MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d1721fff5c74d2dcaefd3b378d7c70a4ea87afec74fcd506ed3019532719bd1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 6d1721fff5c74d2dcaefd3b378d7c70a4ea87afec74fcd506ed3019532719bd1
SHA3-384 hash: 6d50bf73a7afd940ddcf1d3e1bef36d364f7b2e1d988aa240dc6374cfc1163d1049624264f9862423f48355e8075c712
SHA1 hash: f307d6fc3573974e5619978b402ec4c2b91d7035
MD5 hash: fa4868de155ef0a56fa965c67ce33c82
humanhash: winner-coffee-lemon-cardinal
File name:bins.sh
Download: download sample
Signature Mirai
File size:709 bytes
First seen:2026-03-06 20:56:41 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dzCuMtdX+J+828z/KUoub/YDnY2+jrfZFt+jrjgyufiMPZIxy/0w9nG:dzCtOJ/XouTY5+P7t+zgyuBIxy8
TLSH T1F801CB5A42511C342ED9802FB9EED1E0706D14AF26C29C3874DCBDA77F2CE086E109AF
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=cc8f881d-1700-0000-b07a-6273240d0000 pid=3364 /usr/bin/sudo guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369 /tmp/sample.bin guuid=cc8f881d-1700-0000-b07a-6273240d0000 pid=3364->guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369 execve guuid=b3b28f1f-1700-0000-b07a-62732b0d0000 pid=3371 /usr/bin/rm guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=b3b28f1f-1700-0000-b07a-62732b0d0000 pid=3371 execve guuid=86a3cd1f-1700-0000-b07a-62732d0d0000 pid=3373 /usr/bin/wget net send-data write-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=86a3cd1f-1700-0000-b07a-62732d0d0000 pid=3373 execve guuid=45f6aa25-1700-0000-b07a-6273400d0000 pid=3392 /usr/bin/chmod guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=45f6aa25-1700-0000-b07a-6273400d0000 pid=3392 execve guuid=e416ea25-1700-0000-b07a-6273410d0000 pid=3393 /usr/bin/dash guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=e416ea25-1700-0000-b07a-6273410d0000 pid=3393 clone guuid=c2cb9226-1700-0000-b07a-6273460d0000 pid=3398 /usr/bin/rm delete-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=c2cb9226-1700-0000-b07a-6273460d0000 pid=3398 execve guuid=8b16e726-1700-0000-b07a-6273480d0000 pid=3400 /usr/bin/wget net send-data write-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=8b16e726-1700-0000-b07a-6273480d0000 pid=3400 execve guuid=85767a2b-1700-0000-b07a-6273570d0000 pid=3415 /usr/bin/chmod guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=85767a2b-1700-0000-b07a-6273570d0000 pid=3415 execve guuid=409fb12b-1700-0000-b07a-6273580d0000 pid=3416 /usr/bin/dash guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=409fb12b-1700-0000-b07a-6273580d0000 pid=3416 clone guuid=82602f2c-1700-0000-b07a-62735c0d0000 pid=3420 /usr/bin/rm delete-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=82602f2c-1700-0000-b07a-62735c0d0000 pid=3420 execve guuid=98ab6b2c-1700-0000-b07a-62735e0d0000 pid=3422 /usr/bin/wget net send-data write-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=98ab6b2c-1700-0000-b07a-62735e0d0000 pid=3422 execve guuid=086ef033-1700-0000-b07a-6273750d0000 pid=3445 /usr/bin/chmod guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=086ef033-1700-0000-b07a-6273750d0000 pid=3445 execve guuid=91e63934-1700-0000-b07a-6273770d0000 pid=3447 /usr/bin/dash guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=91e63934-1700-0000-b07a-6273770d0000 pid=3447 clone guuid=8d43ca34-1700-0000-b07a-62737b0d0000 pid=3451 /usr/bin/rm delete-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=8d43ca34-1700-0000-b07a-62737b0d0000 pid=3451 execve guuid=dab92c35-1700-0000-b07a-62737d0d0000 pid=3453 /usr/bin/wget net send-data write-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=dab92c35-1700-0000-b07a-62737d0d0000 pid=3453 execve guuid=cb4ef139-1700-0000-b07a-62738d0d0000 pid=3469 /usr/bin/chmod guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=cb4ef139-1700-0000-b07a-62738d0d0000 pid=3469 execve guuid=5d6a413a-1700-0000-b07a-6273900d0000 pid=3472 /usr/bin/dash guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=5d6a413a-1700-0000-b07a-6273900d0000 pid=3472 clone guuid=307ddc3a-1700-0000-b07a-6273940d0000 pid=3476 /usr/bin/rm delete-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=307ddc3a-1700-0000-b07a-6273940d0000 pid=3476 execve guuid=4c3c293b-1700-0000-b07a-6273960d0000 pid=3478 /usr/bin/wget net send-data write-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=4c3c293b-1700-0000-b07a-6273960d0000 pid=3478 execve guuid=9c2e2440-1700-0000-b07a-6273a80d0000 pid=3496 /usr/bin/chmod guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=9c2e2440-1700-0000-b07a-6273a80d0000 pid=3496 execve guuid=1d056940-1700-0000-b07a-6273a90d0000 pid=3497 /tmp/sysa delete-file net guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=1d056940-1700-0000-b07a-6273a90d0000 pid=3497 execve guuid=9d557f40-1700-0000-b07a-6273ab0d0000 pid=3499 /usr/bin/rm guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=9d557f40-1700-0000-b07a-6273ab0d0000 pid=3499 execve guuid=a355da40-1700-0000-b07a-6273af0d0000 pid=3503 /usr/bin/wget net send-data write-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=a355da40-1700-0000-b07a-6273af0d0000 pid=3503 execve guuid=6debf544-1700-0000-b07a-6273ba0d0000 pid=3514 /usr/bin/chmod guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=6debf544-1700-0000-b07a-6273ba0d0000 pid=3514 execve guuid=08574045-1700-0000-b07a-6273bb0d0000 pid=3515 /tmp/sysa delete-file net guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=08574045-1700-0000-b07a-6273bb0d0000 pid=3515 execve guuid=992c8445-1700-0000-b07a-6273bd0d0000 pid=3517 /usr/bin/rm guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=992c8445-1700-0000-b07a-6273bd0d0000 pid=3517 execve guuid=1e01c745-1700-0000-b07a-6273bf0d0000 pid=3519 /usr/bin/wget net send-data write-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=1e01c745-1700-0000-b07a-6273bf0d0000 pid=3519 execve guuid=4db0914a-1700-0000-b07a-6273cb0d0000 pid=3531 /usr/bin/chmod guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=4db0914a-1700-0000-b07a-6273cb0d0000 pid=3531 execve guuid=a7dae14a-1700-0000-b07a-6273cd0d0000 pid=3533 /usr/bin/dash guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=a7dae14a-1700-0000-b07a-6273cd0d0000 pid=3533 clone guuid=a8eb5c4b-1700-0000-b07a-6273d00d0000 pid=3536 /usr/bin/rm delete-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=a8eb5c4b-1700-0000-b07a-6273d00d0000 pid=3536 execve guuid=771ca24b-1700-0000-b07a-6273d20d0000 pid=3538 /usr/bin/wget net send-data write-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=771ca24b-1700-0000-b07a-6273d20d0000 pid=3538 execve guuid=5979a950-1700-0000-b07a-6273dd0d0000 pid=3549 /usr/bin/chmod guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=5979a950-1700-0000-b07a-6273dd0d0000 pid=3549 execve guuid=92ab0151-1700-0000-b07a-6273df0d0000 pid=3551 /usr/bin/dash guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=92ab0151-1700-0000-b07a-6273df0d0000 pid=3551 clone guuid=8f073b52-1700-0000-b07a-6273e40d0000 pid=3556 /usr/bin/rm delete-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=8f073b52-1700-0000-b07a-6273e40d0000 pid=3556 execve guuid=c6999052-1700-0000-b07a-6273e60d0000 pid=3558 /usr/bin/wget net send-data write-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=c6999052-1700-0000-b07a-6273e60d0000 pid=3558 execve guuid=c680d657-1700-0000-b07a-6273ef0d0000 pid=3567 /usr/bin/chmod guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=c680d657-1700-0000-b07a-6273ef0d0000 pid=3567 execve guuid=f2d18158-1700-0000-b07a-6273f00d0000 pid=3568 /usr/bin/dash guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=f2d18158-1700-0000-b07a-6273f00d0000 pid=3568 clone guuid=28df3f5a-1700-0000-b07a-6273f40d0000 pid=3572 /usr/bin/rm delete-file guuid=0c0c561f-1700-0000-b07a-6273290d0000 pid=3369->guuid=28df3f5a-1700-0000-b07a-6273f40d0000 pid=3572 execve 1227c8c9-f647-5d60-9378-cbbde3e2a9ba 2.56.10.144:80 guuid=86a3cd1f-1700-0000-b07a-62732d0d0000 pid=3373->1227c8c9-f647-5d60-9378-cbbde3e2a9ba send: 135B guuid=8b16e726-1700-0000-b07a-6273480d0000 pid=3400->1227c8c9-f647-5d60-9378-cbbde3e2a9ba send: 135B guuid=98ab6b2c-1700-0000-b07a-62735e0d0000 pid=3422->1227c8c9-f647-5d60-9378-cbbde3e2a9ba send: 135B guuid=dab92c35-1700-0000-b07a-62737d0d0000 pid=3453->1227c8c9-f647-5d60-9378-cbbde3e2a9ba send: 134B guuid=4c3c293b-1700-0000-b07a-6273960d0000 pid=3478->1227c8c9-f647-5d60-9378-cbbde3e2a9ba send: 137B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=1d056940-1700-0000-b07a-6273a90d0000 pid=3497->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a1c17840-1700-0000-b07a-6273aa0d0000 pid=3498 /tmp/sysa net zombie guuid=1d056940-1700-0000-b07a-6273a90d0000 pid=3497->guuid=a1c17840-1700-0000-b07a-6273aa0d0000 pid=3498 clone 59deadd9-81e4-5139-988b-da9aa223339c 84.32.98.123:443 guuid=a1c17840-1700-0000-b07a-6273aa0d0000 pid=3498->59deadd9-81e4-5139-988b-da9aa223339c con guuid=92e48c40-1700-0000-b07a-6273ad0d0000 pid=3501 /tmp/sysa guuid=a1c17840-1700-0000-b07a-6273aa0d0000 pid=3498->guuid=92e48c40-1700-0000-b07a-6273ad0d0000 pid=3501 clone guuid=a355da40-1700-0000-b07a-6273af0d0000 pid=3503->1227c8c9-f647-5d60-9378-cbbde3e2a9ba send: 134B guuid=08574045-1700-0000-b07a-6273bb0d0000 pid=3515->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=96907745-1700-0000-b07a-6273bc0d0000 pid=3516 /tmp/sysa delete-file net zombie guuid=08574045-1700-0000-b07a-6273bb0d0000 pid=3515->guuid=96907745-1700-0000-b07a-6273bc0d0000 pid=3516 clone guuid=96907745-1700-0000-b07a-6273bc0d0000 pid=3516->59deadd9-81e4-5139-988b-da9aa223339c con guuid=f0dc9645-1700-0000-b07a-6273be0d0000 pid=3518 /tmp/sysa guuid=96907745-1700-0000-b07a-6273bc0d0000 pid=3516->guuid=f0dc9645-1700-0000-b07a-6273be0d0000 pid=3518 clone guuid=1e01c745-1700-0000-b07a-6273bf0d0000 pid=3519->1227c8c9-f647-5d60-9378-cbbde3e2a9ba send: 134B guuid=771ca24b-1700-0000-b07a-6273d20d0000 pid=3538->1227c8c9-f647-5d60-9378-cbbde3e2a9ba send: 134B guuid=c6999052-1700-0000-b07a-6273e60d0000 pid=3558->1227c8c9-f647-5d60-9378-cbbde3e2a9ba send: 135B
Threat name:
Script.Trojan.Malgent
Status:
Malicious
First seen:
2026-03-06 20:57:13 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Mirai
Mirai family
Malware Config
C2 Extraction:
84.32.98.123
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6d1721fff5c74d2dcaefd3b378d7c70a4ea87afec74fcd506ed3019532719bd1

(this sample)

  
Delivery method
Distributed via web download

Comments