MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 88e932b053f376300b793058cfff2dc32a31990e125f8b11750e458b8bafd1c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 88e932b053f376300b793058cfff2dc32a31990e125f8b11750e458b8bafd1c9
SHA3-384 hash: ca6d856129fbfed488a82ea2cc8a24405e269344ecce54f8d138be94284a00737c21eb89d2379ffcbb067294a304b759
SHA1 hash: be084836af5fc605ead393dd9945e74f28dc3f01
MD5 hash: 13816fd674275045b421000306e08051
humanhash: angel-shade-hawaii-michigan
File name:cat.sh
Download: download sample
Signature Mirai
File size:2'011 bytes
First seen:2025-09-14 11:12:39 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dFXOpo2hCQ8zmqYfsQdt6hRPtNaKjRI6XoODOqRdmDUR3fNvMGRZ1x91ZRDKLBqM:rAhj8ufTcvFTDsjk5atYqAFID
TLSH T1A541D68D1056D161D48CCF42F0B1C774984FE9C9B3A25EE1E463BDB9988D940B517B37
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.71.207/x86_6468d848489d2ba487699cbeffdcd31fb39d22ccb94ab1a2c2983e9538ea551f39 Miraielf mirai ua-wget
http://196.251.71.207/aarch64205ba61018cf49c6ff5df49abfcadbe33a38e830fa4f8f657ffa6e2db230ebde Miraielf mirai ua-wget
http://196.251.71.207/m68k46c181467de432471fa4470564e669ad6bff30b0066720d56552bf6bfbf3b8cd Miraielf mirai ua-wget
http://196.251.71.207/mips551cc47e8a99c0a26e471f433dc186fa24a8381745007255e351ec7b136ed494 Miraielf mirai ua-wget
http://196.251.71.207/mipseld99d31dba21bc3f823b71baf039e14ce6b8a3cd824fb15e497dca07d736d2290 Miraielf mirai ua-wget
http://196.251.71.207/powerpcbb7ca4d580b48c1d259924a7760b2c35c9a24f1d5d816ce321d3b3a2a2c5f92f Miraielf mirai ua-wget
http://196.251.71.207/sparcae7347197673650a50dd6d22ee236c01ccc81a35290d718a25e036b4e9503c90 Miraielf mirai ua-wget
http://196.251.71.207/sh47a14f5cbf5f5cc545c10af6a2226e2d50421ccfd04fbd204ec3eeabf6b49e010 Miraielf mirai ua-wget
http://196.251.71.207/arc9d328f65c944f1043f487c4992a19f80d6142d36f0cf49396e024d159afa6723 Miraielf mirai ua-wget
http://196.251.71.207/i4862b0d719f5dc2684cb734a73e40c1d03a6ee40f408ac15bef289d7e4d9d73f7e8 Miraielf mirai ua-wget
http://196.251.71.207/armv4lfd49df844db6a4e03dac56d1edb17150171b5aa0c14ad92bfae57fbaa82073d0 Gafgytelf gafgyt ua-wget
http://196.251.71.207/armv5la3346c751947ea632fc3405ea46a20730ce4452067c62100fdcf6c62b30f8dd8 Gafgytelf gafgyt ua-wget
http://196.251.71.207/armv6l310f1c6e525d19af148754454e5c6808371fb024ad6f52622c2c044530b4deb0 Miraielf mirai ua-wget
http://196.251.71.207/armv7la270e1c59417d8ec9a977213d3c4fb5dbd7f2507337d0bc703c2ee2e96aaafab Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-14T08:43:00Z UTC
Last seen:
2025-09-14T08:43:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=35102106-1a00-0000-c82b-e228af080000 pid=2223 /usr/bin/sudo guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230 /tmp/sample.bin guuid=35102106-1a00-0000-c82b-e228af080000 pid=2223->guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230 execve guuid=09398108-1a00-0000-c82b-e228b9080000 pid=2233 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=09398108-1a00-0000-c82b-e228b9080000 pid=2233 execve guuid=c1739e10-1a00-0000-c82b-e228cd080000 pid=2253 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=c1739e10-1a00-0000-c82b-e228cd080000 pid=2253 execve guuid=0409f010-1a00-0000-c82b-e228d0080000 pid=2256 /usr/bin/dbus-daemon write-config guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=0409f010-1a00-0000-c82b-e228d0080000 pid=2256 execve guuid=af74aa13-1a00-0000-c82b-e228d8080000 pid=2264 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=af74aa13-1a00-0000-c82b-e228d8080000 pid=2264 execve guuid=28d96419-1a00-0000-c82b-e228e2080000 pid=2274 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=28d96419-1a00-0000-c82b-e228e2080000 pid=2274 execve guuid=c8dfd519-1a00-0000-c82b-e228e5080000 pid=2277 /usr/bin/dash guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=c8dfd519-1a00-0000-c82b-e228e5080000 pid=2277 clone guuid=4eb6871a-1a00-0000-c82b-e228e8080000 pid=2280 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=4eb6871a-1a00-0000-c82b-e228e8080000 pid=2280 execve guuid=3c7a801f-1a00-0000-c82b-e228f2080000 pid=2290 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=3c7a801f-1a00-0000-c82b-e228f2080000 pid=2290 execve guuid=06ebff1f-1a00-0000-c82b-e228f4080000 pid=2292 /usr/bin/dash guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=06ebff1f-1a00-0000-c82b-e228f4080000 pid=2292 clone guuid=a47eec21-1a00-0000-c82b-e228f9080000 pid=2297 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=a47eec21-1a00-0000-c82b-e228f9080000 pid=2297 execve guuid=85299027-1a00-0000-c82b-e22800090000 pid=2304 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=85299027-1a00-0000-c82b-e22800090000 pid=2304 execve guuid=ddcdef27-1a00-0000-c82b-e22803090000 pid=2307 /usr/bin/dash guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=ddcdef27-1a00-0000-c82b-e22803090000 pid=2307 clone guuid=22f0cd2a-1a00-0000-c82b-e22808090000 pid=2312 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=22f0cd2a-1a00-0000-c82b-e22808090000 pid=2312 execve guuid=22bc0730-1a00-0000-c82b-e22811090000 pid=2321 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=22bc0730-1a00-0000-c82b-e22811090000 pid=2321 execve guuid=60657330-1a00-0000-c82b-e22814090000 pid=2324 /usr/bin/dash guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=60657330-1a00-0000-c82b-e22814090000 pid=2324 clone guuid=de12cd31-1a00-0000-c82b-e22819090000 pid=2329 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=de12cd31-1a00-0000-c82b-e22819090000 pid=2329 execve guuid=b84d8f36-1a00-0000-c82b-e22822090000 pid=2338 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=b84d8f36-1a00-0000-c82b-e22822090000 pid=2338 execve guuid=cf25d836-1a00-0000-c82b-e22823090000 pid=2339 /usr/bin/dash guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=cf25d836-1a00-0000-c82b-e22823090000 pid=2339 clone guuid=ee0f9837-1a00-0000-c82b-e22826090000 pid=2342 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=ee0f9837-1a00-0000-c82b-e22826090000 pid=2342 execve guuid=8a134c3b-1a00-0000-c82b-e2282b090000 pid=2347 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=8a134c3b-1a00-0000-c82b-e2282b090000 pid=2347 execve guuid=c973ab3b-1a00-0000-c82b-e2282e090000 pid=2350 /usr/bin/dash guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=c973ab3b-1a00-0000-c82b-e2282e090000 pid=2350 clone guuid=2b61773c-1a00-0000-c82b-e22833090000 pid=2355 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=2b61773c-1a00-0000-c82b-e22833090000 pid=2355 execve guuid=419df745-1a00-0000-c82b-e22846090000 pid=2374 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=419df745-1a00-0000-c82b-e22846090000 pid=2374 execve guuid=d1f74146-1a00-0000-c82b-e22848090000 pid=2376 /usr/bin/dash guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=d1f74146-1a00-0000-c82b-e22848090000 pid=2376 clone guuid=cfe5d746-1a00-0000-c82b-e2284b090000 pid=2379 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=cfe5d746-1a00-0000-c82b-e2284b090000 pid=2379 execve guuid=e6433d4c-1a00-0000-c82b-e2284c090000 pid=2380 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=e6433d4c-1a00-0000-c82b-e2284c090000 pid=2380 execve guuid=a69d894c-1a00-0000-c82b-e2284d090000 pid=2381 /usr/bin/dash guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=a69d894c-1a00-0000-c82b-e2284d090000 pid=2381 clone guuid=f0161b4d-1a00-0000-c82b-e2284f090000 pid=2383 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=f0161b4d-1a00-0000-c82b-e2284f090000 pid=2383 execve guuid=66d9a551-1a00-0000-c82b-e22857090000 pid=2391 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=66d9a551-1a00-0000-c82b-e22857090000 pid=2391 execve guuid=6f8cff51-1a00-0000-c82b-e22859090000 pid=2393 /usr/bin/systemctl write-config guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=6f8cff51-1a00-0000-c82b-e22859090000 pid=2393 execve guuid=de749855-1a00-0000-c82b-e22865090000 pid=2405 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=de749855-1a00-0000-c82b-e22865090000 pid=2405 execve guuid=ff5e055a-1a00-0000-c82b-e2286a090000 pid=2410 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=ff5e055a-1a00-0000-c82b-e2286a090000 pid=2410 execve guuid=8cdb535a-1a00-0000-c82b-e2286d090000 pid=2413 /usr/bin/dash guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=8cdb535a-1a00-0000-c82b-e2286d090000 pid=2413 clone guuid=5cebc95a-1a00-0000-c82b-e22870090000 pid=2416 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=5cebc95a-1a00-0000-c82b-e22870090000 pid=2416 execve guuid=333bda5f-1a00-0000-c82b-e2287e090000 pid=2430 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=333bda5f-1a00-0000-c82b-e2287e090000 pid=2430 execve guuid=89721b60-1a00-0000-c82b-e22880090000 pid=2432 /usr/bin/dash guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=89721b60-1a00-0000-c82b-e22880090000 pid=2432 clone guuid=daea9b60-1a00-0000-c82b-e22883090000 pid=2435 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=daea9b60-1a00-0000-c82b-e22883090000 pid=2435 execve guuid=69709e65-1a00-0000-c82b-e22890090000 pid=2448 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=69709e65-1a00-0000-c82b-e22890090000 pid=2448 execve guuid=684ce065-1a00-0000-c82b-e22892090000 pid=2450 /usr/bin/dash guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=684ce065-1a00-0000-c82b-e22892090000 pid=2450 clone guuid=07687e66-1a00-0000-c82b-e22895090000 pid=2453 /usr/bin/wget net send-data write-file guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=07687e66-1a00-0000-c82b-e22895090000 pid=2453 execve guuid=c9b9a16b-1a00-0000-c82b-e22899090000 pid=2457 /usr/bin/chmod guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=c9b9a16b-1a00-0000-c82b-e22899090000 pid=2457 execve guuid=1f38df6b-1a00-0000-c82b-e2289a090000 pid=2458 /usr/bin/dash guuid=b9ee0708-1a00-0000-c82b-e228b6080000 pid=2230->guuid=1f38df6b-1a00-0000-c82b-e2289a090000 pid=2458 clone 8fe6df6f-38ca-513d-9aab-787258c1e881 196.251.71.207:80 guuid=09398108-1a00-0000-c82b-e228b9080000 pid=2233->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 135B guuid=ad054011-1a00-0000-c82b-e228d2080000 pid=2258 /usr/bin/dash guuid=0409f010-1a00-0000-c82b-e228d0080000 pid=2256->guuid=ad054011-1a00-0000-c82b-e228d2080000 pid=2258 execve guuid=43ed6411-1a00-0000-c82b-e228d3080000 pid=2259 /usr/bin/cp guuid=ad054011-1a00-0000-c82b-e228d2080000 pid=2258->guuid=43ed6411-1a00-0000-c82b-e228d3080000 pid=2259 execve guuid=af74aa13-1a00-0000-c82b-e228d8080000 pid=2264->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 136B guuid=4eb6871a-1a00-0000-c82b-e228e8080000 pid=2280->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 133B guuid=a47eec21-1a00-0000-c82b-e228f9080000 pid=2297->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 133B guuid=22f0cd2a-1a00-0000-c82b-e22808090000 pid=2312->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 135B guuid=de12cd31-1a00-0000-c82b-e22819090000 pid=2329->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 136B guuid=ee0f9837-1a00-0000-c82b-e22826090000 pid=2342->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 134B guuid=2b61773c-1a00-0000-c82b-e22833090000 pid=2355->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 132B guuid=cfe5d746-1a00-0000-c82b-e2284b090000 pid=2379->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 132B guuid=f0161b4d-1a00-0000-c82b-e2284f090000 pid=2383->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 133B guuid=195e4952-1a00-0000-c82b-e2285a090000 pid=2394 /usr/bin/dash guuid=6f8cff51-1a00-0000-c82b-e22859090000 pid=2393->guuid=195e4952-1a00-0000-c82b-e2285a090000 pid=2394 execve guuid=9ec99a52-1a00-0000-c82b-e2285b090000 pid=2395 /usr/bin/cp guuid=195e4952-1a00-0000-c82b-e2285a090000 pid=2394->guuid=9ec99a52-1a00-0000-c82b-e2285b090000 pid=2395 execve guuid=de749855-1a00-0000-c82b-e22865090000 pid=2405->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 135B guuid=5cebc95a-1a00-0000-c82b-e22870090000 pid=2416->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 135B guuid=daea9b60-1a00-0000-c82b-e22883090000 pid=2435->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 135B guuid=07687e66-1a00-0000-c82b-e22895090000 pid=2453->8fe6df6f-38ca-513d-9aab-787258c1e881 send: 135B
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-09-14 11:13:36 UTC
File Type:
Text (Shell)
AV detection:
14 of 38 (36.84%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Enumerates running processes
Modifies init.d
Modifies rc script
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 88e932b053f376300b793058cfff2dc32a31990e125f8b11750e458b8bafd1c9

(this sample)

  
Delivery method
Distributed via web download

Comments