MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6aab92ef885c935519271ae546ad8f9d7ce25fe08bf752f9facb5fe043a19bb6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 6aab92ef885c935519271ae546ad8f9d7ce25fe08bf752f9facb5fe043a19bb6
SHA3-384 hash: 725c5f4d7f98b392f268c54a151c9b6d218cb3c5cbe59c017306f81816377b8fa6723d0caf84981e95e8bca84fbb403e
SHA1 hash: 26b0a9567c3ec125134cfdb446f94df80f0732b1
MD5 hash: e0a4e02f4db42464291439242c1c6878
humanhash: pennsylvania-east-winner-failed
File name:av.sh
Download: download sample
Signature Mirai
File size:431 bytes
First seen:2025-07-20 03:57:56 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:aSFJFFZalKbL1iJakFJFFcXqalKdJJ3cRFJFFMcRalK9Fa0LKiu:j9PwKbL1i59m6wKdJdk9OkwKa0LKj
TLSH T1B5E08CC077622AB3CF4C8D1D73A28C1C6015A18E1801DA84AC0E58B89170E41B73444B
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://156.238.225.44/arm5n/an/aua-wget
http://156.238.225.44/armn/an/aua-wget
http://156.238.225.44/arm7n/an/aua-wget
ftp://6.238.225.44:8021/arm5n/an/an/a
ftp://6.238.225.44:8021/armn/an/an/a
ftp://6.238.225.44:8021/arm7n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Status:
terminated
Behavior Graph:
%3 guuid=3416e9e4-1c00-0000-a9ca-ade77c080000 pid=2172 /usr/bin/sudo guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179 /tmp/sample.bin guuid=3416e9e4-1c00-0000-a9ca-ade77c080000 pid=2172->guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179 execve guuid=3f3420e7-1c00-0000-a9ca-ade785080000 pid=2181 /usr/bin/rm guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=3f3420e7-1c00-0000-a9ca-ade785080000 pid=2181 execve guuid=1eb87ee7-1c00-0000-a9ca-ade787080000 pid=2183 /usr/bin/busybox net send-data guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=1eb87ee7-1c00-0000-a9ca-ade787080000 pid=2183 execve guuid=0415a335-1d00-0000-a9ca-ade723090000 pid=2339 /usr/bin/busybox net send-data guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=0415a335-1d00-0000-a9ca-ade723090000 pid=2339 execve guuid=2d362847-1d00-0000-a9ca-ade746090000 pid=2374 /usr/bin/chmod guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=2d362847-1d00-0000-a9ca-ade746090000 pid=2374 execve guuid=c1586b47-1d00-0000-a9ca-ade748090000 pid=2376 /usr/bin/dash guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=c1586b47-1d00-0000-a9ca-ade748090000 pid=2376 clone guuid=3c707647-1d00-0000-a9ca-ade74a090000 pid=2378 /usr/bin/rm guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=3c707647-1d00-0000-a9ca-ade74a090000 pid=2378 execve guuid=5dfeb247-1d00-0000-a9ca-ade74b090000 pid=2379 /usr/bin/busybox net send-data guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=5dfeb247-1d00-0000-a9ca-ade74b090000 pid=2379 execve guuid=749a2799-1d00-0000-a9ca-ade7fd090000 pid=2557 /usr/bin/busybox net send-data guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=749a2799-1d00-0000-a9ca-ade7fd090000 pid=2557 execve guuid=288a41ab-1d00-0000-a9ca-ade72d0a0000 pid=2605 /usr/bin/chmod guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=288a41ab-1d00-0000-a9ca-ade72d0a0000 pid=2605 execve guuid=d42498ab-1d00-0000-a9ca-ade72e0a0000 pid=2606 /usr/bin/dash guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=d42498ab-1d00-0000-a9ca-ade72e0a0000 pid=2606 clone guuid=46b1a8ab-1d00-0000-a9ca-ade7300a0000 pid=2608 /usr/bin/rm guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=46b1a8ab-1d00-0000-a9ca-ade7300a0000 pid=2608 execve guuid=a875f2ab-1d00-0000-a9ca-ade7310a0000 pid=2609 /usr/bin/busybox net send-data guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=a875f2ab-1d00-0000-a9ca-ade7310a0000 pid=2609 execve guuid=0fcde6fc-1d00-0000-a9ca-ade7f10a0000 pid=2801 /usr/bin/busybox net send-data guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=0fcde6fc-1d00-0000-a9ca-ade7f10a0000 pid=2801 execve guuid=0290750e-1e00-0000-a9ca-ade70a0b0000 pid=2826 /usr/bin/chmod guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=0290750e-1e00-0000-a9ca-ade70a0b0000 pid=2826 execve guuid=bbb7cb0e-1e00-0000-a9ca-ade70c0b0000 pid=2828 /usr/bin/dash guuid=d0d9d0e6-1c00-0000-a9ca-ade783080000 pid=2179->guuid=bbb7cb0e-1e00-0000-a9ca-ade70c0b0000 pid=2828 clone d53fc82d-7282-5625-a085-002b269287ec 156.238.225.44:8021 guuid=1eb87ee7-1c00-0000-a9ca-ade787080000 pid=2183->d53fc82d-7282-5625-a085-002b269287ec send: 66B 83d0ddc9-ba07-5b59-8466-782c0d303e5e 156.238.225.44:42358 guuid=1eb87ee7-1c00-0000-a9ca-ade787080000 pid=2183->83d0ddc9-ba07-5b59-8466-782c0d303e5e con 05ace81a-fc31-5465-9c32-7c16540b9ba1 156.238.225.44:80 guuid=0415a335-1d00-0000-a9ca-ade723090000 pid=2339->05ace81a-fc31-5465-9c32-7c16540b9ba1 send: 81B guuid=5dfeb247-1d00-0000-a9ca-ade74b090000 pid=2379->d53fc82d-7282-5625-a085-002b269287ec send: 64B 7271b9a0-4e93-5b9e-95b1-38f6e202c5fb 156.238.225.44:37868 guuid=5dfeb247-1d00-0000-a9ca-ade74b090000 pid=2379->7271b9a0-4e93-5b9e-95b1-38f6e202c5fb con guuid=749a2799-1d00-0000-a9ca-ade7fd090000 pid=2557->05ace81a-fc31-5465-9c32-7c16540b9ba1 send: 80B guuid=a875f2ab-1d00-0000-a9ca-ade7310a0000 pid=2609->d53fc82d-7282-5625-a085-002b269287ec send: 66B 89a7e9df-147c-5688-9204-650fee06d90c 156.238.225.44:39242 guuid=a875f2ab-1d00-0000-a9ca-ade7310a0000 pid=2609->89a7e9df-147c-5688-9204-650fee06d90c con guuid=0fcde6fc-1d00-0000-a9ca-ade7f10a0000 pid=2801->05ace81a-fc31-5465-9c32-7c16540b9ba1 send: 81B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-07-20 03:23:06 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6aab92ef885c935519271ae546ad8f9d7ce25fe08bf752f9facb5fe043a19bb6

(this sample)

  
Delivery method
Distributed via web download

Comments