MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81dd5cc988d10607beab49bef837fb526eb279d3d7d0d95e990bb8db3114bcd9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 81dd5cc988d10607beab49bef837fb526eb279d3d7d0d95e990bb8db3114bcd9
SHA3-384 hash: 6a3e1fb038cada9288d403d124656383dbddb97cf98f04222395f370e253387e237b13df616e2da435d7d0fb0f6ee0c4
SHA1 hash: bb3ed87bf7a3725c5eb52f87e1fe99e68dbb69b0
MD5 hash: 5c1405db80f06056e8206ef4ecc81af8
humanhash: monkey-mars-winner-pluto
File name:w.sh
Download: download sample
Signature Mirai
File size:930 bytes
First seen:2025-09-11 05:29:33 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:w3ZeL53ZeCY+E3ZerNIl5s3Ze40LKc3ZeK+OFw3Ze3jM43ZeZT93ZeeSO43ZeXto:HY6NI7fKW+I/j2T3lXt3ROn
TLSH T10511A2CD77B162AAC848CD28A17584989134A9C0314C0F9E5DCD0CF7E9D9F157E66E7C
Magika asm
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://161.97.106.129/systemcl/arma2812bf91c1836b0749615f8c92f49b055ed1152a0cfcb03cffb4473388ae1f9 Miraielf mirai
http://161.97.106.129/systemcl/arm5467ca3ecdb388a31f9687f3f93134ae992fbfbe2936cfbd700c3d198b3b65ecb Miraielf mirai
http://161.97.106.129/systemcl/arm67a4627901da5e02ceacaf688cc103b4944a3cf75b4f1f4316ee638893eaa4104 Miraielf mirai
http://161.97.106.129/systemcl/arm71745a1dc09e108e719186017f4d6f10e1835aa4ba3f74b50b8394e3268c66524 Miraielf mirai
http://161.97.106.129/systemcl/m68k19abfca0200531ee5ddc2dd7bc4454af84d9ffe0ef2e12cd2a54fc828ebdc659 Miraielf mirai
http://161.97.106.129/systemcl/mipsad42066092b60784e1579fb3742cf3a41450dacc13b254e9c3a0c5b84aaf0db4 Miraielf mirai
http://161.97.106.129/systemcl/mpsl7365564e3fc5bc60caa91eb8b6b87a6d8da423389be87134899fcd0caaeb3242 Miraielf mirai
http://161.97.106.129/systemcl/ppcabfd19ac36a02a8d3552a65a6e023b7499af427f7ea558cbc5064b8475bd955e Miraielf mirai
http://161.97.106.129/systemcl/sh4b5d5a320320766751e9a1e31bc6ff850196e0c3f0b5baee15eee600b8a3cdae2 Miraielf mirai
http://161.97.106.129/systemcl/spc2b4e44a8a37c63ce0a2c007bb22d903ae9d13b643b6b556f4d15199926cdd54c Miraielf mirai
http://161.97.106.129/systemcl/x862e9b4bb064c078485eab38389da45cfecd1f865d77cd5c199ae3c2fe195daf72 Miraielf mirai
http://161.97.106.129/systemcl/x86_6447a0fa2b9aa3ebdb48324d5ad43903187a528176193716db81991191b3d3b230 Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=e0b5add0-1a00-0000-3a19-d9c5590b0000 pid=2905 /usr/bin/sudo guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907 /tmp/sample.bin guuid=e0b5add0-1a00-0000-3a19-d9c5590b0000 pid=2905->guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907 execve guuid=f391acd2-1a00-0000-3a19-d9c55d0b0000 pid=2909 /usr/bin/busybox net send-data write-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=f391acd2-1a00-0000-3a19-d9c55d0b0000 pid=2909 execve guuid=2b77bfd7-1a00-0000-3a19-d9c5670b0000 pid=2919 /usr/bin/chmod guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=2b77bfd7-1a00-0000-3a19-d9c5670b0000 pid=2919 execve guuid=8ee0fbd7-1a00-0000-3a19-d9c5680b0000 pid=2920 /usr/bin/dash guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=8ee0fbd7-1a00-0000-3a19-d9c5680b0000 pid=2920 clone guuid=ddd587d9-1a00-0000-3a19-d9c56a0b0000 pid=2922 /usr/bin/busybox net send-data write-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=ddd587d9-1a00-0000-3a19-d9c56a0b0000 pid=2922 execve guuid=a814aedd-1a00-0000-3a19-d9c56b0b0000 pid=2923 /usr/bin/chmod guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=a814aedd-1a00-0000-3a19-d9c56b0b0000 pid=2923 execve guuid=950dfbdd-1a00-0000-3a19-d9c56c0b0000 pid=2924 /usr/bin/dash guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=950dfbdd-1a00-0000-3a19-d9c56c0b0000 pid=2924 clone guuid=37109cde-1a00-0000-3a19-d9c56e0b0000 pid=2926 /usr/bin/busybox net send-data write-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=37109cde-1a00-0000-3a19-d9c56e0b0000 pid=2926 execve guuid=737848e3-1a00-0000-3a19-d9c56f0b0000 pid=2927 /usr/bin/chmod guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=737848e3-1a00-0000-3a19-d9c56f0b0000 pid=2927 execve guuid=8387d8e3-1a00-0000-3a19-d9c5700b0000 pid=2928 /usr/bin/dash guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=8387d8e3-1a00-0000-3a19-d9c5700b0000 pid=2928 clone guuid=8996cbe4-1a00-0000-3a19-d9c5720b0000 pid=2930 /usr/bin/busybox net send-data write-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=8996cbe4-1a00-0000-3a19-d9c5720b0000 pid=2930 execve guuid=6e4a28e7-1a00-0000-3a19-d9c5770b0000 pid=2935 /usr/bin/chmod guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=6e4a28e7-1a00-0000-3a19-d9c5770b0000 pid=2935 execve guuid=cabc91e7-1a00-0000-3a19-d9c5790b0000 pid=2937 /usr/bin/dash guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=cabc91e7-1a00-0000-3a19-d9c5790b0000 pid=2937 clone guuid=a3f06fe8-1a00-0000-3a19-d9c57d0b0000 pid=2941 /usr/bin/busybox net send-data write-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=a3f06fe8-1a00-0000-3a19-d9c57d0b0000 pid=2941 execve guuid=38a2fbee-1a00-0000-3a19-d9c5850b0000 pid=2949 /usr/bin/chmod guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=38a2fbee-1a00-0000-3a19-d9c5850b0000 pid=2949 execve guuid=e5d319f2-1a00-0000-3a19-d9c5890b0000 pid=2953 /usr/bin/dash guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=e5d319f2-1a00-0000-3a19-d9c5890b0000 pid=2953 clone guuid=b839f3f2-1a00-0000-3a19-d9c58d0b0000 pid=2957 /usr/bin/busybox net send-data write-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=b839f3f2-1a00-0000-3a19-d9c58d0b0000 pid=2957 execve guuid=906afff4-1a00-0000-3a19-d9c5910b0000 pid=2961 /usr/bin/chmod guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=906afff4-1a00-0000-3a19-d9c5910b0000 pid=2961 execve guuid=8bad52f5-1a00-0000-3a19-d9c5920b0000 pid=2962 /usr/bin/dash guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=8bad52f5-1a00-0000-3a19-d9c5920b0000 pid=2962 clone guuid=1bafedf6-1a00-0000-3a19-d9c5950b0000 pid=2965 /usr/bin/busybox net send-data write-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=1bafedf6-1a00-0000-3a19-d9c5950b0000 pid=2965 execve guuid=e43edefc-1a00-0000-3a19-d9c5a30b0000 pid=2979 /usr/bin/chmod guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=e43edefc-1a00-0000-3a19-d9c5a30b0000 pid=2979 execve guuid=6efd42fd-1a00-0000-3a19-d9c5a50b0000 pid=2981 /usr/bin/dash guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=6efd42fd-1a00-0000-3a19-d9c5a50b0000 pid=2981 clone guuid=e46afffd-1a00-0000-3a19-d9c5a90b0000 pid=2985 /usr/bin/busybox net send-data write-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=e46afffd-1a00-0000-3a19-d9c5a90b0000 pid=2985 execve guuid=2adcd2ff-1a00-0000-3a19-d9c5ab0b0000 pid=2987 /usr/bin/chmod guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=2adcd2ff-1a00-0000-3a19-d9c5ab0b0000 pid=2987 execve guuid=3e5d3300-1b00-0000-3a19-d9c5ac0b0000 pid=2988 /usr/bin/dash guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=3e5d3300-1b00-0000-3a19-d9c5ac0b0000 pid=2988 clone guuid=44a7a901-1b00-0000-3a19-d9c5b10b0000 pid=2993 /usr/bin/busybox net send-data write-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=44a7a901-1b00-0000-3a19-d9c5b10b0000 pid=2993 execve guuid=836df303-1b00-0000-3a19-d9c5b70b0000 pid=2999 /usr/bin/chmod guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=836df303-1b00-0000-3a19-d9c5b70b0000 pid=2999 execve guuid=da9a5904-1b00-0000-3a19-d9c5b80b0000 pid=3000 /usr/bin/dash guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=da9a5904-1b00-0000-3a19-d9c5b80b0000 pid=3000 clone guuid=d0e54d05-1b00-0000-3a19-d9c5bb0b0000 pid=3003 /usr/bin/busybox net send-data write-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=d0e54d05-1b00-0000-3a19-d9c5bb0b0000 pid=3003 execve guuid=50bd1608-1b00-0000-3a19-d9c5bf0b0000 pid=3007 /usr/bin/chmod guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=50bd1608-1b00-0000-3a19-d9c5bf0b0000 pid=3007 execve guuid=11d3a808-1b00-0000-3a19-d9c5c10b0000 pid=3009 /usr/bin/dash guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=11d3a808-1b00-0000-3a19-d9c5c10b0000 pid=3009 clone guuid=ef6f5209-1b00-0000-3a19-d9c5c50b0000 pid=3013 /usr/bin/busybox net send-data write-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=ef6f5209-1b00-0000-3a19-d9c5c50b0000 pid=3013 execve guuid=20d1e40d-1b00-0000-3a19-d9c5d10b0000 pid=3025 /usr/bin/chmod guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=20d1e40d-1b00-0000-3a19-d9c5d10b0000 pid=3025 execve guuid=75be450e-1b00-0000-3a19-d9c5d30b0000 pid=3027 /home/sandbox/x86 net guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=75be450e-1b00-0000-3a19-d9c5d30b0000 pid=3027 execve guuid=8e6aab1f-1b00-0000-3a19-d9c5fd0b0000 pid=3069 /usr/bin/busybox net send-data write-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=8e6aab1f-1b00-0000-3a19-d9c5fd0b0000 pid=3069 execve guuid=b3374026-1b00-0000-3a19-d9c5110c0000 pid=3089 /usr/bin/chmod guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=b3374026-1b00-0000-3a19-d9c5110c0000 pid=3089 execve guuid=20d6a326-1b00-0000-3a19-d9c5130c0000 pid=3091 /usr/bin/dash guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=20d6a326-1b00-0000-3a19-d9c5130c0000 pid=3091 clone guuid=8ed9df27-1b00-0000-3a19-d9c5180c0000 pid=3096 /usr/bin/rm delete-file guuid=d8cd72d2-1a00-0000-3a19-d9c55b0b0000 pid=2907->guuid=8ed9df27-1b00-0000-3a19-d9c5180c0000 pid=3096 execve 2b1801dc-b67a-5da1-8e84-0d7a99e1894a 161.97.106.129:80 guuid=f391acd2-1a00-0000-3a19-d9c55d0b0000 pid=2909->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 89B guuid=ddd587d9-1a00-0000-3a19-d9c56a0b0000 pid=2922->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 90B guuid=37109cde-1a00-0000-3a19-d9c56e0b0000 pid=2926->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 90B guuid=8996cbe4-1a00-0000-3a19-d9c5720b0000 pid=2930->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 90B guuid=a3f06fe8-1a00-0000-3a19-d9c57d0b0000 pid=2941->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 90B guuid=b839f3f2-1a00-0000-3a19-d9c58d0b0000 pid=2957->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 90B guuid=1bafedf6-1a00-0000-3a19-d9c5950b0000 pid=2965->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 90B guuid=e46afffd-1a00-0000-3a19-d9c5a90b0000 pid=2985->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 89B guuid=44a7a901-1b00-0000-3a19-d9c5b10b0000 pid=2993->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 89B guuid=d0e54d05-1b00-0000-3a19-d9c5bb0b0000 pid=3003->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 89B guuid=ef6f5209-1b00-0000-3a19-d9c5c50b0000 pid=3013->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 89B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=75be450e-1b00-0000-3a19-d9c5d30b0000 pid=3027->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=493da11f-1b00-0000-3a19-d9c5fb0b0000 pid=3067 /home/sandbox/x86 guuid=75be450e-1b00-0000-3a19-d9c5d30b0000 pid=3027->guuid=493da11f-1b00-0000-3a19-d9c5fb0b0000 pid=3067 clone guuid=d240a61f-1b00-0000-3a19-d9c5fc0b0000 pid=3068 /home/sandbox/x86 net send-data zombie guuid=75be450e-1b00-0000-3a19-d9c5d30b0000 pid=3027->guuid=d240a61f-1b00-0000-3a19-d9c5fc0b0000 pid=3068 clone guuid=d240a61f-1b00-0000-3a19-d9c5fc0b0000 pid=3068->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con dfbb6132-9b3a-5fcc-ae73-0a5bea22ee6b 87.121.84.220:61459 guuid=d240a61f-1b00-0000-3a19-d9c5fc0b0000 pid=3068->dfbb6132-9b3a-5fcc-ae73-0a5bea22ee6b send: 43B guuid=8e6aab1f-1b00-0000-3a19-d9c5fd0b0000 pid=3069->2b1801dc-b67a-5da1-8e84-0d7a99e1894a send: 92B
Threat name:
Linux.Trojan.Alevaul
Status:
Malicious
First seen:
2025-09-10 18:06:28 UTC
File Type:
Text (Shell)
AV detection:
18 of 38 (47.37%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 81dd5cc988d10607beab49bef837fb526eb279d3d7d0d95e990bb8db3114bcd9

(this sample)

  
Delivery method
Distributed via web download

Comments