MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8c7b3f63caa72cffd4af29633789b2df5a4f8e6d4fec731ddca7767feddd3bf7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 8c7b3f63caa72cffd4af29633789b2df5a4f8e6d4fec731ddca7767feddd3bf7
SHA3-384 hash: 03c0d8bf8b9d3b2c3c18958f5d8552cbf4cb88a58a8b6c9d32cf185a4d774dd162c71a723e7d50a20570596d3558adef
SHA1 hash: 4ed0888fb57a82815b3ae4917ea68e0602ff437d
MD5 hash: 6f305966478d61ee3a071d32c1fcfae9
humanhash: beryllium-twelve-eight-missouri
File name:l
Download: download sample
Signature Mirai
File size:924 bytes
First seen:2025-09-24 16:55:22 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:E22IbO5zOt+MB0Cq2kVNaNmkVJZkJS8bav:EAO5CEA06k5kVkJS8bav
TLSH T19A1127CF00B09C315C81499A75938C1865CBC5F81ACB8F98648A047BB8CA918B376F99
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://194.31.222.17/v/armv7lc3788d92bfc3a08dbcca4476832c46b099bcad182c56cdbccf837eb0edb6cd77 Miraiarm elf geofenced mirai ua-wget USA
http://194.31.222.17/v/armv5l79d810e67c7bd6c6669214c1c4b631829d90726886b4167a232813d8434ef3f7 Miraiarm elf geofenced mirai ua-wget USA
http://194.31.222.17/v/armv4le333d6098ba7af114b4e8b290f0e587592067b8e153798bf4763262d2074ad96 Miraiarm elf geofenced mirai ua-wget USA
http://s.cuckstudios.su/l50c803adcccd987eb77495efe4ed62c7fe939beea1259508ab2270f7e7384b72 Miraibotnetdomain DEU geofenced mirai opendir sh ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
ps1
First seen:
2025-09-24T15:07:00Z UTC
Last seen:
2025-09-24T15:07:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=642023bd-1600-0000-2d69-08fc950c0000 pid=3221 /usr/bin/sudo guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222 /tmp/sample.bin guuid=642023bd-1600-0000-2d69-08fc950c0000 pid=3221->guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222 execve guuid=0c6d14c0-1600-0000-2d69-08fc970c0000 pid=3223 /usr/bin/dash guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=0c6d14c0-1600-0000-2d69-08fc970c0000 pid=3223 clone guuid=0916dac1-1600-0000-2d69-08fc9e0c0000 pid=3230 /usr/bin/rm delete-file guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=0916dac1-1600-0000-2d69-08fc9e0c0000 pid=3230 execve guuid=0c871fc2-1600-0000-2d69-08fc9f0c0000 pid=3231 /usr/bin/rm delete-file guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=0c871fc2-1600-0000-2d69-08fc9f0c0000 pid=3231 execve guuid=23fc5ac2-1600-0000-2d69-08fca10c0000 pid=3233 /usr/bin/rm delete-file guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=23fc5ac2-1600-0000-2d69-08fca10c0000 pid=3233 execve guuid=414f96c2-1600-0000-2d69-08fca30c0000 pid=3235 /usr/bin/dash guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=414f96c2-1600-0000-2d69-08fca30c0000 pid=3235 clone guuid=70667ac3-1600-0000-2d69-08fca80c0000 pid=3240 /usr/bin/dash guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=70667ac3-1600-0000-2d69-08fca80c0000 pid=3240 clone guuid=561db9c3-1600-0000-2d69-08fcab0c0000 pid=3243 /usr/bin/dash guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=561db9c3-1600-0000-2d69-08fcab0c0000 pid=3243 clone guuid=8e9713d0-1600-0000-2d69-08fcbc0c0000 pid=3260 /usr/bin/chmod guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=8e9713d0-1600-0000-2d69-08fcbc0c0000 pid=3260 execve guuid=26135ad0-1600-0000-2d69-08fcbd0c0000 pid=3261 /usr/bin/dash guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=26135ad0-1600-0000-2d69-08fcbd0c0000 pid=3261 clone guuid=fbe2ebd1-1600-0000-2d69-08fcc30c0000 pid=3267 /usr/bin/dash guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=fbe2ebd1-1600-0000-2d69-08fcc30c0000 pid=3267 clone guuid=e05641dc-1600-0000-2d69-08fce10c0000 pid=3297 /usr/bin/chmod guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=e05641dc-1600-0000-2d69-08fce10c0000 pid=3297 execve guuid=aad4afdc-1600-0000-2d69-08fce30c0000 pid=3299 /usr/bin/dash guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=aad4afdc-1600-0000-2d69-08fce30c0000 pid=3299 clone guuid=bba052de-1600-0000-2d69-08fce90c0000 pid=3305 /usr/bin/dash guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=bba052de-1600-0000-2d69-08fce90c0000 pid=3305 clone guuid=65136ce9-1600-0000-2d69-08fc000d0000 pid=3328 /usr/bin/chmod guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=65136ce9-1600-0000-2d69-08fc000d0000 pid=3328 execve guuid=e5dbe2e9-1600-0000-2d69-08fc030d0000 pid=3331 /usr/bin/dash guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=e5dbe2e9-1600-0000-2d69-08fc030d0000 pid=3331 clone guuid=00a35eeb-1600-0000-2d69-08fc070d0000 pid=3335 /usr/bin/grep guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=00a35eeb-1600-0000-2d69-08fc070d0000 pid=3335 execve guuid=39acc8eb-1600-0000-2d69-08fc090d0000 pid=3337 /usr/bin/sed guuid=490a92bf-1600-0000-2d69-08fc960c0000 pid=3222->guuid=39acc8eb-1600-0000-2d69-08fc090d0000 pid=3337 execve guuid=49df3ac0-1600-0000-2d69-08fc980c0000 pid=3224 /usr/bin/cat guuid=0c6d14c0-1600-0000-2d69-08fc970c0000 pid=3223->guuid=49df3ac0-1600-0000-2d69-08fc980c0000 pid=3224 execve guuid=05e24dc0-1600-0000-2d69-08fc990c0000 pid=3225 /usr/bin/grep guuid=0c6d14c0-1600-0000-2d69-08fc970c0000 pid=3223->guuid=05e24dc0-1600-0000-2d69-08fc990c0000 pid=3225 execve guuid=a45a5cc0-1600-0000-2d69-08fc9a0c0000 pid=3226 /usr/bin/grep guuid=0c6d14c0-1600-0000-2d69-08fc970c0000 pid=3223->guuid=a45a5cc0-1600-0000-2d69-08fc9a0c0000 pid=3226 execve guuid=d9756ac0-1600-0000-2d69-08fc9b0c0000 pid=3227 /usr/bin/grep guuid=0c6d14c0-1600-0000-2d69-08fc970c0000 pid=3223->guuid=d9756ac0-1600-0000-2d69-08fc9b0c0000 pid=3227 execve guuid=38b77cc0-1600-0000-2d69-08fc9c0c0000 pid=3228 /usr/bin/cut guuid=0c6d14c0-1600-0000-2d69-08fc970c0000 pid=3223->guuid=38b77cc0-1600-0000-2d69-08fc9c0c0000 pid=3228 execve guuid=dd049dc2-1600-0000-2d69-08fca40c0000 pid=3236 /usr/bin/cp write-file guuid=414f96c2-1600-0000-2d69-08fca30c0000 pid=3235->guuid=dd049dc2-1600-0000-2d69-08fca40c0000 pid=3236 execve guuid=1fca80c3-1600-0000-2d69-08fca90c0000 pid=3241 /usr/bin/chmod guuid=70667ac3-1600-0000-2d69-08fca80c0000 pid=3240->guuid=1fca80c3-1600-0000-2d69-08fca90c0000 pid=3241 execve guuid=10e1c0c3-1600-0000-2d69-08fcac0c0000 pid=3244 /usr/bin/wget net send-data write-file guuid=561db9c3-1600-0000-2d69-08fcab0c0000 pid=3243->guuid=10e1c0c3-1600-0000-2d69-08fcac0c0000 pid=3244 execve 287749b9-1937-53b1-8818-44b73ae22708 194.31.222.17:80 guuid=10e1c0c3-1600-0000-2d69-08fcac0c0000 pid=3244->287749b9-1937-53b1-8818-44b73ae22708 send: 136B guuid=7d12f4d1-1600-0000-2d69-08fcc40c0000 pid=3268 /usr/bin/wget net send-data write-file guuid=fbe2ebd1-1600-0000-2d69-08fcc30c0000 pid=3267->guuid=7d12f4d1-1600-0000-2d69-08fcc40c0000 pid=3268 execve guuid=7d12f4d1-1600-0000-2d69-08fcc40c0000 pid=3268->287749b9-1937-53b1-8818-44b73ae22708 send: 136B guuid=be8b59de-1600-0000-2d69-08fcea0c0000 pid=3306 /usr/bin/wget net send-data write-file guuid=bba052de-1600-0000-2d69-08fce90c0000 pid=3305->guuid=be8b59de-1600-0000-2d69-08fcea0c0000 pid=3306 execve guuid=be8b59de-1600-0000-2d69-08fcea0c0000 pid=3306->287749b9-1937-53b1-8818-44b73ae22708 send: 136B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2025-09-23 07:16:11 UTC
File Type:
Text (Shell)
AV detection:
8 of 38 (21.05%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8c7b3f63caa72cffd4af29633789b2df5a4f8e6d4fec731ddca7767feddd3bf7

(this sample)

Comments