MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 73f2d6a2e72911c7c2f7e4ac44b2b560cb0e98f47bfa12f211d9e0703f240dc8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 73f2d6a2e72911c7c2f7e4ac44b2b560cb0e98f47bfa12f211d9e0703f240dc8
SHA3-384 hash: 6e4a14653651e1b702f79b8ad03406f30f1e42388e14dd8fa0134d1c41eb45d9d9ce4b2780554d63b76eb0092f10bd07
SHA1 hash: d6450f1023d4f3ac7b9d4346f5806955409770f8
MD5 hash: bb21f4d5758cd3ed3c58d24133a2e071
humanhash: victor-hot-six-massachusetts
File name:shell
Download: download sample
Signature Mirai
File size:281 bytes
First seen:2025-06-15 22:03:33 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hJa6SHzi7W5juL6QFuTPrCsp2Hu/Y3WI+a7uFsCFQGALcKW:t0ziNFuTP2sougGI+aiFsC2LcKW
TLSH T1DBD02B950996247A053A1A7FE27B2918A60C4047FC53D275FBCAAD26CFCA6107450C41
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
mirai agent virus shell
Status:
terminated
Behavior Graph:
%3 guuid=37ed86d4-2000-0000-76f9-dd457a0a0000 pid=2682 /usr/bin/sudo guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690 /tmp/sample.bin guuid=37ed86d4-2000-0000-76f9-dd457a0a0000 pid=2682->guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690 execve guuid=31355cd6-2000-0000-76f9-dd45840a0000 pid=2692 /usr/bin/rm guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=31355cd6-2000-0000-76f9-dd45840a0000 pid=2692 execve guuid=bd7997d6-2000-0000-76f9-dd45850a0000 pid=2693 /usr/bin/cp guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=bd7997d6-2000-0000-76f9-dd45850a0000 pid=2693 execve guuid=161e69d7-2000-0000-76f9-dd45890a0000 pid=2697 /usr/bin/chmod guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=161e69d7-2000-0000-76f9-dd45890a0000 pid=2697 execve guuid=c5fbb3d7-2000-0000-76f9-dd458b0a0000 pid=2699 /usr/bin/wget net send-data guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=c5fbb3d7-2000-0000-76f9-dd458b0a0000 pid=2699 execve guuid=7baf01f5-2000-0000-76f9-dd45d40a0000 pid=2772 /home/sandbox/.z guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=7baf01f5-2000-0000-76f9-dd45d40a0000 pid=2772 execve guuid=89e4c1f5-2000-0000-76f9-dd45d80a0000 pid=2776 /usr/bin/rm delete-file guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=89e4c1f5-2000-0000-76f9-dd45d80a0000 pid=2776 execve guuid=19d801f6-2000-0000-76f9-dd45d90a0000 pid=2777 /usr/bin/cp guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=19d801f6-2000-0000-76f9-dd45d90a0000 pid=2777 execve guuid=6d6283f9-2000-0000-76f9-dd45e00a0000 pid=2784 /usr/bin/chmod guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=6d6283f9-2000-0000-76f9-dd45e00a0000 pid=2784 execve guuid=7abff0f9-2000-0000-76f9-dd45e10a0000 pid=2785 /usr/bin/wget net send-data guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=7abff0f9-2000-0000-76f9-dd45e10a0000 pid=2785 execve guuid=b41e3118-2100-0000-76f9-dd451e0b0000 pid=2846 /home/sandbox/.z guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=b41e3118-2100-0000-76f9-dd451e0b0000 pid=2846 execve guuid=ef1f4f19-2100-0000-76f9-dd45220b0000 pid=2850 /usr/bin/rm delete-file guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=ef1f4f19-2100-0000-76f9-dd45220b0000 pid=2850 execve guuid=af6ec519-2100-0000-76f9-dd45240b0000 pid=2852 /usr/bin/cp guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=af6ec519-2100-0000-76f9-dd45240b0000 pid=2852 execve guuid=0815d31b-2100-0000-76f9-dd45280b0000 pid=2856 /usr/bin/chmod guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=0815d31b-2100-0000-76f9-dd45280b0000 pid=2856 execve guuid=0c00401c-2100-0000-76f9-dd45290b0000 pid=2857 /usr/bin/wget net send-data guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=0c00401c-2100-0000-76f9-dd45290b0000 pid=2857 execve guuid=0fe4ba39-2100-0000-76f9-dd45710b0000 pid=2929 /home/sandbox/.z guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=0fe4ba39-2100-0000-76f9-dd45710b0000 pid=2929 execve guuid=cde0ad3a-2100-0000-76f9-dd45760b0000 pid=2934 /usr/bin/rm delete-file guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=cde0ad3a-2100-0000-76f9-dd45760b0000 pid=2934 execve guuid=218afa3a-2100-0000-76f9-dd45770b0000 pid=2935 /usr/bin/cp guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=218afa3a-2100-0000-76f9-dd45770b0000 pid=2935 execve guuid=b6e6633c-2100-0000-76f9-dd45780b0000 pid=2936 /usr/bin/chmod guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=b6e6633c-2100-0000-76f9-dd45780b0000 pid=2936 execve guuid=4db2cb3c-2100-0000-76f9-dd45790b0000 pid=2937 /usr/bin/wget net send-data guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=4db2cb3c-2100-0000-76f9-dd45790b0000 pid=2937 execve guuid=0134225d-2100-0000-76f9-dd45a90b0000 pid=2985 /home/sandbox/.z guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=0134225d-2100-0000-76f9-dd45a90b0000 pid=2985 execve guuid=ff05005f-2100-0000-76f9-dd45ad0b0000 pid=2989 /usr/bin/rm delete-file guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=ff05005f-2100-0000-76f9-dd45ad0b0000 pid=2989 execve guuid=076a645f-2100-0000-76f9-dd45ae0b0000 pid=2990 /usr/bin/cp guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=076a645f-2100-0000-76f9-dd45ae0b0000 pid=2990 execve guuid=0a6af862-2100-0000-76f9-dd45b60b0000 pid=2998 /usr/bin/chmod guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=0a6af862-2100-0000-76f9-dd45b60b0000 pid=2998 execve guuid=76303e63-2100-0000-76f9-dd45b70b0000 pid=2999 /usr/bin/wget net send-data guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=76303e63-2100-0000-76f9-dd45b70b0000 pid=2999 execve guuid=5e6fb580-2100-0000-76f9-dd45080c0000 pid=3080 /home/sandbox/.z guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=5e6fb580-2100-0000-76f9-dd45080c0000 pid=3080 execve guuid=cf0bca81-2100-0000-76f9-dd450d0c0000 pid=3085 /usr/bin/rm delete-file guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=cf0bca81-2100-0000-76f9-dd450d0c0000 pid=3085 execve guuid=08b12882-2100-0000-76f9-dd450f0c0000 pid=3087 /usr/bin/cp guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=08b12882-2100-0000-76f9-dd450f0c0000 pid=3087 execve guuid=fa836f85-2100-0000-76f9-dd45190c0000 pid=3097 /usr/bin/chmod guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=fa836f85-2100-0000-76f9-dd45190c0000 pid=3097 execve guuid=bff3b185-2100-0000-76f9-dd451b0c0000 pid=3099 /usr/bin/wget net send-data guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=bff3b185-2100-0000-76f9-dd451b0c0000 pid=3099 execve guuid=fc0879a4-2100-0000-76f9-dd456f0c0000 pid=3183 /home/sandbox/.z guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=fc0879a4-2100-0000-76f9-dd456f0c0000 pid=3183 execve guuid=eede1fa5-2100-0000-76f9-dd45730c0000 pid=3187 /usr/bin/rm delete-file guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=eede1fa5-2100-0000-76f9-dd45730c0000 pid=3187 execve guuid=f54064a5-2100-0000-76f9-dd45740c0000 pid=3188 /usr/bin/cp guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=f54064a5-2100-0000-76f9-dd45740c0000 pid=3188 execve guuid=da0260a6-2100-0000-76f9-dd45760c0000 pid=3190 /usr/bin/chmod guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=da0260a6-2100-0000-76f9-dd45760c0000 pid=3190 execve guuid=7d38b5a6-2100-0000-76f9-dd45770c0000 pid=3191 /usr/bin/wget net send-data guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=7d38b5a6-2100-0000-76f9-dd45770c0000 pid=3191 execve guuid=755b75c5-2100-0000-76f9-dd45970c0000 pid=3223 /home/sandbox/.z guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=755b75c5-2100-0000-76f9-dd45970c0000 pid=3223 execve guuid=317f8dc7-2100-0000-76f9-dd459e0c0000 pid=3230 /usr/bin/rm delete-file guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=317f8dc7-2100-0000-76f9-dd459e0c0000 pid=3230 execve guuid=9917f1c7-2100-0000-76f9-dd45a00c0000 pid=3232 /usr/bin/cp guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=9917f1c7-2100-0000-76f9-dd45a00c0000 pid=3232 execve guuid=8c98d0c8-2100-0000-76f9-dd45a30c0000 pid=3235 /usr/bin/chmod guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=8c98d0c8-2100-0000-76f9-dd45a30c0000 pid=3235 execve guuid=d78741c9-2100-0000-76f9-dd45a50c0000 pid=3237 /usr/bin/wget net send-data guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=d78741c9-2100-0000-76f9-dd45a50c0000 pid=3237 execve guuid=ad675ee8-2100-0000-76f9-dd45c60c0000 pid=3270 /home/sandbox/.z guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=ad675ee8-2100-0000-76f9-dd45c60c0000 pid=3270 execve guuid=f107fae9-2100-0000-76f9-dd45cd0c0000 pid=3277 /usr/bin/rm delete-file guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=f107fae9-2100-0000-76f9-dd45cd0c0000 pid=3277 execve guuid=914f53ea-2100-0000-76f9-dd45cf0c0000 pid=3279 /usr/bin/cp guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=914f53ea-2100-0000-76f9-dd45cf0c0000 pid=3279 execve guuid=aca124ed-2100-0000-76f9-dd45d00c0000 pid=3280 /usr/bin/chmod guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=aca124ed-2100-0000-76f9-dd45d00c0000 pid=3280 execve guuid=4d06aded-2100-0000-76f9-dd45d10c0000 pid=3281 /usr/bin/wget net send-data guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=4d06aded-2100-0000-76f9-dd45d10c0000 pid=3281 execve guuid=2c607c0c-2200-0000-76f9-dd450d0d0000 pid=3341 /home/sandbox/.z guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=2c607c0c-2200-0000-76f9-dd450d0d0000 pid=3341 execve guuid=29cc620d-2200-0000-76f9-dd45100d0000 pid=3344 /usr/bin/rm delete-file guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=29cc620d-2200-0000-76f9-dd45100d0000 pid=3344 execve guuid=5da6b00d-2200-0000-76f9-dd45110d0000 pid=3345 /usr/bin/cp guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=5da6b00d-2200-0000-76f9-dd45110d0000 pid=3345 execve guuid=d8399f0e-2200-0000-76f9-dd45120d0000 pid=3346 /usr/bin/chmod guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=d8399f0e-2200-0000-76f9-dd45120d0000 pid=3346 execve guuid=b6c4e80e-2200-0000-76f9-dd45140d0000 pid=3348 /usr/bin/wget net send-data guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=b6c4e80e-2200-0000-76f9-dd45140d0000 pid=3348 execve guuid=48d1fd2b-2200-0000-76f9-dd45430d0000 pid=3395 /home/sandbox/.z guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=48d1fd2b-2200-0000-76f9-dd45430d0000 pid=3395 execve guuid=bf1de22c-2200-0000-76f9-dd45470d0000 pid=3399 /usr/bin/rm delete-file guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=bf1de22c-2200-0000-76f9-dd45470d0000 pid=3399 execve guuid=be332d2d-2200-0000-76f9-dd45480d0000 pid=3400 /usr/bin/cp guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=be332d2d-2200-0000-76f9-dd45480d0000 pid=3400 execve guuid=0d9f2c31-2200-0000-76f9-dd45520d0000 pid=3410 /usr/bin/chmod guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=0d9f2c31-2200-0000-76f9-dd45520d0000 pid=3410 execve guuid=39fa7331-2200-0000-76f9-dd45530d0000 pid=3411 /usr/bin/wget net send-data guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=39fa7331-2200-0000-76f9-dd45530d0000 pid=3411 execve guuid=c869df4f-2200-0000-76f9-dd45a60d0000 pid=3494 /home/sandbox/.z guuid=a2982cd6-2000-0000-76f9-dd45820a0000 pid=2690->guuid=c869df4f-2200-0000-76f9-dd45a60d0000 pid=3494 execve b95ce511-3591-5114-995b-9ce77bb440cb 103.149.252.178:80 guuid=c5fbb3d7-2000-0000-76f9-dd458b0a0000 pid=2699->b95ce511-3591-5114-995b-9ce77bb440cb send: 139B guuid=7abff0f9-2000-0000-76f9-dd45e10a0000 pid=2785->b95ce511-3591-5114-995b-9ce77bb440cb send: 138B guuid=0c00401c-2100-0000-76f9-dd45290b0000 pid=2857->b95ce511-3591-5114-995b-9ce77bb440cb send: 139B guuid=4db2cb3c-2100-0000-76f9-dd45790b0000 pid=2937->b95ce511-3591-5114-995b-9ce77bb440cb send: 141B guuid=76303e63-2100-0000-76f9-dd45b70b0000 pid=2999->b95ce511-3591-5114-995b-9ce77bb440cb send: 142B guuid=bff3b185-2100-0000-76f9-dd451b0c0000 pid=3099->b95ce511-3591-5114-995b-9ce77bb440cb send: 139B guuid=7d38b5a6-2100-0000-76f9-dd45770c0000 pid=3191->b95ce511-3591-5114-995b-9ce77bb440cb send: 138B guuid=d78741c9-2100-0000-76f9-dd45a50c0000 pid=3237->b95ce511-3591-5114-995b-9ce77bb440cb send: 140B guuid=4d06aded-2100-0000-76f9-dd45d10c0000 pid=3281->b95ce511-3591-5114-995b-9ce77bb440cb send: 141B guuid=b6c4e80e-2200-0000-76f9-dd45140d0000 pid=3348->b95ce511-3591-5114-995b-9ce77bb440cb send: 141B guuid=39fa7331-2200-0000-76f9-dd45530d0000 pid=3411->b95ce511-3591-5114-995b-9ce77bb440cb send: 139B
Threat name:
Linux.Downloader.MiraiB
Status:
Malicious
First seen:
2025-06-15 22:58:45 UTC
File Type:
Text (Shell)
AV detection:
14 of 38 (36.84%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 73f2d6a2e72911c7c2f7e4ac44b2b560cb0e98f47bfa12f211d9e0703f240dc8

(this sample)

  
Delivery method
Distributed via web download

Comments