MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 88bd4fd3404943114c13ac91fcb7c41b077736aa1e9984aa0c24fd4bc97d4957. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 88bd4fd3404943114c13ac91fcb7c41b077736aa1e9984aa0c24fd4bc97d4957
SHA3-384 hash: 62373124fcba79cd1acf3f29c730935a20192857907f1777546f627b219d9ac1eadc5f0202a90d6a3e7418dc667a34ed
SHA1 hash: 29639c6d67c5ba7b1dac9220101bdfa6698cff02
MD5 hash: a85ac51d6423b1d7f69ea5173ebd38ad
humanhash: west-winner-finch-don
File name:wget.sh
Download: download sample
Signature Mirai
File size:1'112 bytes
First seen:2025-08-11 05:33:46 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:XENs+d0NniaUZLR3DjTJRMw8rGkUM0XioJxzxdH:x+d0NiaUZLR3DjTJR77kp0XioJxzxdH
TLSH T1AB2150CD4365198884144D95769786509FCFC6C6BC758FA6E4CA0DF394C9A00FA38FDB
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.42.88.217/HBTs/top1miku.arcn/an/aelf ua-wget
http://89.42.88.217/HBTs/.ksysda999f47eecd7e38895349eb39c6d2350815b5de5dc06629cd3008ab712b95a49 Miraielf mirai ua-wget
http://89.42.88.217/HBTs/.dbusd4fca520cba6b303a00db04c5525f9ebcd91027396a8daea21428623d9c000cd9 Miraielf mirai ua-wget
http://89.42.88.217/HBTs/top1miku.i686n/an/aelf ua-wget
http://89.42.88.217/HBTs/.udevmonebf5b2fe63545dd6486a8424d3660e89fec0f5b4d9f5697cf639c71a30e5084f Miraielf mirai ua-wget
http://89.42.88.217/HBTs/.upstart5f346db94dd74ca9f5b9bbef9a3acede4ff545868d9302ce9e9f6afadd174c3e Miraielf mirai ua-wget
http://89.42.88.217/HBTs/.netd3fe3f07475a7f97dbd70d217568915acf9107cf6ac1225758d3068dcca3b894d Miraielf mirai ua-wget
http://89.42.88.217/HBTs/.syncd2e03f8c53cfdc53d28de4014c6d1bf599f6db13e805ddf40ec63fc2728d99615 Miraielf mirai ua-wget
http://89.42.88.217/HBTs/.irqbal2cc247d74f81b12e13cfee4617575ac1e0ab5dca352947af77072916b3f91532 Miraielf mirai ua-wget
http://89.42.88.217/HBTs/.rsysl739aef07d54c89858d617dcfaa25a44ea5d28f75efab5c14f884d3b89c24181b Miraielf mirai ua-wget
http://89.42.88.217/HBTs/.modprobea4c5d10e0484cc0b3005ba65e1499780acb68a18b476f846bc8fce1d318f07bf Miraielf mirai ua-wget
http://89.42.88.217/HBTs/.systemd-jdn/an/aelf ua-wget
http://89.42.88.217/HBTs/.kthreadd188e8c19cfc165712b2e5d83a4a79eb6c0f68fe0a03d0811cd2972da755be0ed Miraielf mirai ua-wget
http://89.42.88.217/HBTs/.klogda2d1334928d5ae1368924865254295e14290e36a88dc01c309ae66c04b1ab468 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=dea76fa1-1900-0000-7c5b-1fe5670f0000 pid=3943 /usr/bin/sudo guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953 /tmp/sample.bin guuid=dea76fa1-1900-0000-7c5b-1fe5670f0000 pid=3943->guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953 execve guuid=cd063da3-1900-0000-7c5b-1fe5720f0000 pid=3954 /usr/bin/wget net send-data guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=cd063da3-1900-0000-7c5b-1fe5720f0000 pid=3954 execve guuid=8de18361-1a00-0000-7c5b-1fe53b110000 pid=4411 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=8de18361-1a00-0000-7c5b-1fe53b110000 pid=4411 execve guuid=5bb3f261-1a00-0000-7c5b-1fe53d110000 pid=4413 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=5bb3f261-1a00-0000-7c5b-1fe53d110000 pid=4413 clone guuid=b255fe61-1a00-0000-7c5b-1fe53e110000 pid=4414 /usr/bin/wget net send-data write-file guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=b255fe61-1a00-0000-7c5b-1fe53e110000 pid=4414 execve guuid=e087b9ab-1a00-0000-7c5b-1fe5e5110000 pid=4581 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=e087b9ab-1a00-0000-7c5b-1fe5e5110000 pid=4581 execve guuid=a6c136ac-1a00-0000-7c5b-1fe5e8110000 pid=4584 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=a6c136ac-1a00-0000-7c5b-1fe5e8110000 pid=4584 clone guuid=bcb0c4ae-1a00-0000-7c5b-1fe5ef110000 pid=4591 /usr/bin/wget net send-data write-file guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=bcb0c4ae-1a00-0000-7c5b-1fe5ef110000 pid=4591 execve guuid=3a8ab3f7-1a00-0000-7c5b-1fe58e120000 pid=4750 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=3a8ab3f7-1a00-0000-7c5b-1fe58e120000 pid=4750 execve guuid=e8434df8-1a00-0000-7c5b-1fe590120000 pid=4752 /home/sandbox/.dbusd net guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=e8434df8-1a00-0000-7c5b-1fe590120000 pid=4752 execve guuid=f51e8bf8-1a00-0000-7c5b-1fe594120000 pid=4756 /usr/bin/wget guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=f51e8bf8-1a00-0000-7c5b-1fe594120000 pid=4756 execve guuid=ec53a7f9-1a00-0000-7c5b-1fe59b120000 pid=4763 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=ec53a7f9-1a00-0000-7c5b-1fe59b120000 pid=4763 execve guuid=947b21fa-1a00-0000-7c5b-1fe59d120000 pid=4765 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=947b21fa-1a00-0000-7c5b-1fe59d120000 pid=4765 clone guuid=423430fa-1a00-0000-7c5b-1fe59e120000 pid=4766 /usr/bin/wget guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=423430fa-1a00-0000-7c5b-1fe59e120000 pid=4766 execve guuid=36c073fa-1a00-0000-7c5b-1fe5a1120000 pid=4769 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=36c073fa-1a00-0000-7c5b-1fe5a1120000 pid=4769 execve guuid=a062d7fa-1a00-0000-7c5b-1fe5a3120000 pid=4771 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=a062d7fa-1a00-0000-7c5b-1fe5a3120000 pid=4771 clone guuid=2d8a08fb-1a00-0000-7c5b-1fe5a5120000 pid=4773 /usr/bin/wget guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=2d8a08fb-1a00-0000-7c5b-1fe5a5120000 pid=4773 execve guuid=630781fb-1a00-0000-7c5b-1fe5a9120000 pid=4777 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=630781fb-1a00-0000-7c5b-1fe5a9120000 pid=4777 execve guuid=012c28fc-1a00-0000-7c5b-1fe5ad120000 pid=4781 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=012c28fc-1a00-0000-7c5b-1fe5ad120000 pid=4781 clone guuid=e204adfc-1a00-0000-7c5b-1fe5b1120000 pid=4785 /usr/bin/wget guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=e204adfc-1a00-0000-7c5b-1fe5b1120000 pid=4785 execve guuid=d632e2fc-1a00-0000-7c5b-1fe5b2120000 pid=4786 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=d632e2fc-1a00-0000-7c5b-1fe5b2120000 pid=4786 execve guuid=ef603bfd-1a00-0000-7c5b-1fe5b5120000 pid=4789 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=ef603bfd-1a00-0000-7c5b-1fe5b5120000 pid=4789 clone guuid=200a53fd-1a00-0000-7c5b-1fe5b6120000 pid=4790 /usr/bin/wget guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=200a53fd-1a00-0000-7c5b-1fe5b6120000 pid=4790 execve guuid=f40871fd-1a00-0000-7c5b-1fe5b8120000 pid=4792 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=f40871fd-1a00-0000-7c5b-1fe5b8120000 pid=4792 execve guuid=27febffd-1a00-0000-7c5b-1fe5ba120000 pid=4794 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=27febffd-1a00-0000-7c5b-1fe5ba120000 pid=4794 clone guuid=4d37dbfd-1a00-0000-7c5b-1fe5bc120000 pid=4796 /usr/bin/wget guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=4d37dbfd-1a00-0000-7c5b-1fe5bc120000 pid=4796 execve guuid=64b8f4fd-1a00-0000-7c5b-1fe5bd120000 pid=4797 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=64b8f4fd-1a00-0000-7c5b-1fe5bd120000 pid=4797 execve guuid=516436fe-1a00-0000-7c5b-1fe5c0120000 pid=4800 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=516436fe-1a00-0000-7c5b-1fe5c0120000 pid=4800 clone guuid=5d243bfe-1a00-0000-7c5b-1fe5c1120000 pid=4801 /usr/bin/wget guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=5d243bfe-1a00-0000-7c5b-1fe5c1120000 pid=4801 execve guuid=d70771fe-1a00-0000-7c5b-1fe5c3120000 pid=4803 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=d70771fe-1a00-0000-7c5b-1fe5c3120000 pid=4803 execve guuid=3571a9fe-1a00-0000-7c5b-1fe5c5120000 pid=4805 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=3571a9fe-1a00-0000-7c5b-1fe5c5120000 pid=4805 clone guuid=22afb2fe-1a00-0000-7c5b-1fe5c6120000 pid=4806 /usr/bin/wget guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=22afb2fe-1a00-0000-7c5b-1fe5c6120000 pid=4806 execve guuid=2550c4fe-1a00-0000-7c5b-1fe5c7120000 pid=4807 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=2550c4fe-1a00-0000-7c5b-1fe5c7120000 pid=4807 execve guuid=d96d1eff-1a00-0000-7c5b-1fe5ca120000 pid=4810 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=d96d1eff-1a00-0000-7c5b-1fe5ca120000 pid=4810 clone guuid=3be628ff-1a00-0000-7c5b-1fe5cb120000 pid=4811 /usr/bin/wget guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=3be628ff-1a00-0000-7c5b-1fe5cb120000 pid=4811 execve guuid=cd814aff-1a00-0000-7c5b-1fe5cc120000 pid=4812 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=cd814aff-1a00-0000-7c5b-1fe5cc120000 pid=4812 execve guuid=b4ef80ff-1a00-0000-7c5b-1fe5cf120000 pid=4815 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=b4ef80ff-1a00-0000-7c5b-1fe5cf120000 pid=4815 clone guuid=ac3089ff-1a00-0000-7c5b-1fe5d0120000 pid=4816 /usr/bin/wget guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=ac3089ff-1a00-0000-7c5b-1fe5d0120000 pid=4816 execve guuid=ef92a0ff-1a00-0000-7c5b-1fe5d1120000 pid=4817 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=ef92a0ff-1a00-0000-7c5b-1fe5d1120000 pid=4817 execve guuid=a179daff-1a00-0000-7c5b-1fe5d3120000 pid=4819 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=a179daff-1a00-0000-7c5b-1fe5d3120000 pid=4819 clone guuid=1c1ce3ff-1a00-0000-7c5b-1fe5d4120000 pid=4820 /usr/bin/wget guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=1c1ce3ff-1a00-0000-7c5b-1fe5d4120000 pid=4820 execve guuid=9037f5ff-1a00-0000-7c5b-1fe5d6120000 pid=4822 /usr/bin/chmod guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=9037f5ff-1a00-0000-7c5b-1fe5d6120000 pid=4822 execve guuid=50903100-1b00-0000-7c5b-1fe5d8120000 pid=4824 /usr/bin/dash guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=50903100-1b00-0000-7c5b-1fe5d8120000 pid=4824 clone guuid=1d903800-1b00-0000-7c5b-1fe5d9120000 pid=4825 /usr/bin/rm delete-file guuid=6f2b0ba3-1900-0000-7c5b-1fe5710f0000 pid=3953->guuid=1d903800-1b00-0000-7c5b-1fe5d9120000 pid=4825 execve 04c56e7c-282b-5750-bed9-7d1d59974342 89.42.88.217:80 guuid=cd063da3-1900-0000-7c5b-1fe5720f0000 pid=3954->04c56e7c-282b-5750-bed9-7d1d59974342 send: 144B guuid=b255fe61-1a00-0000-7c5b-1fe53e110000 pid=4414->04c56e7c-282b-5750-bed9-7d1d59974342 send: 138B guuid=bcb0c4ae-1a00-0000-7c5b-1fe5ef110000 pid=4591->04c56e7c-282b-5750-bed9-7d1d59974342 send: 138B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e8434df8-1a00-0000-7c5b-1fe590120000 pid=4752->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f06a73f8-1a00-0000-7c5b-1fe592120000 pid=4754 /home/sandbox/.dbusd zombie guuid=e8434df8-1a00-0000-7c5b-1fe590120000 pid=4752->guuid=f06a73f8-1a00-0000-7c5b-1fe592120000 pid=4754 clone guuid=420a7df8-1a00-0000-7c5b-1fe593120000 pid=4755 /home/sandbox/.dbusd zombie guuid=e8434df8-1a00-0000-7c5b-1fe590120000 pid=4752->guuid=420a7df8-1a00-0000-7c5b-1fe593120000 pid=4755 clone guuid=24a68df8-1a00-0000-7c5b-1fe595120000 pid=4757 /home/sandbox/.dbusd write-config zombie guuid=420a7df8-1a00-0000-7c5b-1fe593120000 pid=4755->guuid=24a68df8-1a00-0000-7c5b-1fe595120000 pid=4757 clone guuid=9a7ff9f8-1a00-0000-7c5b-1fe597120000 pid=4759 /usr/bin/dash guuid=24a68df8-1a00-0000-7c5b-1fe595120000 pid=4757->guuid=9a7ff9f8-1a00-0000-7c5b-1fe597120000 pid=4759 execve guuid=13bb4cfa-1a00-0000-7c5b-1fe59f120000 pid=4767 /home/sandbox/.dbusd dns net send-data guuid=24a68df8-1a00-0000-7c5b-1fe595120000 pid=4757->guuid=13bb4cfa-1a00-0000-7c5b-1fe59f120000 pid=4767 clone guuid=cfc336f9-1a00-0000-7c5b-1fe599120000 pid=4761 /usr/bin/cp guuid=9a7ff9f8-1a00-0000-7c5b-1fe597120000 pid=4759->guuid=cfc336f9-1a00-0000-7c5b-1fe599120000 pid=4761 execve guuid=13bb4cfa-1a00-0000-7c5b-1fe59f120000 pid=4767->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B a1cb65f6-afd3-5a3a-9fa0-f13741392136 top1miku.duckdns.org:2004 guuid=13bb4cfa-1a00-0000-7c5b-1fe59f120000 pid=4767->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 14B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-08-11 05:34:13 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 88bd4fd3404943114c13ac91fcb7c41b077736aa1e9984aa0c24fd4bc97d4957

(this sample)

  
Delivery method
Distributed via web download

Comments