MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8b7dc9188d31e6b1f44728e44bfdfad35e7c1a29f49724beb99d4d7c64d95d2d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 8b7dc9188d31e6b1f44728e44bfdfad35e7c1a29f49724beb99d4d7c64d95d2d
SHA3-384 hash: bf1022aea7d4c7b430f85b37a58c036cf0bb2bf54c3136ac691c42144bfdc61e077f2081fed772e7d497e9eb5a01e0dc
SHA1 hash: 530a4c08480dc9893a15ac0af326a5d037a2332d
MD5 hash: 0ec99dee479f671ec8c45c5937cb3919
humanhash: social-timing-uranus-table
File name:b
Download: download sample
Signature Mirai
File size:393 bytes
First seen:2025-12-17 18:52:41 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:h9OnFflE0FkeDyMwXBLFMLFdnB6Ea5XKbF8dvwtMs:d0FSBKzY7COs
TLSH T1AAE092D524710075F848BA6466A94B9CF071FBC566C02B38C8DD7977880DD0C7584E32
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://kpq.at/f79f7b96b1cfa658a6e67bfc701ab897d52a8756cd827a413f7088a8d4c933406 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-17T19:47:00Z UTC
Last seen:
2025-12-17T20:33:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=896c1816-1900-0000-652c-8de384080000 pid=2180 /usr/bin/sudo guuid=dfe63b19-1900-0000-652c-8de38e080000 pid=2190 /tmp/sample.bin guuid=896c1816-1900-0000-652c-8de384080000 pid=2180->guuid=dfe63b19-1900-0000-652c-8de38e080000 pid=2190 execve guuid=3cbc9c19-1900-0000-652c-8de390080000 pid=2192 /usr/bin/wget dns net send-data write-file guuid=dfe63b19-1900-0000-652c-8de38e080000 pid=2190->guuid=3cbc9c19-1900-0000-652c-8de390080000 pid=2192 execve guuid=69fa4f2c-1900-0000-652c-8de3c3080000 pid=2243 /usr/bin/wget dns net send-data write-file guuid=dfe63b19-1900-0000-652c-8de38e080000 pid=2190->guuid=69fa4f2c-1900-0000-652c-8de3c3080000 pid=2243 execve guuid=3ac7c435-1900-0000-652c-8de3d7080000 pid=2263 /usr/bin/chmod guuid=dfe63b19-1900-0000-652c-8de38e080000 pid=2190->guuid=3ac7c435-1900-0000-652c-8de3d7080000 pid=2263 execve guuid=6b893836-1900-0000-652c-8de3d9080000 pid=2265 /usr/bin/dash guuid=dfe63b19-1900-0000-652c-8de38e080000 pid=2190->guuid=6b893836-1900-0000-652c-8de3d9080000 pid=2265 clone guuid=d4e94036-1900-0000-652c-8de3da080000 pid=2266 /usr/bin/sleep guuid=dfe63b19-1900-0000-652c-8de38e080000 pid=2190->guuid=d4e94036-1900-0000-652c-8de3da080000 pid=2266 execve guuid=5d1d21ae-1900-0000-652c-8de3a3090000 pid=2467 /usr/bin/rm delete-file guuid=dfe63b19-1900-0000-652c-8de38e080000 pid=2190->guuid=5d1d21ae-1900-0000-652c-8de3a3090000 pid=2467 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=3cbc9c19-1900-0000-652c-8de390080000 pid=2192->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B 8de90fb0-2a98-5c62-9fc5-9fac58f25014 kpq.at:80 guuid=3cbc9c19-1900-0000-652c-8de390080000 pid=2192->8de90fb0-2a98-5c62-9fc5-9fac58f25014 send: 122B guuid=69fa4f2c-1900-0000-652c-8de3c3080000 pid=2243->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=69fa4f2c-1900-0000-652c-8de3c3080000 pid=2243->8de90fb0-2a98-5c62-9fc5-9fac58f25014 send: 122B guuid=1c2a4136-1900-0000-652c-8de3db080000 pid=2267 /usr/bin/dash guuid=6b893836-1900-0000-652c-8de3d9080000 pid=2265->guuid=1c2a4136-1900-0000-652c-8de3db080000 pid=2267 clone
Threat name:
Script-Shell.Downloader.MiraiB
Status:
Malicious
First seen:
2025-12-17 19:22:09 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8b7dc9188d31e6b1f44728e44bfdfad35e7c1a29f49724beb99d4d7c64d95d2d

(this sample)

  
Delivery method
Distributed via web download

Comments