🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7ed2ce6d2ce3d7dc061977ee90fe41320e8bb910d9a6c52bbdcd13a60bc30186. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 7ed2ce6d2ce3d7dc061977ee90fe41320e8bb910d9a6c52bbdcd13a60bc30186
SHA3-384 hash: 7e778d86e62f5373789057cbdf554548c69476ac5c224bb358d2e08d8694fab0a1c43a6f47c17ea322959523e2c400db
SHA1 hash: 31df2a5616cbfcde6a2381559bdad03ddd916b15
MD5 hash: e73610bb68cf9467f4b1f19a7890fb3a
humanhash: snake-nine-rugby-mike
File name:wget.sh
Download: download sample
Signature Mirai
File size:516 bytes
First seen:2026-05-03 07:47:16 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:KSs6wZNzQNyHe0uNzRsHNl8OSYeJBONl8p5pB:KSKZNzQ6MzRstlle8lqpB
TLSH T152F024DE0A74365245CCCA4FB7D38909104E83CE269F1BCD7EDD08A6E640BE9F044E58
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.104.63.91/arm56ca41e94a25129be2ceb7e800cf26a333433e4214fba40465645c9159de77015 Miraielf mips mirai wget
http://185.104.63.91/arm7b7506dc4658335ba227f0eed574e5651fffc1b07997c2ec7b16435918e3c8d06 Miraielf mips mirai wget
http://185.104.63.91/mipsa4adb6140b1e746597097f9f8b101ff548aae4207573afebd442e08afe296cdd Miraielf mips mirai wget
http://185.104.63.91/mipselda3437201802fed5ce0b843bd4639deed3314679d472958d77efb33bb8986fe8 Miraielf mips mirai wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
bash busybox lolbin mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-01T11:03:00Z UTC
Last seen:
2026-05-03T06:36:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=a599537e-1700-0000-dc28-9afbfa0c0000 pid=3322 /usr/bin/sudo guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323 /tmp/sample.bin guuid=a599537e-1700-0000-dc28-9afbfa0c0000 pid=3322->guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323 execve guuid=d3dce081-1700-0000-dc28-9afbfc0c0000 pid=3324 /usr/bin/rm guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=d3dce081-1700-0000-dc28-9afbfc0c0000 pid=3324 execve guuid=d62e3682-1700-0000-dc28-9afbfd0c0000 pid=3325 /usr/bin/rm guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=d62e3682-1700-0000-dc28-9afbfd0c0000 pid=3325 execve guuid=d2ab8882-1700-0000-dc28-9afbfe0c0000 pid=3326 /usr/bin/rm guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=d2ab8882-1700-0000-dc28-9afbfe0c0000 pid=3326 execve guuid=2bafd582-1700-0000-dc28-9afbff0c0000 pid=3327 /usr/bin/rm guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=2bafd582-1700-0000-dc28-9afbff0c0000 pid=3327 execve guuid=e77d2383-1700-0000-dc28-9afb000d0000 pid=3328 /usr/bin/rm guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=e77d2383-1700-0000-dc28-9afb000d0000 pid=3328 execve guuid=4bc27683-1700-0000-dc28-9afb010d0000 pid=3329 /usr/bin/rm guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=4bc27683-1700-0000-dc28-9afb010d0000 pid=3329 execve guuid=563fbd83-1700-0000-dc28-9afb030d0000 pid=3331 /usr/bin/rm guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=563fbd83-1700-0000-dc28-9afb030d0000 pid=3331 execve guuid=f8e5fb83-1700-0000-dc28-9afb040d0000 pid=3332 /usr/bin/cp guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=f8e5fb83-1700-0000-dc28-9afb040d0000 pid=3332 execve guuid=4094ef88-1700-0000-dc28-9afb0e0d0000 pid=3342 /usr/bin/busybox net send-data write-file guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=4094ef88-1700-0000-dc28-9afb0e0d0000 pid=3342 execve guuid=01758c8e-1700-0000-dc28-9afb180d0000 pid=3352 /usr/bin/chmod guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=01758c8e-1700-0000-dc28-9afb180d0000 pid=3352 execve guuid=341a038f-1700-0000-dc28-9afb190d0000 pid=3353 /usr/bin/dash guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=341a038f-1700-0000-dc28-9afb190d0000 pid=3353 clone guuid=3b258790-1700-0000-dc28-9afb1b0d0000 pid=3355 /usr/bin/busybox net send-data write-file guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=3b258790-1700-0000-dc28-9afb1b0d0000 pid=3355 execve guuid=b8752796-1700-0000-dc28-9afb2b0d0000 pid=3371 /usr/bin/chmod guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=b8752796-1700-0000-dc28-9afb2b0d0000 pid=3371 execve guuid=cab56c96-1700-0000-dc28-9afb2d0d0000 pid=3373 /usr/bin/dash guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=cab56c96-1700-0000-dc28-9afb2d0d0000 pid=3373 clone guuid=67076997-1700-0000-dc28-9afb310d0000 pid=3377 /usr/bin/busybox net send-data write-file guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=67076997-1700-0000-dc28-9afb310d0000 pid=3377 execve guuid=4a76119d-1700-0000-dc28-9afb3c0d0000 pid=3388 /usr/bin/chmod guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=4a76119d-1700-0000-dc28-9afb3c0d0000 pid=3388 execve guuid=df7f8f9d-1700-0000-dc28-9afb3e0d0000 pid=3390 /usr/bin/dash guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=df7f8f9d-1700-0000-dc28-9afb3e0d0000 pid=3390 clone guuid=257d6f9e-1700-0000-dc28-9afb420d0000 pid=3394 /usr/bin/busybox net send-data write-file guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=257d6f9e-1700-0000-dc28-9afb420d0000 pid=3394 execve guuid=daf066a5-1700-0000-dc28-9afb500d0000 pid=3408 /usr/bin/chmod guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=daf066a5-1700-0000-dc28-9afb500d0000 pid=3408 execve guuid=afb6faa5-1700-0000-dc28-9afb510d0000 pid=3409 /usr/bin/dash guuid=3c3f8881-1700-0000-dc28-9afbfb0c0000 pid=3323->guuid=afb6faa5-1700-0000-dc28-9afb510d0000 pid=3409 clone b520467e-a7f6-5a27-a09d-dcf4d704d509 185.104.63.91:80 guuid=4094ef88-1700-0000-dc28-9afb0e0d0000 pid=3342->b520467e-a7f6-5a27-a09d-dcf4d704d509 send: 80B guuid=3b258790-1700-0000-dc28-9afb1b0d0000 pid=3355->b520467e-a7f6-5a27-a09d-dcf4d704d509 send: 80B guuid=67076997-1700-0000-dc28-9afb310d0000 pid=3377->b520467e-a7f6-5a27-a09d-dcf4d704d509 send: 80B guuid=257d6f9e-1700-0000-dc28-9afb420d0000 pid=3394->b520467e-a7f6-5a27-a09d-dcf4d704d509 send: 82B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-04-29 22:01:11 UTC
File Type:
Text (Shell)
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
antivm credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads process memory
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Contacts a large (23424) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 7ed2ce6d2ce3d7dc061977ee90fe41320e8bb910d9a6c52bbdcd13a60bc30186

(this sample)

  
Delivery method
Distributed via web download

Comments