MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 70f17fa4dfb42d1487466f5ac56b954f301ff48398fbf0a87b2fdebcb5a3bb59. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 70f17fa4dfb42d1487466f5ac56b954f301ff48398fbf0a87b2fdebcb5a3bb59
SHA3-384 hash: 2b81b3f526d6f487b69942b3247e7dc8dfbdf8e7737d10cb79dc6595b503c97d88db16f62c69173d4466c8a4061aafac
SHA1 hash: 1a6b4221676ed9c7b65e7696348d05d63d83e335
MD5 hash: 0f36442574e4029bb33acf9418fad1ae
humanhash: arizona-magnesium-india-seven
File name:goahead
Download: download sample
Signature Mirai
File size:1'074 bytes
First seen:2025-09-08 16:34:31 UTC
Last seen:2025-09-09 14:41:30 UTC
File type: sh
MIME type:text/plain
ssdeep 24:IiScySSWkKaxVUyCCoQ0NeXYH0OzYK8KNIyZklQIGyBr:IiPybWkKaxiyCCoQ0NeXw0OzY76ZklQ6
TLSH T18C11E2DE6861B541440A7F8461F23734B811D1D123A0AF8DEED82EB587CCE2071F9BC5
Magika javascript
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://109.205.213.5/resgod.x86b0ff5d417b98975a78c034c4c9ed42cd68813c8c3415ea894b7687e06c10cf3b Miraielf mirai
http://109.205.213.5/resgod.spc6e0f15c3a92edea0104cd9050dea4f26e61ccccb0c04503c0574a0ea4c6d8c1a Miraielf mirai ua-wget
http://109.205.213.5/resgod.sh4d9c3bdbfc3930340483c07ff809d21b3a70c431b4e93b0938c010a90bd629538 Miraielf mirai
http://109.205.213.5/resgod.ppc79c1d9a2427318b5bfedc8040e8d3bdbd503892b3ad16c641b62886e03efa1f4 Miraielf mirai
http://109.205.213.5/resgod.mpslab2e398b9d039ff05a0e2361e7b8391e1957e0252efab1ff4a37efbadcdc8357 Miraielf mirai
http://109.205.213.5/resgod.mipsa829c07ba77c4fa8e2153e65e68b14ffa0fe8bfb5da8b0643ecd43ad63f20506 Miraielf mirai
http://109.205.213.5/resgod.m68kd062d1cf10cc8da9da71b159e7d7dcf62990cd6bcc32041ed8f7e4151621c6be Miraielf mirai ua-wget
http://109.205.213.5/resgod.arm7ab1a7156179e8ba66177bfe455a2a00e0bdec190e2dda53fe046518853d93a06 Miraielf mirai
http://109.205.213.5/resgod.arm646de942f38760912e646e5832eb6dbc8dc128b8f8e20b678de7e2e34c4ea1300 Miraielf mirai
http://109.205.213.5/resgod.arm5e89328219e412a061745f826ee6ad9be1a56ea91de224f3178a93b63375604b9 Miraielf mirai
http://109.205.213.5/resgod.arm6139cadea1690b3f429e693688a7c024b596d373d592ee6d2e7edb77bc436fe2 Miraielf mirai
http://109.205.213.5/resgod.arc3c1f47cb749115c78ccb72e75eb06e3a0b8f5ec68169c55b0bbf4674b9c35f7a Miraielf mirai

Intelligence


File Origin
# of uploads :
4
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-09-08T14:32:00Z UTC
Last seen:
2025-09-08T14:32:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=19c177b5-1c00-0000-9a75-a5a2100a0000 pid=2576 /usr/bin/sudo guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585 /tmp/sample.bin guuid=19c177b5-1c00-0000-9a75-a5a2100a0000 pid=2576->guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585 execve guuid=efcc4cb8-1c00-0000-9a75-a5a21b0a0000 pid=2587 /usr/bin/wget net send-data guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=efcc4cb8-1c00-0000-9a75-a5a21b0a0000 pid=2587 execve guuid=640c9ec6-1c00-0000-9a75-a5a2430a0000 pid=2627 /usr/bin/chmod guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=640c9ec6-1c00-0000-9a75-a5a2430a0000 pid=2627 execve guuid=ec59e1c6-1c00-0000-9a75-a5a2450a0000 pid=2629 /usr/bin/dash guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=ec59e1c6-1c00-0000-9a75-a5a2450a0000 pid=2629 clone guuid=7694ebc6-1c00-0000-9a75-a5a2460a0000 pid=2630 /usr/bin/wget net send-data guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=7694ebc6-1c00-0000-9a75-a5a2460a0000 pid=2630 execve guuid=5e6eb2d1-1c00-0000-9a75-a5a2600a0000 pid=2656 /usr/bin/chmod guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=5e6eb2d1-1c00-0000-9a75-a5a2600a0000 pid=2656 execve guuid=19232fd2-1c00-0000-9a75-a5a2620a0000 pid=2658 /usr/bin/dash guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=19232fd2-1c00-0000-9a75-a5a2620a0000 pid=2658 clone guuid=cbf93cd2-1c00-0000-9a75-a5a2630a0000 pid=2659 /usr/bin/wget net send-data guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=cbf93cd2-1c00-0000-9a75-a5a2630a0000 pid=2659 execve guuid=629f0cdd-1c00-0000-9a75-a5a2800a0000 pid=2688 /usr/bin/chmod guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=629f0cdd-1c00-0000-9a75-a5a2800a0000 pid=2688 execve guuid=6af879dd-1c00-0000-9a75-a5a2820a0000 pid=2690 /usr/bin/dash guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=6af879dd-1c00-0000-9a75-a5a2820a0000 pid=2690 clone guuid=704488dd-1c00-0000-9a75-a5a2830a0000 pid=2691 /usr/bin/wget net send-data guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=704488dd-1c00-0000-9a75-a5a2830a0000 pid=2691 execve guuid=805df1e9-1c00-0000-9a75-a5a2a80a0000 pid=2728 /usr/bin/chmod guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=805df1e9-1c00-0000-9a75-a5a2a80a0000 pid=2728 execve guuid=c89e48ea-1c00-0000-9a75-a5a2a90a0000 pid=2729 /usr/bin/dash guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=c89e48ea-1c00-0000-9a75-a5a2a90a0000 pid=2729 clone guuid=381958ea-1c00-0000-9a75-a5a2aa0a0000 pid=2730 /usr/bin/wget net send-data guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=381958ea-1c00-0000-9a75-a5a2aa0a0000 pid=2730 execve guuid=01a588f5-1c00-0000-9a75-a5a2c40a0000 pid=2756 /usr/bin/chmod guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=01a588f5-1c00-0000-9a75-a5a2c40a0000 pid=2756 execve guuid=9436e5f5-1c00-0000-9a75-a5a2c60a0000 pid=2758 /usr/bin/dash guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=9436e5f5-1c00-0000-9a75-a5a2c60a0000 pid=2758 clone guuid=ed95f3f5-1c00-0000-9a75-a5a2c80a0000 pid=2760 /usr/bin/wget net send-data guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=ed95f3f5-1c00-0000-9a75-a5a2c80a0000 pid=2760 execve guuid=31ca0f01-1d00-0000-9a75-a5a2dc0a0000 pid=2780 /usr/bin/chmod guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=31ca0f01-1d00-0000-9a75-a5a2dc0a0000 pid=2780 execve guuid=9f4c7901-1d00-0000-9a75-a5a2de0a0000 pid=2782 /usr/bin/dash guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=9f4c7901-1d00-0000-9a75-a5a2de0a0000 pid=2782 clone guuid=49a18801-1d00-0000-9a75-a5a2df0a0000 pid=2783 /usr/bin/wget net send-data guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=49a18801-1d00-0000-9a75-a5a2df0a0000 pid=2783 execve guuid=04fb8f0d-1d00-0000-9a75-a5a2ea0a0000 pid=2794 /usr/bin/chmod guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=04fb8f0d-1d00-0000-9a75-a5a2ea0a0000 pid=2794 execve guuid=f8340a0e-1d00-0000-9a75-a5a2eb0a0000 pid=2795 /usr/bin/dash guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=f8340a0e-1d00-0000-9a75-a5a2eb0a0000 pid=2795 clone guuid=3977180e-1d00-0000-9a75-a5a2ec0a0000 pid=2796 /usr/bin/wget net send-data guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=3977180e-1d00-0000-9a75-a5a2ec0a0000 pid=2796 execve guuid=92f91119-1d00-0000-9a75-a5a2000b0000 pid=2816 /usr/bin/chmod guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=92f91119-1d00-0000-9a75-a5a2000b0000 pid=2816 execve guuid=99bd5c19-1d00-0000-9a75-a5a2020b0000 pid=2818 /usr/bin/dash guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=99bd5c19-1d00-0000-9a75-a5a2020b0000 pid=2818 clone guuid=576a6c19-1d00-0000-9a75-a5a2040b0000 pid=2820 /usr/bin/wget net send-data guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=576a6c19-1d00-0000-9a75-a5a2040b0000 pid=2820 execve guuid=be28bc24-1d00-0000-9a75-a5a2140b0000 pid=2836 /usr/bin/chmod guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=be28bc24-1d00-0000-9a75-a5a2140b0000 pid=2836 execve guuid=5d76fe24-1d00-0000-9a75-a5a2160b0000 pid=2838 /usr/bin/dash guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=5d76fe24-1d00-0000-9a75-a5a2160b0000 pid=2838 clone guuid=d95c0b25-1d00-0000-9a75-a5a2170b0000 pid=2839 /usr/bin/wget net send-data guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=d95c0b25-1d00-0000-9a75-a5a2170b0000 pid=2839 execve guuid=5f959b2f-1d00-0000-9a75-a5a2290b0000 pid=2857 /usr/bin/chmod guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=5f959b2f-1d00-0000-9a75-a5a2290b0000 pid=2857 execve guuid=4ecee22f-1d00-0000-9a75-a5a22b0b0000 pid=2859 /usr/bin/dash guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=4ecee22f-1d00-0000-9a75-a5a22b0b0000 pid=2859 clone guuid=d723ea2f-1d00-0000-9a75-a5a22c0b0000 pid=2860 /usr/bin/wget net send-data guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=d723ea2f-1d00-0000-9a75-a5a22c0b0000 pid=2860 execve guuid=8e4cd83a-1d00-0000-9a75-a5a2400b0000 pid=2880 /usr/bin/chmod guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=8e4cd83a-1d00-0000-9a75-a5a2400b0000 pid=2880 execve guuid=07983a3b-1d00-0000-9a75-a5a2420b0000 pid=2882 /usr/bin/dash guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=07983a3b-1d00-0000-9a75-a5a2420b0000 pid=2882 clone guuid=bed04b3b-1d00-0000-9a75-a5a2430b0000 pid=2883 /usr/bin/wget net send-data guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=bed04b3b-1d00-0000-9a75-a5a2430b0000 pid=2883 execve guuid=9ff9e646-1d00-0000-9a75-a5a25d0b0000 pid=2909 /usr/bin/chmod guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=9ff9e646-1d00-0000-9a75-a5a25d0b0000 pid=2909 execve guuid=f0704947-1d00-0000-9a75-a5a25f0b0000 pid=2911 /usr/bin/dash guuid=925e07b8-1c00-0000-9a75-a5a2190a0000 pid=2585->guuid=f0704947-1d00-0000-9a75-a5a25f0b0000 pid=2911 clone 9df19bce-d755-5940-91ff-d0e847757959 109.205.213.5:80 guuid=efcc4cb8-1c00-0000-9a75-a5a21b0a0000 pid=2587->9df19bce-d755-5940-91ff-d0e847757959 send: 138B guuid=7694ebc6-1c00-0000-9a75-a5a2460a0000 pid=2630->9df19bce-d755-5940-91ff-d0e847757959 send: 138B guuid=cbf93cd2-1c00-0000-9a75-a5a2630a0000 pid=2659->9df19bce-d755-5940-91ff-d0e847757959 send: 138B guuid=704488dd-1c00-0000-9a75-a5a2830a0000 pid=2691->9df19bce-d755-5940-91ff-d0e847757959 send: 138B guuid=381958ea-1c00-0000-9a75-a5a2aa0a0000 pid=2730->9df19bce-d755-5940-91ff-d0e847757959 send: 139B guuid=ed95f3f5-1c00-0000-9a75-a5a2c80a0000 pid=2760->9df19bce-d755-5940-91ff-d0e847757959 send: 139B guuid=49a18801-1d00-0000-9a75-a5a2df0a0000 pid=2783->9df19bce-d755-5940-91ff-d0e847757959 send: 139B guuid=3977180e-1d00-0000-9a75-a5a2ec0a0000 pid=2796->9df19bce-d755-5940-91ff-d0e847757959 send: 139B guuid=576a6c19-1d00-0000-9a75-a5a2040b0000 pid=2820->9df19bce-d755-5940-91ff-d0e847757959 send: 139B guuid=d95c0b25-1d00-0000-9a75-a5a2170b0000 pid=2839->9df19bce-d755-5940-91ff-d0e847757959 send: 139B guuid=d723ea2f-1d00-0000-9a75-a5a22c0b0000 pid=2860->9df19bce-d755-5940-91ff-d0e847757959 send: 138B guuid=bed04b3b-1d00-0000-9a75-a5a2430b0000 pid=2883->9df19bce-d755-5940-91ff-d0e847757959 send: 138B
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-09-08 17:16:53 UTC
File Type:
Text (Shell)
AV detection:
18 of 38 (47.37%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 70f17fa4dfb42d1487466f5ac56b954f301ff48398fbf0a87b2fdebcb5a3bb59

(this sample)

  
Delivery method
Distributed via web download

Comments