MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8200b00a02c29b54d8018ba33bd1fc697c4cc915e67775bf8b8dc08510dd9de6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8200b00a02c29b54d8018ba33bd1fc697c4cc915e67775bf8b8dc08510dd9de6
SHA3-384 hash: a33127f8f8d69b38f898ab74a8f8752ca23015250b736bbdfe6269fb71ab397fbfcd68a3c4463d6bf8729e08ad6e2cca
SHA1 hash: 817aea41628bd01bf8b8d9a4fff7bfcd4dd0cc2b
MD5 hash: 358f03ffd6e734584f92f916ba1fd647
humanhash: earth-missouri-quiet-william
File name:l
Download: download sample
Signature Mirai
File size:1'253 bytes
First seen:2025-11-21 20:30:49 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:boWBGhBh9Mk8QoOwIStCdnHmUXmqmFmiiPmjmSKLH2Kpatkk0:boGGhL8QoYSodnHTJUPiPq5aH2Iat/0
TLSH T178218BEE76D163359AD88F02F292A931B71F5BCDA4541ED8F58F38B1AA5CC007025B23
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.146.23.141/mips08fe033056f2f363637df7eaa1395592cb81e9fe81cd47c0ebd4179dae842f31 Miraielf geofenced mips mirai ua-wget USA
http://103.146.23.141/mpsl1e8f3cf5b4d3f882baf522d62bf9fc105fc34ad3562f0d2dca48dad26f5e2b26 Miraielf geofenced mips mirai ua-wget USA
http://103.146.23.141/arme6c563c09c5b0d3ece466e66741c73e24763c901a9511f2664128ba80ee653af Miraiarm elf geofenced mirai ua-wget USA
http://103.146.23.141/arm507ad16f0878b5af7f123753058da3660d83cac7a6244038fa82a5279ecbcdec7 Miraiarm elf geofenced mirai ua-wget USA
http://103.146.23.141/arm70feffdb13c3bce429c074cf1b5d10a33001b34a4e21d014d5f5151a9d01283f6 Miraiarm elf geofenced mirai ua-wget USA
http://103.146.23.141/x8686b6d6e282d0c889d7e97e6414672b37cbcb016d8f133212958a9b3af90c53e5 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-21T18:06:00Z UTC
Last seen:
2025-11-22T10:20:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=7f43f366-1900-0000-737e-a464d80f0000 pid=4056 /usr/bin/sudo guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059 /tmp/sample.bin guuid=7f43f366-1900-0000-737e-a464d80f0000 pid=4056->guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059 execve guuid=c389ed6d-1900-0000-737e-a464f20f0000 pid=4082 /usr/bin/rm guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=c389ed6d-1900-0000-737e-a464f20f0000 pid=4082 execve guuid=05092a6e-1900-0000-737e-a464f40f0000 pid=4084 /usr/bin/wget net send-data write-file guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=05092a6e-1900-0000-737e-a464f40f0000 pid=4084 execve guuid=7a89feb1-1900-0000-737e-a464f7100000 pid=4343 /usr/bin/chmod guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=7a89feb1-1900-0000-737e-a464f7100000 pid=4343 execve guuid=e89e41b2-1900-0000-737e-a464f8100000 pid=4344 /usr/bin/dash guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=e89e41b2-1900-0000-737e-a464f8100000 pid=4344 clone guuid=0b53ccb2-1900-0000-737e-a464fc100000 pid=4348 /usr/bin/wget net send-data write-file guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=0b53ccb2-1900-0000-737e-a464fc100000 pid=4348 execve guuid=91915d1b-1a00-0000-737e-a46488120000 pid=4744 /usr/bin/chmod guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=91915d1b-1a00-0000-737e-a46488120000 pid=4744 execve guuid=e13fc11b-1a00-0000-737e-a4648a120000 pid=4746 /usr/bin/dash guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=e13fc11b-1a00-0000-737e-a4648a120000 pid=4746 clone guuid=7fbd731c-1a00-0000-737e-a4648e120000 pid=4750 /usr/bin/wget net send-data write-file guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=7fbd731c-1a00-0000-737e-a4648e120000 pid=4750 execve guuid=b62d9e60-1a00-0000-737e-a46428130000 pid=4904 /usr/bin/chmod guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=b62d9e60-1a00-0000-737e-a46428130000 pid=4904 execve guuid=9da20461-1a00-0000-737e-a4642a130000 pid=4906 /usr/bin/dash guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=9da20461-1a00-0000-737e-a4642a130000 pid=4906 clone guuid=6b83de61-1a00-0000-737e-a4642e130000 pid=4910 /usr/bin/wget net send-data write-file guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=6b83de61-1a00-0000-737e-a4642e130000 pid=4910 execve guuid=c47cf7b0-1a00-0000-737e-a464fa130000 pid=5114 /usr/bin/chmod guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=c47cf7b0-1a00-0000-737e-a464fa130000 pid=5114 execve guuid=04316ab1-1a00-0000-737e-a464fc130000 pid=5116 /usr/bin/dash guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=04316ab1-1a00-0000-737e-a464fc130000 pid=5116 clone guuid=11064fb2-1a00-0000-737e-a464ff130000 pid=5119 /usr/bin/wget net send-data write-file guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=11064fb2-1a00-0000-737e-a464ff130000 pid=5119 execve guuid=f7ee11f6-1a00-0000-737e-a4646d140000 pid=5229 /usr/bin/chmod guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=f7ee11f6-1a00-0000-737e-a4646d140000 pid=5229 execve guuid=b719a8f6-1a00-0000-737e-a4646e140000 pid=5230 /usr/bin/dash guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=b719a8f6-1a00-0000-737e-a4646e140000 pid=5230 clone guuid=86e65cf9-1a00-0000-737e-a46470140000 pid=5232 /usr/bin/wget net send-data guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=86e65cf9-1a00-0000-737e-a46470140000 pid=5232 execve guuid=5b880e14-1b00-0000-737e-a4647c140000 pid=5244 /usr/bin/busybox net send-data guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=5b880e14-1b00-0000-737e-a4647c140000 pid=5244 execve guuid=44be4231-1b00-0000-737e-a4647d140000 pid=5245 /usr/bin/chmod guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=44be4231-1b00-0000-737e-a4647d140000 pid=5245 execve guuid=3f25c031-1b00-0000-737e-a4647e140000 pid=5246 /usr/bin/dash guuid=34ffaf68-1900-0000-737e-a464db0f0000 pid=4059->guuid=3f25c031-1b00-0000-737e-a4647e140000 pid=5246 clone c56865db-3b4b-54b6-a6ba-cee0ad256cff 103.146.23.141:80 guuid=05092a6e-1900-0000-737e-a464f40f0000 pid=4084->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 133B guuid=0b53ccb2-1900-0000-737e-a464fc100000 pid=4348->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 133B guuid=7fbd731c-1a00-0000-737e-a4648e120000 pid=4750->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 132B guuid=6b83de61-1a00-0000-737e-a4642e130000 pid=4910->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 133B guuid=11064fb2-1a00-0000-737e-a464ff130000 pid=5119->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 133B guuid=86e65cf9-1a00-0000-737e-a46470140000 pid=5232->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 132B guuid=5b880e14-1b00-0000-737e-a4647c140000 pid=5244->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 80B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-11-21 21:22:35 UTC
File Type:
Text (Shell)
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8200b00a02c29b54d8018ba33bd1fc697c4cc915e67775bf8b8dc08510dd9de6

(this sample)

  
Delivery method
Distributed via web download

Comments