cc-1900-0000-bdfb-95b0160c0000 pid=3094 clone guuid=e7375ccc-1900-0000-bdfb-95b0170c0000 pid=3095 /usr/bin/curl net send-data guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=e7375ccc-1900-0000-bdfb-95b0170c0000 pid=3095 execve guuid=3c296dbb-1a00-0000-bdfb-95b0890d0000 pid=3465 /usr/bin/chmod guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=3c296dbb-1a00-0000-bdfb-95b0890d0000 pid=3465 execve guuid=58cfc8bb-1a00-0000-bdfb-95b08b0d0000 pid=3467 /usr/bin/dash guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=58cfc8bb-1a00-0000-bdfb-95b08b0d0000 pid=3467 clone guuid=3e50dabb-1a00-0000-bdfb-95b08c0d0000 pid=3468 /usr/bin/curl net send-data guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=3e50dabb-1a00-0000-bdfb-95b08c0d0000 pid=3468 execve guuid=7bb7ad64-1b00-0000-bdfb-95b0e60e0000 pid=3814 /usr/bin/chmod guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=7bb7ad64-1b00-0000-bdfb-95b0e60e0000 pid=3814 execve guuid=dbcb2e65-1b00-0000-bdfb-95b0e90e0000 pid=3817 /usr/bin/dash guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=dbcb2e65-1b00-0000-bdfb-95b0e90e0000 pid=3817 clone guuid=defb3d65-1b00-0000-bdfb-95b0ea0e0000 pid=3818 /usr/bin/curl net send-data guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=defb3d65-1b00-0000-bdfb-95b0ea0e0000 pid=3818 execve guuid=0dbd7ac8-1c00-0000-bdfb-95b083120000 pid=4739 /usr/bin/chmod guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=0dbd7ac8-1c00-0000-bdfb-95b083120000 pid=4739 execve guuid=9a1fc8c8-1c00-0000-bdfb-95b085120000 pid=4741 /usr/bin/dash guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=9a1fc8c8-1c00-0000-bdfb-95b085120000 pid=4741 clone guuid=bdeed2c8-1c00-0000-bdfb-95b086120000 pid=4742 /usr/bin/curl net send-data guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=bdeed2c8-1c00-0000-bdfb-95b086120000 pid=4742 execve guuid=fc6b7ef4-1c00-0000-bdfb-95b0e5120000 pid=4837 /usr/bin/chmod guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=fc6b7ef4-1c00-0000-bdfb-95b0e5120000 pid=4837 execve guuid=634ef6f4-1c00-0000-bdfb-95b0e7120000 pid=4839 /usr/bin/dash guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=634ef6f4-1c00-0000-bdfb-95b0e7120000 pid=4839 clone guuid=e7d701f5-1c00-0000-bdfb-95b0e8120000 pid=4840 /usr/bin/curl net send-data guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=e7d701f5-1c00-0000-bdfb-95b0e8120000 pid=4840 execve guuid=d7825b6e-1d00-0000-bdfb-95b0a8130000 pid=5032 /usr/bin/chmod guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=d7825b6e-1d00-0000-bdfb-95b0a8130000 pid=5032 execve guuid=5af91f6f-1d00-0000-bdfb-95b0a9130000 pid=5033 /usr/bin/dash guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=5af91f6f-1d00-0000-bdfb-95b0a9130000 pid=5033 clone guuid=785e356f-1d00-0000-bdfb-95b0aa130000 pid=5034 /usr/bin/curl net send-data guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=785e356f-1d00-0000-bdfb-95b0aa130000 pid=5034 execve guuid=2c16a6ea-1d00-0000-bdfb-95b083140000 pid=5251 /usr/bin/chmod guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=2c16a6ea-1d00-0000-bdfb-95b083140000 pid=5251 execve guuid=ebdcf0ea-1d00-0000-bdfb-95b084140000 pid=5252 /usr/bin/dash guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=ebdcf0ea-1d00-0000-bdfb-95b084140000 pid=5252 clone guuid=529ffdea-1d00-0000-bdfb-95b085140000 pid=5253 /usr/bin/curl net send-data guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=529ffdea-1d00-0000-bdfb-95b085140000 pid=5253 execve guuid=d794ad15-1e00-0000-bdfb-95b086140000 pid=5254 /usr/bin/chmod guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=d794ad15-1e00-0000-bdfb-95b086140000 pid=5254 execve guuid=6b390916-1e00-0000-bdfb-95b087140000 pid=5255 /usr/bin/dash guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=6b390916-1e00-0000-bdfb-95b087140000 pid=5255 clone guuid=a5a51816-1e00-0000-bdfb-95b088140000 pid=5256 /usr/bin/curl net send-data guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=a5a51816-1e00-0000-bdfb-95b088140000 pid=5256 execve guuid=3efe2d34-1e00-0000-bdfb-95b089140000 pid=5257 /usr/bin/chmod guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=3efe2d34-1e00-0000-bdfb-95b089140000 pid=5257 execve guuid=82597f34-1e00-0000-bdfb-95b08a140000 pid=5258 /usr/bin/dash guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=82597f34-1e00-0000-bdfb-95b08a140000 pid=5258 clone guuid=b9189234-1e00-0000-bdfb-95b08b140000 pid=5259 /usr/bin/rm delete-file guuid=9f1bb423-1900-0000-bdfb-95b0d20a0000 pid=2770->guuid=b9189234-1e00-0000-bdfb-95b08b140000 pid=5259 execve e631e79e-cc3d-5c43-938f-501d6e4522d0 36.50.54.209:80 guuid=11c2f023-1900-0000-bdfb-95b0d40a0000 pid=2772->e631e79e-cc3d-5c43-938f-501d6e4522d0 send: 87B guuid=ed18bf55-1900-0000-bdfb-95b01d0b0000 pid=2845->e631e79e-cc3d-5c43-938f-501d6e4522d0 send: 88B guuid=77c50f82-1900-0000-bdfb-95b0810b0000 pid=2945->e631e79e-cc3d-5c43-938f-501d6e4522d0 send: 88B guuid=01a861ae-1900-0000-bdfb-95b0de0b0000 pid=3038->e631e79e-cc3d-5c43-938f-501d6e4522d0 send: 88B guuid=e7375ccc-1900-0000-bdfb-95b0170c0000 pid=3095->e631e79e-cc3d-5c43-938f-501d6e4522d0 send: 88B guuid=3e50dabb-1a00-0000-bdfb-95b08c0d0000 pid=3468->e631e79e-cc3d-5c43-938f-501d6e4522d0 send: 88B guuid=defb3d65-1b00-0000-bdfb-95b0ea0e0000 pid=3818->e631e79e-cc3d-5c43-938f-501d6e4522d0 send: 88B guuid=bdeed2c8-1c00-0000-bdfb-95b086120000 pid=4742->e631e79e-cc3d-5c43-938f-501d6e4522d0 send: 87B guuid=e7d701f5-1c00-0000-bdfb-95b0e8120000 pid=4840->e631e79e-cc3d-5c43-938f-501d6e4522d0 send: 87B guuid=785e356f-1d00-0000-bdfb-95b0aa130000 pid=5034->e631e79e-cc3d-5c43-938f-501d6e4522d0 send: 87B guuid=529ffdea-1d00-0000-bdfb-95b085140000 pid=5253->e631e79e-cc3d-5c43-938f-501d6e4522d0 send: 87B guuid=a5a51816-1e00-0000-bdfb-95b088140000 pid=5256->e631e79e-cc3d-5c43-938f-501d6e4522d0 send: 90B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-08-26 05:32:34 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 68f75588bb196e1c62cd7d8d05b3ed50e0c9e446b684e65ebd1511379a0573c8

(this sample)

  
Delivery method
Distributed via web download

Comments