🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8471b7bdce792836bd6465c9a05ef6303541ba64dcd040d6ccd1a6cc962c0238. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8471b7bdce792836bd6465c9a05ef6303541ba64dcd040d6ccd1a6cc962c0238
SHA3-384 hash: d4940327be4072633a126a4d6962d22cb5ca8952e64ea28ccea568a3b692c7e706834dc0a29763d10c645ab7ca51a072
SHA1 hash: 98817e9f0b9a69817d65985b91aa553eca8815d0
MD5 hash: 3f74b691991e0926b25fc27bed2d1ea2
humanhash: green-fourteen-december-winter
File name:dvr.sh
Download: download sample
Signature Mirai
File size:907 bytes
First seen:2025-10-14 00:16:59 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ToWBGhBh9Mk8QoWkp/A5VE+/I/V7R78atkk0:ToGGhL8QoWlVE+wV7Rgat/0
TLSH T11111D099E680E3A45C56502CB2C7C12BF06B43F806E51A64BC0E6D74F78C888F861B35
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://42.112.26.45/arm18b40a18fe04c05ee7bbdc7a07125633eb803dd7cd9f198e89a2b824df628c5c Miraielf mirai ua-wget
http://42.112.26.45/arm5be61d9c23d4359b4a4d4911f0f8fc09f69124f3cf991856d5c871e23568c5cd2 Miraielf mirai ua-wget
http://42.112.26.45/arm748f8ba323a18feb719e4cba9d502e85a73e89c0e7d4c6a5b2dae7e808b19f692 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-13T21:24:00Z UTC
Last seen:
2025-10-13T21:51:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=9f020d03-1900-0000-935c-b3bc04130000 pid=4868 /usr/bin/sudo guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875 /tmp/sample.bin guuid=9f020d03-1900-0000-935c-b3bc04130000 pid=4868->guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875 execve guuid=71e1910a-1900-0000-935c-b3bc27130000 pid=4903 /usr/bin/rm guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=71e1910a-1900-0000-935c-b3bc27130000 pid=4903 execve guuid=fe0fd20a-1900-0000-935c-b3bc29130000 pid=4905 /usr/bin/wget net send-data write-file guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=fe0fd20a-1900-0000-935c-b3bc29130000 pid=4905 execve guuid=3b214950-1900-0000-935c-b3bcd0130000 pid=5072 /usr/bin/chmod guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=3b214950-1900-0000-935c-b3bcd0130000 pid=5072 execve guuid=a230df50-1900-0000-935c-b3bcd4130000 pid=5076 /usr/bin/dash guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=a230df50-1900-0000-935c-b3bcd4130000 pid=5076 clone guuid=5334e552-1900-0000-935c-b3bcd8130000 pid=5080 /usr/bin/rm guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=5334e552-1900-0000-935c-b3bcd8130000 pid=5080 execve guuid=91254753-1900-0000-935c-b3bcdc130000 pid=5084 /usr/bin/wget net send-data write-file guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=91254753-1900-0000-935c-b3bcdc130000 pid=5084 execve guuid=8b9c53a5-1900-0000-935c-b3bc49140000 pid=5193 /usr/bin/chmod guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=8b9c53a5-1900-0000-935c-b3bc49140000 pid=5193 execve guuid=8f52cfa5-1900-0000-935c-b3bc4a140000 pid=5194 /usr/bin/dash guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=8f52cfa5-1900-0000-935c-b3bc4a140000 pid=5194 clone guuid=ad4bd8a7-1900-0000-935c-b3bc5a140000 pid=5210 /usr/bin/rm guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=ad4bd8a7-1900-0000-935c-b3bc5a140000 pid=5210 execve guuid=278c29a8-1900-0000-935c-b3bc5d140000 pid=5213 /usr/bin/wget net send-data write-file guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=278c29a8-1900-0000-935c-b3bc5d140000 pid=5213 execve guuid=68f2dee7-1900-0000-935c-b3bc6c140000 pid=5228 /usr/bin/chmod guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=68f2dee7-1900-0000-935c-b3bc6c140000 pid=5228 execve guuid=ab0d26e8-1900-0000-935c-b3bc6d140000 pid=5229 /usr/bin/dash guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=ab0d26e8-1900-0000-935c-b3bc6d140000 pid=5229 clone guuid=44f0b6e8-1900-0000-935c-b3bc6f140000 pid=5231 /usr/bin/busybox guuid=dcd6c004-1900-0000-935c-b3bc0b130000 pid=4875->guuid=44f0b6e8-1900-0000-935c-b3bc6f140000 pid=5231 execve 7e1f030a-193f-5ef8-b58f-206d09d04b13 42.112.26.45:80 guuid=fe0fd20a-1900-0000-935c-b3bc29130000 pid=4905->7e1f030a-193f-5ef8-b58f-206d09d04b13 send: 130B guuid=91254753-1900-0000-935c-b3bcdc130000 pid=5084->7e1f030a-193f-5ef8-b58f-206d09d04b13 send: 131B guuid=278c29a8-1900-0000-935c-b3bc5d140000 pid=5213->7e1f030a-193f-5ef8-b58f-206d09d04b13 send: 131B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-10-14 00:17:33 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads process memory
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8471b7bdce792836bd6465c9a05ef6303541ba64dcd040d6ccd1a6cc962c0238

(this sample)

  
Delivery method
Distributed via web download

Comments