MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 70f341f6de13cd88d681d64e2726afb96eb421a715e1ac29f7b62a4ae0d54be6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 70f341f6de13cd88d681d64e2726afb96eb421a715e1ac29f7b62a4ae0d54be6
SHA3-384 hash: ee446c2ead336ca5522f6aafdb0677fd58c49452b03f73c9a657a8f2d86419a41a626de7bf6513a0c0c2197e66124bdd
SHA1 hash: c3795d99c4134f21ccf60742107d00d49cc64ae2
MD5 hash: 9d10d22c5656c3992cdafef7312b3ceb
humanhash: romeo-table-crazy-river
File name:f
Download: download sample
Signature Mirai
File size:277 bytes
First seen:2026-07-18 01:42:30 UTC
Last seen:2026-07-18 17:41:38 UTC
File type: sh
MIME type:text/plain
ssdeep 6:L2gWFYju/gWFYMDNk3aoseugm8FoZu/gm8FhDNk3aose3:Cgeg8DNk3axgmLZ6gmiDNk3aK
TLSH T15FD08CDF11101A200D80A84D3AE3B48E684280E9A08CDE49A8484221A58580C7028F8C
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.249.125.141/gmpslcc6964a4808fddb922b8889d83fd0724f6bab22125458690ab189a93978b2638 Miraicensys elf mirai ua-wget
http://162.249.125.141/gmipsfd0ff75925ea15760d72c1a9ffbcc0e751abebb2f4cd49f0bd11274a04706217 Miraicensys elf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
408
# of downloads :
12
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-07-17T23:55:00Z UTC
Last seen:
2026-07-19T22:12:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=72f716ae-1a00-0000-db48-71f31e0a0000 pid=2590 /usr/bin/sudo guuid=c8d5f0b0-1a00-0000-db48-71f3260a0000 pid=2598 /tmp/sample.bin guuid=72f716ae-1a00-0000-db48-71f31e0a0000 pid=2590->guuid=c8d5f0b0-1a00-0000-db48-71f3260a0000 pid=2598 execve guuid=9d2956b1-1a00-0000-db48-71f3280a0000 pid=2600 /usr/bin/dash guuid=c8d5f0b0-1a00-0000-db48-71f3260a0000 pid=2598->guuid=9d2956b1-1a00-0000-db48-71f3280a0000 pid=2600 clone guuid=e545bac6-1a00-0000-db48-71f3620a0000 pid=2658 /usr/bin/chmod guuid=c8d5f0b0-1a00-0000-db48-71f3260a0000 pid=2598->guuid=e545bac6-1a00-0000-db48-71f3620a0000 pid=2658 execve guuid=28650ec7-1a00-0000-db48-71f3640a0000 pid=2660 /usr/bin/dash guuid=c8d5f0b0-1a00-0000-db48-71f3260a0000 pid=2598->guuid=28650ec7-1a00-0000-db48-71f3640a0000 pid=2660 clone guuid=2bda02c9-1a00-0000-db48-71f3670a0000 pid=2663 /usr/bin/rm delete-file guuid=c8d5f0b0-1a00-0000-db48-71f3260a0000 pid=2598->guuid=2bda02c9-1a00-0000-db48-71f3670a0000 pid=2663 execve guuid=6a664ac9-1a00-0000-db48-71f3690a0000 pid=2665 /usr/bin/dash guuid=c8d5f0b0-1a00-0000-db48-71f3260a0000 pid=2598->guuid=6a664ac9-1a00-0000-db48-71f3690a0000 pid=2665 clone guuid=9227b7da-1a00-0000-db48-71f3870a0000 pid=2695 /usr/bin/chmod guuid=c8d5f0b0-1a00-0000-db48-71f3260a0000 pid=2598->guuid=9227b7da-1a00-0000-db48-71f3870a0000 pid=2695 execve guuid=796cfada-1a00-0000-db48-71f3880a0000 pid=2696 /usr/bin/dash guuid=c8d5f0b0-1a00-0000-db48-71f3260a0000 pid=2598->guuid=796cfada-1a00-0000-db48-71f3880a0000 pid=2696 clone guuid=8561a9db-1a00-0000-db48-71f38b0a0000 pid=2699 /usr/bin/rm delete-file guuid=c8d5f0b0-1a00-0000-db48-71f3260a0000 pid=2598->guuid=8561a9db-1a00-0000-db48-71f38b0a0000 pid=2699 execve guuid=190465b1-1a00-0000-db48-71f3290a0000 pid=2601 /usr/bin/busybox net send-data write-file guuid=9d2956b1-1a00-0000-db48-71f3280a0000 pid=2600->guuid=190465b1-1a00-0000-db48-71f3290a0000 pid=2601 execve 922b8aa5-64e3-558c-a654-34cc3d1ae30e 162.249.125.141:80 guuid=190465b1-1a00-0000-db48-71f3290a0000 pid=2601->922b8aa5-64e3-558c-a654-34cc3d1ae30e send: 83B guuid=4fd154c9-1a00-0000-db48-71f36a0a0000 pid=2666 /usr/bin/busybox net send-data write-file guuid=6a664ac9-1a00-0000-db48-71f3690a0000 pid=2665->guuid=4fd154c9-1a00-0000-db48-71f36a0a0000 pid=2666 execve guuid=4fd154c9-1a00-0000-db48-71f36a0a0000 pid=2666->922b8aa5-64e3-558c-a654-34cc3d1ae30e send: 83B
Gathering data
Threat name:
Script-BAT.Trojan.Sonbokli
Status:
Malicious
First seen:
2026-07-18 05:04:02 UTC
File Type:
Text (Shell)
AV detection:
7 of 38 (18.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 70f341f6de13cd88d681d64e2726afb96eb421a715e1ac29f7b62a4ae0d54be6

(this sample)

  
Delivery method
Distributed via web download

Comments