MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8d05784053d2e626ff73cca99be41a3f027df0393788e79c508695da15e11a75. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 8d05784053d2e626ff73cca99be41a3f027df0393788e79c508695da15e11a75
SHA3-384 hash: 16889caaddb712e1aa7fbb1319ac46b0a04f7978d7e1f66a75944973d10ddcaf1e522b433313e2980125c01acb1b274f
SHA1 hash: ca7e38642cf2c7a7b9ef5ce47382d1e4dc06856e
MD5 hash: df088332cdaa17f747c98485fb81f6ea
humanhash: washington-princess-king-alanine
File name:r
Download: download sample
Signature Mirai
File size:993 bytes
First seen:2025-06-19 11:00:57 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:k9E5zLt+MB08xJxDkvSxnkxnmkvSx3xJkvSxSx0kv8jn:kC5XEA0gzDkvOomkvOhJkvOO0kv8j
TLSH T1D811E9CF41A5CD7268404EDD31930A1AA4C6C9D907CF8FC6F48E01BAA1CD94DB251FB9
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.26.90.217/vv/armv4la82594f321a14d22c63b44b8b3f4e5dcb725aeda14db201cfe59d6b37cb8093f Miraielf gafgyt mirai ua-wget
http://94.26.90.217/vv/armv5ld64ce359bc97c9643e66057dbd0ea9ed69d5272487e873119dc7a01134f852bc Miraielf gafgyt mirai ua-wget
http://94.26.90.217/vv/armv6l176858d674f19ed1c385ebfd952caea9f6a76f4b44828d6b8f21985476a35df0 Miraielf gafgyt mirai ua-wget
http://94.26.90.217/vv/armv7lae5dbccdfcd0e48e2065b462be5879d1c103e3dc9c553ce8eb319c6385580d78 Miraielf gafgyt mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Status:
terminated
Behavior Graph:
%3 guuid=b2924783-1600-0000-2b7d-7e63080d0000 pid=3336 /usr/bin/sudo guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341 /tmp/sample.bin guuid=b2924783-1600-0000-2b7d-7e63080d0000 pid=3336->guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341 execve guuid=04bb6885-1600-0000-2b7d-7e630f0d0000 pid=3343 /usr/bin/cat guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=04bb6885-1600-0000-2b7d-7e630f0d0000 pid=3343 execve guuid=6647d485-1600-0000-2b7d-7e63110d0000 pid=3345 /usr/bin/dash guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=6647d485-1600-0000-2b7d-7e63110d0000 pid=3345 clone guuid=83cf8b86-1600-0000-2b7d-7e63190d0000 pid=3353 /usr/bin/rm delete-file guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=83cf8b86-1600-0000-2b7d-7e63190d0000 pid=3353 execve guuid=3d8ece86-1600-0000-2b7d-7e631b0d0000 pid=3355 /usr/bin/rm delete-file guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=3d8ece86-1600-0000-2b7d-7e631b0d0000 pid=3355 execve guuid=7d621587-1600-0000-2b7d-7e631d0d0000 pid=3357 /usr/bin/rm delete-file guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=7d621587-1600-0000-2b7d-7e631d0d0000 pid=3357 execve guuid=9ee35e87-1600-0000-2b7d-7e631f0d0000 pid=3359 /usr/bin/rm guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=9ee35e87-1600-0000-2b7d-7e631f0d0000 pid=3359 execve guuid=4e419d87-1600-0000-2b7d-7e63200d0000 pid=3360 /usr/bin/dash guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=4e419d87-1600-0000-2b7d-7e63200d0000 pid=3360 clone guuid=ac5ad788-1600-0000-2b7d-7e63250d0000 pid=3365 /usr/bin/dash guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=ac5ad788-1600-0000-2b7d-7e63250d0000 pid=3365 clone guuid=ced72189-1600-0000-2b7d-7e63270d0000 pid=3367 /usr/bin/dash guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=ced72189-1600-0000-2b7d-7e63270d0000 pid=3367 clone guuid=9d6384d4-1600-0000-2b7d-7e63b20d0000 pid=3506 /usr/bin/chmod guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=9d6384d4-1600-0000-2b7d-7e63b20d0000 pid=3506 execve guuid=00adfad4-1600-0000-2b7d-7e63b40d0000 pid=3508 /usr/bin/dash guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=00adfad4-1600-0000-2b7d-7e63b40d0000 pid=3508 clone guuid=eef63ed6-1600-0000-2b7d-7e63b60d0000 pid=3510 /usr/bin/dash guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=eef63ed6-1600-0000-2b7d-7e63b60d0000 pid=3510 clone guuid=6502ff46-1700-0000-2b7d-7e63610e0000 pid=3681 /usr/bin/chmod guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=6502ff46-1700-0000-2b7d-7e63610e0000 pid=3681 execve guuid=bb677447-1700-0000-2b7d-7e63630e0000 pid=3683 /usr/bin/dash guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=bb677447-1700-0000-2b7d-7e63630e0000 pid=3683 clone guuid=e5fc7d48-1700-0000-2b7d-7e636a0e0000 pid=3690 /usr/bin/dash guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=e5fc7d48-1700-0000-2b7d-7e636a0e0000 pid=3690 clone guuid=5ac12c96-1700-0000-2b7d-7e632a0f0000 pid=3882 /usr/bin/chmod guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=5ac12c96-1700-0000-2b7d-7e632a0f0000 pid=3882 execve guuid=69db8696-1700-0000-2b7d-7e632b0f0000 pid=3883 /usr/bin/dash guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=69db8696-1700-0000-2b7d-7e632b0f0000 pid=3883 clone guuid=a0f86697-1700-0000-2b7d-7e632f0f0000 pid=3887 /usr/bin/dash guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=a0f86697-1700-0000-2b7d-7e632f0f0000 pid=3887 clone guuid=4a976ee5-1700-0000-2b7d-7e63d80f0000 pid=4056 /usr/bin/chmod guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=4a976ee5-1700-0000-2b7d-7e63d80f0000 pid=4056 execve guuid=69abe2e5-1700-0000-2b7d-7e63da0f0000 pid=4058 /usr/bin/dash guuid=50751285-1600-0000-2b7d-7e630d0d0000 pid=3341->guuid=69abe2e5-1700-0000-2b7d-7e63da0f0000 pid=4058 clone guuid=a32ee085-1600-0000-2b7d-7e63130d0000 pid=3347 /usr/bin/cat guuid=6647d485-1600-0000-2b7d-7e63110d0000 pid=3345->guuid=a32ee085-1600-0000-2b7d-7e63130d0000 pid=3347 execve guuid=506fe485-1600-0000-2b7d-7e63140d0000 pid=3348 /usr/bin/grep guuid=6647d485-1600-0000-2b7d-7e63110d0000 pid=3345->guuid=506fe485-1600-0000-2b7d-7e63140d0000 pid=3348 execve guuid=183fea85-1600-0000-2b7d-7e63150d0000 pid=3349 /usr/bin/grep guuid=6647d485-1600-0000-2b7d-7e63110d0000 pid=3345->guuid=183fea85-1600-0000-2b7d-7e63150d0000 pid=3349 execve guuid=e038f185-1600-0000-2b7d-7e63160d0000 pid=3350 /usr/bin/grep guuid=6647d485-1600-0000-2b7d-7e63110d0000 pid=3345->guuid=e038f185-1600-0000-2b7d-7e63160d0000 pid=3350 execve guuid=762ff685-1600-0000-2b7d-7e63170d0000 pid=3351 /usr/bin/cut guuid=6647d485-1600-0000-2b7d-7e63110d0000 pid=3345->guuid=762ff685-1600-0000-2b7d-7e63170d0000 pid=3351 execve guuid=5b92a687-1600-0000-2b7d-7e63210d0000 pid=3361 /usr/bin/cp write-file guuid=4e419d87-1600-0000-2b7d-7e63200d0000 pid=3360->guuid=5b92a687-1600-0000-2b7d-7e63210d0000 pid=3361 execve guuid=5724dc88-1600-0000-2b7d-7e63260d0000 pid=3366 /usr/bin/chmod guuid=ac5ad788-1600-0000-2b7d-7e63250d0000 pid=3365->guuid=5724dc88-1600-0000-2b7d-7e63260d0000 pid=3366 execve guuid=62382d89-1600-0000-2b7d-7e63280d0000 pid=3368 /usr/bin/wget net send-data write-file guuid=ced72189-1600-0000-2b7d-7e63270d0000 pid=3367->guuid=62382d89-1600-0000-2b7d-7e63280d0000 pid=3368 execve fbb9a6c5-a595-5199-8d51-c1632aa72f16 94.26.90.217:80 guuid=62382d89-1600-0000-2b7d-7e63280d0000 pid=3368->fbb9a6c5-a595-5199-8d51-c1632aa72f16 send: 136B guuid=d5d253d6-1600-0000-2b7d-7e63b70d0000 pid=3511 /usr/bin/wget net send-data write-file guuid=eef63ed6-1600-0000-2b7d-7e63b60d0000 pid=3510->guuid=d5d253d6-1600-0000-2b7d-7e63b70d0000 pid=3511 execve guuid=d5d253d6-1600-0000-2b7d-7e63b70d0000 pid=3511->fbb9a6c5-a595-5199-8d51-c1632aa72f16 send: 136B guuid=65fd8c48-1700-0000-2b7d-7e636b0e0000 pid=3691 /usr/bin/wget net send-data write-file guuid=e5fc7d48-1700-0000-2b7d-7e636a0e0000 pid=3690->guuid=65fd8c48-1700-0000-2b7d-7e636b0e0000 pid=3691 execve guuid=65fd8c48-1700-0000-2b7d-7e636b0e0000 pid=3691->fbb9a6c5-a595-5199-8d51-c1632aa72f16 send: 136B guuid=a9687197-1700-0000-2b7d-7e63300f0000 pid=3888 /usr/bin/wget net send-data write-file guuid=a0f86697-1700-0000-2b7d-7e632f0f0000 pid=3887->guuid=a9687197-1700-0000-2b7d-7e63300f0000 pid=3888 execve guuid=a9687197-1700-0000-2b7d-7e63300f0000 pid=3888->fbb9a6c5-a595-5199-8d51-c1632aa72f16 send: 136B
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2025-06-19 11:04:41 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8d05784053d2e626ff73cca99be41a3f027df0393788e79c508695da15e11a75

(this sample)

  
Delivery method
Distributed via web download

Comments