MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 87de4ac28121ca9e926a270d2a4e5ab08708d1ef6e3e99071f0fed3bf4e376d9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 87de4ac28121ca9e926a270d2a4e5ab08708d1ef6e3e99071f0fed3bf4e376d9
SHA3-384 hash: 22ab3d31ff67d775f333b03441ab8c9ec57fa1561b57458bce8e024793fd3578530b5fce1f9d8a260c1e6984d878a2be
SHA1 hash: 1260e65a961101dbb4733c07b9eb08b3a65499f6
MD5 hash: d4980ee2f119483b18c0447d4dd8bac4
humanhash: charlie-helium-magazine-low
File name:g
Download: download sample
Signature Mirai
File size:1'067 bytes
First seen:2025-09-24 16:55:27 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:E22IbO5zOt+MB0CJZkdNaNmkdq2kHLZmQkHPlkA:EAO5CEA0GkBkZkrZvk9kA
TLSH T1B911C0CE00B4A82258D89D9A75638C2478CBC6F419C7CE98648A8537BCCDA14F372F69
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://194.31.222.17/v/armv4le333d6098ba7af114b4e8b290f0e587592067b8e153798bf4763262d2074ad96 Miraiarm elf geofenced mirai ua-wget USA
http://194.31.222.17/v/armv5l79d810e67c7bd6c6669214c1c4b631829d90726886b4167a232813d8434ef3f7 Miraiarm elf geofenced mirai ua-wget USA
http://194.31.222.17/v/armv7lc3788d92bfc3a08dbcca4476832c46b099bcad182c56cdbccf837eb0edb6cd77 Miraiarm elf geofenced mirai ua-wget USA
http://194.31.222.17/v/mipsd4e2e83716082a12346f565d13cc06546a099a05725f194c135f7b3839473a6c Mirai32-bit DEU elf geofenced mirai Mozi opendir
http://194.31.222.17/v/mipsel8db391280f5fda83a9dc476d69d093827bb72b3a90c3112679855eacabb996e1 Mirai32-bit DEU elf geofenced mirai Mozi opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
ps1
First seen:
2025-09-24T15:07:00Z UTC
Last seen:
2025-09-24T15:07:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=6d260c9e-1900-0000-e45f-55aed9090000 pid=2521 /usr/bin/sudo guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525 /tmp/sample.bin guuid=6d260c9e-1900-0000-e45f-55aed9090000 pid=2521->guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525 execve guuid=6daec9a0-1900-0000-e45f-55aedf090000 pid=2527 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=6daec9a0-1900-0000-e45f-55aedf090000 pid=2527 clone guuid=ab072fa2-1900-0000-e45f-55aee6090000 pid=2534 /usr/bin/rm delete-file guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=ab072fa2-1900-0000-e45f-55aee6090000 pid=2534 execve guuid=573a8ba2-1900-0000-e45f-55aee8090000 pid=2536 /usr/bin/rm delete-file guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=573a8ba2-1900-0000-e45f-55aee8090000 pid=2536 execve guuid=8953e9a2-1900-0000-e45f-55aeea090000 pid=2538 /usr/bin/rm delete-file guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=8953e9a2-1900-0000-e45f-55aeea090000 pid=2538 execve guuid=170550a3-1900-0000-e45f-55aeed090000 pid=2541 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=170550a3-1900-0000-e45f-55aeed090000 pid=2541 clone guuid=90a71ba4-1900-0000-e45f-55aef1090000 pid=2545 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=90a71ba4-1900-0000-e45f-55aef1090000 pid=2545 clone guuid=c8776ca4-1900-0000-e45f-55aef4090000 pid=2548 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=c8776ca4-1900-0000-e45f-55aef4090000 pid=2548 clone guuid=db72d5ae-1900-0000-e45f-55ae080a0000 pid=2568 /usr/bin/chmod guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=db72d5ae-1900-0000-e45f-55ae080a0000 pid=2568 execve guuid=1ee92caf-1900-0000-e45f-55ae090a0000 pid=2569 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=1ee92caf-1900-0000-e45f-55ae090a0000 pid=2569 clone guuid=4a0442b0-1900-0000-e45f-55ae0e0a0000 pid=2574 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=4a0442b0-1900-0000-e45f-55ae0e0a0000 pid=2574 clone guuid=7cbe89ba-1900-0000-e45f-55ae290a0000 pid=2601 /usr/bin/chmod guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=7cbe89ba-1900-0000-e45f-55ae290a0000 pid=2601 execve guuid=9892d0ba-1900-0000-e45f-55ae2b0a0000 pid=2603 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=9892d0ba-1900-0000-e45f-55ae2b0a0000 pid=2603 clone guuid=ba3873bb-1900-0000-e45f-55ae2f0a0000 pid=2607 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=ba3873bb-1900-0000-e45f-55ae2f0a0000 pid=2607 clone guuid=c53513c7-1900-0000-e45f-55ae4f0a0000 pid=2639 /usr/bin/chmod guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=c53513c7-1900-0000-e45f-55ae4f0a0000 pid=2639 execve guuid=63fb4cc7-1900-0000-e45f-55ae510a0000 pid=2641 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=63fb4cc7-1900-0000-e45f-55ae510a0000 pid=2641 clone guuid=028ed4c7-1900-0000-e45f-55ae540a0000 pid=2644 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=028ed4c7-1900-0000-e45f-55ae540a0000 pid=2644 clone guuid=a3a05ed2-1900-0000-e45f-55ae740a0000 pid=2676 /usr/bin/chmod guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=a3a05ed2-1900-0000-e45f-55ae740a0000 pid=2676 execve guuid=7212b5d2-1900-0000-e45f-55ae760a0000 pid=2678 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=7212b5d2-1900-0000-e45f-55ae760a0000 pid=2678 clone guuid=74b44cd3-1900-0000-e45f-55ae7a0a0000 pid=2682 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=74b44cd3-1900-0000-e45f-55ae7a0a0000 pid=2682 clone guuid=08459fde-1900-0000-e45f-55ae9d0a0000 pid=2717 /usr/bin/chmod guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=08459fde-1900-0000-e45f-55ae9d0a0000 pid=2717 execve guuid=d0eedcde-1900-0000-e45f-55ae9f0a0000 pid=2719 /usr/bin/dash guuid=ad9684a0-1900-0000-e45f-55aedd090000 pid=2525->guuid=d0eedcde-1900-0000-e45f-55ae9f0a0000 pid=2719 clone guuid=ec4bf3a0-1900-0000-e45f-55aee0090000 pid=2528 /usr/bin/cat guuid=6daec9a0-1900-0000-e45f-55aedf090000 pid=2527->guuid=ec4bf3a0-1900-0000-e45f-55aee0090000 pid=2528 execve guuid=ce1516a1-1900-0000-e45f-55aee1090000 pid=2529 /usr/bin/grep guuid=6daec9a0-1900-0000-e45f-55aedf090000 pid=2527->guuid=ce1516a1-1900-0000-e45f-55aee1090000 pid=2529 execve guuid=ef8c25a1-1900-0000-e45f-55aee2090000 pid=2530 /usr/bin/grep guuid=6daec9a0-1900-0000-e45f-55aedf090000 pid=2527->guuid=ef8c25a1-1900-0000-e45f-55aee2090000 pid=2530 execve guuid=10a76ca1-1900-0000-e45f-55aee3090000 pid=2531 /usr/bin/grep guuid=6daec9a0-1900-0000-e45f-55aedf090000 pid=2527->guuid=10a76ca1-1900-0000-e45f-55aee3090000 pid=2531 execve guuid=3f298da1-1900-0000-e45f-55aee4090000 pid=2532 /usr/bin/cut guuid=6daec9a0-1900-0000-e45f-55aedf090000 pid=2527->guuid=3f298da1-1900-0000-e45f-55aee4090000 pid=2532 execve guuid=b6ee5ca3-1900-0000-e45f-55aeee090000 pid=2542 /usr/bin/cp write-file guuid=170550a3-1900-0000-e45f-55aeed090000 pid=2541->guuid=b6ee5ca3-1900-0000-e45f-55aeee090000 pid=2542 execve guuid=189d27a4-1900-0000-e45f-55aef2090000 pid=2546 /usr/bin/chmod guuid=90a71ba4-1900-0000-e45f-55aef1090000 pid=2545->guuid=189d27a4-1900-0000-e45f-55aef2090000 pid=2546 execve guuid=fa5976a4-1900-0000-e45f-55aef5090000 pid=2549 /usr/bin/wget net send-data write-file guuid=c8776ca4-1900-0000-e45f-55aef4090000 pid=2548->guuid=fa5976a4-1900-0000-e45f-55aef5090000 pid=2549 execve 287749b9-1937-53b1-8818-44b73ae22708 194.31.222.17:80 guuid=fa5976a4-1900-0000-e45f-55aef5090000 pid=2549->287749b9-1937-53b1-8818-44b73ae22708 send: 136B guuid=f4be47b0-1900-0000-e45f-55ae100a0000 pid=2576 /usr/bin/wget net send-data write-file guuid=4a0442b0-1900-0000-e45f-55ae0e0a0000 pid=2574->guuid=f4be47b0-1900-0000-e45f-55ae100a0000 pid=2576 execve guuid=f4be47b0-1900-0000-e45f-55ae100a0000 pid=2576->287749b9-1937-53b1-8818-44b73ae22708 send: 136B guuid=f1617abb-1900-0000-e45f-55ae300a0000 pid=2608 /usr/bin/wget net send-data write-file guuid=ba3873bb-1900-0000-e45f-55ae2f0a0000 pid=2607->guuid=f1617abb-1900-0000-e45f-55ae300a0000 pid=2608 execve guuid=f1617abb-1900-0000-e45f-55ae300a0000 pid=2608->287749b9-1937-53b1-8818-44b73ae22708 send: 136B guuid=3950dcc7-1900-0000-e45f-55ae560a0000 pid=2646 /usr/bin/wget net send-data write-file guuid=028ed4c7-1900-0000-e45f-55ae540a0000 pid=2644->guuid=3950dcc7-1900-0000-e45f-55ae560a0000 pid=2646 execve guuid=3950dcc7-1900-0000-e45f-55ae560a0000 pid=2646->287749b9-1937-53b1-8818-44b73ae22708 send: 134B guuid=f8cf54d3-1900-0000-e45f-55ae7b0a0000 pid=2683 /usr/bin/wget net send-data write-file guuid=74b44cd3-1900-0000-e45f-55ae7a0a0000 pid=2682->guuid=f8cf54d3-1900-0000-e45f-55ae7b0a0000 pid=2683 execve guuid=f8cf54d3-1900-0000-e45f-55ae7b0a0000 pid=2683->287749b9-1937-53b1-8818-44b73ae22708 send: 136B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2025-09-23 07:15:48 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 87de4ac28121ca9e926a270d2a4e5ab08708d1ef6e3e99071f0fed3bf4e376d9

(this sample)

  
Delivery method
Distributed via web download

Comments