MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6c5dec1a36d92859c396afc2487fefe03adc5dccade6eb19c20220c32ac22d46. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 6c5dec1a36d92859c396afc2487fefe03adc5dccade6eb19c20220c32ac22d46
SHA3-384 hash: f50c560aff14c39543b32ded76995a2e621acfb97cbe041af5801411161347e8c9e4b2ce144d72786f7fb6c53936b571
SHA1 hash: 861831616c13f370745853d5411d46ee0f0bc24a
MD5 hash: b8b85a67ceed723d85fa53f037e3facd
humanhash: happy-ack-solar-nuts
File name:w.sh
Download: download sample
Signature Mirai
File size:1'018 bytes
First seen:2025-07-08 08:06:25 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:XQg3R53BNIqc30KxE3k3h3vU3F3L1xl3sv3Pg35HR:AgB5NcESE0xfU1DlcvYpx
TLSH T17511EBCE2058E0A0062ECDD3311D4C2931099FE4E86C9FBC6CACD9F76799914F561F19
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://195.26.230.140/bot.armd94afe94f28da93136e6fcdcb59260db22379b125bd3ce0ea5ab9ee67c09b012 Miraielf mirai ua-wget
http://195.26.230.140/bot.arm54b92accedb3b297a4f9b16b467a5bfac77e9c6d38d8096c8c7c58a92015669fb Miraielf mirai ua-wget
http://195.26.230.140/bot.arm6f269d80a3d18771944f214a776e60b38f64a99fb0b8129a64ee5d0c6a5a31845 Miraielf mirai ua-wget
http://195.26.230.140/bot.arm7ac8db928e4215e533461654aded561ee9ac1c3f081255c175555a8079ab69e6c Miraielf mirai ua-wget
http://195.26.230.140/bot.m68k06b5fd574b7204363aefce8aad552780db6e9c6ec7eb37663b4665668283a0fc Miraielf mirai ua-wget
http://195.26.230.140/bot.mips9d45b00ecf01f0a0440e0645effb035e7d1d25d65d89d2e34286833498659965 Miraielf mirai ua-wget
http://195.26.230.140/bot.mpslde85ebe281b21a7ea8024f29a777f41ba292ac34534b7b23d8bd486e0a402d78 Miraielf mirai ua-wget
http://195.26.230.140/bot.ppc03fd4ae0f5d4ee9964cccb0285b5293f1833d54c9e80d5dfc709e9f81f3156bf Miraielf mirai ua-wget
http://195.26.230.140/bot.sh476c43797846a7f65e635d8f1d17737935e4c5b7db02d9e004b3e616553e2f3d2 Miraielf mirai ua-wget
http://195.26.230.140/bot.spcn/an/acensys elf ua-wget
http://195.26.230.140/bot.x86ae59955a41dbfbc15a1626d17b08f6d9e592bdb88fd244c058a86a40754c6be7 Miraielf mirai ua-wget
http://195.26.230.140/bot.x86_64e62d6fbaf1cd9798956a1649a12ac2ad242f0ff9ee8c905e27d2b02dacfeb802 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
24
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=a4d6c363-1a00-0000-3a4d-ec97550b0000 pid=2901 /usr/bin/sudo guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906 /tmp/sample.bin guuid=a4d6c363-1a00-0000-3a4d-ec97550b0000 pid=2901->guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906 execve guuid=8e876866-1a00-0000-3a4d-ec975b0b0000 pid=2907 /usr/bin/busybox net send-data write-file guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=8e876866-1a00-0000-3a4d-ec975b0b0000 pid=2907 execve guuid=43e3ac70-1a00-0000-3a4d-ec97680b0000 pid=2920 /usr/bin/chmod guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=43e3ac70-1a00-0000-3a4d-ec97680b0000 pid=2920 execve guuid=3bc7ec70-1a00-0000-3a4d-ec976a0b0000 pid=2922 /usr/bin/dash guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=3bc7ec70-1a00-0000-3a4d-ec976a0b0000 pid=2922 clone guuid=01caf770-1a00-0000-3a4d-ec976b0b0000 pid=2923 /usr/bin/busybox net send-data write-file guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=01caf770-1a00-0000-3a4d-ec976b0b0000 pid=2923 execve guuid=1f8a047b-1a00-0000-3a4d-ec97810b0000 pid=2945 /usr/bin/chmod guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=1f8a047b-1a00-0000-3a4d-ec97810b0000 pid=2945 execve guuid=bd0b587b-1a00-0000-3a4d-ec97830b0000 pid=2947 /usr/bin/dash guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=bd0b587b-1a00-0000-3a4d-ec97830b0000 pid=2947 clone guuid=2320d67b-1a00-0000-3a4d-ec97870b0000 pid=2951 /usr/bin/busybox net send-data write-file guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=2320d67b-1a00-0000-3a4d-ec97870b0000 pid=2951 execve guuid=1608ce85-1a00-0000-3a4d-ec979b0b0000 pid=2971 /usr/bin/chmod guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=1608ce85-1a00-0000-3a4d-ec979b0b0000 pid=2971 execve guuid=2f9c1086-1a00-0000-3a4d-ec979d0b0000 pid=2973 /usr/bin/dash guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=2f9c1086-1a00-0000-3a4d-ec979d0b0000 pid=2973 clone guuid=70c7bb86-1a00-0000-3a4d-ec97a00b0000 pid=2976 /usr/bin/busybox net send-data write-file guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=70c7bb86-1a00-0000-3a4d-ec97a00b0000 pid=2976 execve guuid=3b70d690-1a00-0000-3a4d-ec97bf0b0000 pid=3007 /usr/bin/chmod guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=3b70d690-1a00-0000-3a4d-ec97bf0b0000 pid=3007 execve guuid=9de01891-1a00-0000-3a4d-ec97c00b0000 pid=3008 /usr/bin/dash guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=9de01891-1a00-0000-3a4d-ec97c00b0000 pid=3008 clone guuid=9b10ae91-1a00-0000-3a4d-ec97c30b0000 pid=3011 /usr/bin/busybox net send-data write-file guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=9b10ae91-1a00-0000-3a4d-ec97c30b0000 pid=3011 execve guuid=73a0f69b-1a00-0000-3a4d-ec97dc0b0000 pid=3036 /usr/bin/chmod guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=73a0f69b-1a00-0000-3a4d-ec97dc0b0000 pid=3036 execve guuid=f720339c-1a00-0000-3a4d-ec97de0b0000 pid=3038 /usr/bin/dash guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=f720339c-1a00-0000-3a4d-ec97de0b0000 pid=3038 clone guuid=24eac19c-1a00-0000-3a4d-ec97e20b0000 pid=3042 /usr/bin/busybox net send-data write-file guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=24eac19c-1a00-0000-3a4d-ec97e20b0000 pid=3042 execve guuid=3446bfa6-1a00-0000-3a4d-ec97010c0000 pid=3073 /usr/bin/chmod guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=3446bfa6-1a00-0000-3a4d-ec97010c0000 pid=3073 execve guuid=92a0f7a6-1a00-0000-3a4d-ec97030c0000 pid=3075 /usr/bin/dash guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=92a0f7a6-1a00-0000-3a4d-ec97030c0000 pid=3075 clone guuid=10bd77a7-1a00-0000-3a4d-ec97060c0000 pid=3078 /usr/bin/busybox net send-data write-file guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=10bd77a7-1a00-0000-3a4d-ec97060c0000 pid=3078 execve guuid=ba1a63b1-1a00-0000-3a4d-ec971f0c0000 pid=3103 /usr/bin/chmod guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=ba1a63b1-1a00-0000-3a4d-ec971f0c0000 pid=3103 execve guuid=eef1a9b1-1a00-0000-3a4d-ec97210c0000 pid=3105 /usr/bin/dash guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=eef1a9b1-1a00-0000-3a4d-ec97210c0000 pid=3105 clone guuid=49fb81b2-1a00-0000-3a4d-ec97250c0000 pid=3109 /usr/bin/busybox net send-data write-file guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=49fb81b2-1a00-0000-3a4d-ec97250c0000 pid=3109 execve guuid=474a4ebc-1a00-0000-3a4d-ec973d0c0000 pid=3133 /usr/bin/chmod guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=474a4ebc-1a00-0000-3a4d-ec973d0c0000 pid=3133 execve guuid=40c781bc-1a00-0000-3a4d-ec973f0c0000 pid=3135 /usr/bin/dash guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=40c781bc-1a00-0000-3a4d-ec973f0c0000 pid=3135 clone guuid=c00e0abd-1a00-0000-3a4d-ec97430c0000 pid=3139 /usr/bin/busybox net send-data write-file guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=c00e0abd-1a00-0000-3a4d-ec97430c0000 pid=3139 execve guuid=63a737d0-1a00-0000-3a4d-ec97670c0000 pid=3175 /usr/bin/chmod guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=63a737d0-1a00-0000-3a4d-ec97670c0000 pid=3175 execve guuid=f6e97ed0-1a00-0000-3a4d-ec97680c0000 pid=3176 /usr/bin/dash guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=f6e97ed0-1a00-0000-3a4d-ec97680c0000 pid=3176 clone guuid=d3a879d1-1a00-0000-3a4d-ec976a0c0000 pid=3178 /usr/bin/busybox net send-data guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=d3a879d1-1a00-0000-3a4d-ec976a0c0000 pid=3178 execve guuid=66a5acd5-1a00-0000-3a4d-ec97750c0000 pid=3189 /usr/bin/chmod guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=66a5acd5-1a00-0000-3a4d-ec97750c0000 pid=3189 execve guuid=565623d6-1a00-0000-3a4d-ec97770c0000 pid=3191 /usr/bin/dash guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=565623d6-1a00-0000-3a4d-ec97770c0000 pid=3191 clone guuid=c5ed35d6-1a00-0000-3a4d-ec97780c0000 pid=3192 /usr/bin/busybox net send-data write-file guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=c5ed35d6-1a00-0000-3a4d-ec97780c0000 pid=3192 execve guuid=232880de-1a00-0000-3a4d-ec978b0c0000 pid=3211 /usr/bin/chmod guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=232880de-1a00-0000-3a4d-ec978b0c0000 pid=3211 execve guuid=d6e0eede-1a00-0000-3a4d-ec978d0c0000 pid=3213 /home/sandbox/bot.x86 delete-file net guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=d6e0eede-1a00-0000-3a4d-ec978d0c0000 pid=3213 execve guuid=c37f58df-1a00-0000-3a4d-ec97900c0000 pid=3216 /usr/bin/busybox net send-data guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=c37f58df-1a00-0000-3a4d-ec97900c0000 pid=3216 execve guuid=2fdc1ce2-1a00-0000-3a4d-ec97920c0000 pid=3218 /usr/bin/chmod guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=2fdc1ce2-1a00-0000-3a4d-ec97920c0000 pid=3218 execve guuid=ef68c8e2-1a00-0000-3a4d-ec97930c0000 pid=3219 /usr/bin/dash guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=ef68c8e2-1a00-0000-3a4d-ec97930c0000 pid=3219 clone guuid=53d9d2e2-1a00-0000-3a4d-ec97940c0000 pid=3220 /usr/bin/rm delete-file guuid=635cf865-1a00-0000-3a4d-ec975a0b0000 pid=2906->guuid=53d9d2e2-1a00-0000-3a4d-ec97940c0000 pid=3220 execve d6b75aa7-51a9-5843-b27b-09c56746b46d 195.26.230.140:80 guuid=8e876866-1a00-0000-3a4d-ec975b0b0000 pid=2907->d6b75aa7-51a9-5843-b27b-09c56746b46d send: 84B guuid=01caf770-1a00-0000-3a4d-ec976b0b0000 pid=2923->d6b75aa7-51a9-5843-b27b-09c56746b46d send: 85B guuid=2320d67b-1a00-0000-3a4d-ec97870b0000 pid=2951->d6b75aa7-51a9-5843-b27b-09c56746b46d send: 85B guuid=70c7bb86-1a00-0000-3a4d-ec97a00b0000 pid=2976->d6b75aa7-51a9-5843-b27b-09c56746b46d send: 85B guuid=9b10ae91-1a00-0000-3a4d-ec97c30b0000 pid=3011->d6b75aa7-51a9-5843-b27b-09c56746b46d send: 85B guuid=24eac19c-1a00-0000-3a4d-ec97e20b0000 pid=3042->d6b75aa7-51a9-5843-b27b-09c56746b46d send: 85B guuid=10bd77a7-1a00-0000-3a4d-ec97060c0000 pid=3078->d6b75aa7-51a9-5843-b27b-09c56746b46d send: 85B guuid=49fb81b2-1a00-0000-3a4d-ec97250c0000 pid=3109->d6b75aa7-51a9-5843-b27b-09c56746b46d send: 84B guuid=c00e0abd-1a00-0000-3a4d-ec97430c0000 pid=3139->d6b75aa7-51a9-5843-b27b-09c56746b46d send: 84B guuid=d3a879d1-1a00-0000-3a4d-ec976a0c0000 pid=3178->d6b75aa7-51a9-5843-b27b-09c56746b46d send: 84B guuid=c5ed35d6-1a00-0000-3a4d-ec97780c0000 pid=3192->d6b75aa7-51a9-5843-b27b-09c56746b46d send: 84B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=d6e0eede-1a00-0000-3a4d-ec978d0c0000 pid=3213->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a6b64adf-1a00-0000-3a4d-ec978f0c0000 pid=3215 /home/sandbox/bot.x86 dns net send-data zombie guuid=d6e0eede-1a00-0000-3a4d-ec978d0c0000 pid=3213->guuid=a6b64adf-1a00-0000-3a4d-ec978f0c0000 pid=3215 clone guuid=a6b64adf-1a00-0000-3a4d-ec978f0c0000 pid=3215->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B 6fd6da78-f5ed-58c4-b670-58f6c605a94c uranet.duckdns.org:43957 guuid=a6b64adf-1a00-0000-3a4d-ec978f0c0000 pid=3215->6fd6da78-f5ed-58c4-b670-58f6c605a94c send: 14B guuid=50685ddf-1a00-0000-3a4d-ec97910c0000 pid=3217 /home/sandbox/bot.x86 guuid=a6b64adf-1a00-0000-3a4d-ec978f0c0000 pid=3215->guuid=50685ddf-1a00-0000-3a4d-ec97910c0000 pid=3217 clone guuid=c37f58df-1a00-0000-3a4d-ec97900c0000 pid=3216->d6b75aa7-51a9-5843-b27b-09c56746b46d send: 87B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-07-06 20:34:16 UTC
File Type:
Text (Shell)
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6c5dec1a36d92859c396afc2487fefe03adc5dccade6eb19c20220c32ac22d46

(this sample)

  
Delivery method
Distributed via web download

Comments