MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8df3986c1c1391c6e7e765c2ceca28e0d4286a2edf54119d352b38d35ec2f583. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 8df3986c1c1391c6e7e765c2ceca28e0d4286a2edf54119d352b38d35ec2f583
SHA3-384 hash: ef40ceb077c2420c02fe940fb1c29af59cc7e0a9cce2db84a16c13caff2ebe93811f21189a0a62daaa7ece20142e2aa6
SHA1 hash: 6787222de811e946f90029a4056370ef19c94b28
MD5 hash: 681073504e2d8e2e0c1a0ba0ce9c48e6
humanhash: spring-johnny-salami-carbon
File name:wget.sh
Download: download sample
Signature Mirai
File size:1'149 bytes
First seen:2025-07-09 08:50:21 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:2NC3gNBI3NuNNIUuiupNn4K6x9mr8xjGp6NmBpE27d6oCSdV2fxn:2nOY2Hpuz9mr8xjGp6NmBpE27d6ondV0
TLSH T17221FC894E23D04B543C8F21E09B4769479E86C2F0B46E65698E4C77948DB04B438F5B
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.66.32/LjEZs/top1miku.armd67f3c81398537d6e361b5002a54d9ef3b4de2a95aee647e6f7696305f8ebb4a Miraielf mirai ua-wget
http://196.251.66.32/LjEZs/top1miku.arm54300c039a3d8b17a9e2663d0e8853141dfc93b1e11975706ca3a463b7284e410 Miraielf mirai ua-wget
http://196.251.66.32/LjEZs/top1miku.arm6eaa5a72f4c6f1f7ae025c4222cb84277a4f73566a7c9fed4ccf52120a16edf72 Miraielf mirai ua-wget
http://196.251.66.32/LjEZs/top1miku.arm7b43beb52a40d65c9fad461f1a2c7bf52d7d32cbc4ce3413c7c110d0e73875965 Miraielf mirai ua-wget
http://196.251.66.32/LjEZs/top1miku.m68k9b2fa701ca354364b50a5f165c945bc99b58f00e789c11b1b141f74d6c46ecf4 Miraielf mirai ua-wget
http://196.251.66.32/LjEZs/top1miku.mips05bb4a3491ddf037a4282c6fdb19406103dd8acdedbfca229768dcddbb156b77 Miraielf mirai ua-wget
http://196.251.66.32/LjEZs/top1miku.mpslbdcff829ac7520228ad160fadaf081b44a8ff17397ef7e3138fb7b544879582a Miraielf mirai ua-wget
http://196.251.66.32/LjEZs/top1miku.ppc96155cd3d0b32ac3bcb71b9dc94ec0c83db739836f2e924b00532e473d3f05ac Miraielf mirai ua-wget
http://196.251.66.32/LjEZs/top1miku.sh46666837a8339c4d64813e79346e6a07a3e71f41c912fe93ce47d9dc17299dfd7 Miraielf mirai ua-wget
http://196.251.66.32/LjEZs/top1miku.spcbe5da15beacb98e8e95dcbb3f9658e3aa9fc07665df8b6a8a10bcf185a2f54ad Miraielf mirai ua-wget
http://196.251.66.32/LjEZs/top1miku.x86243e36182318eff7614e2a6ffb0ea54c7136a90034bc4611c76bca76c4dfb637 Miraielf mirai ua-wget
http://196.251.66.32/LjEZs/top1miku.x86_64bbb67f68d2bb43c17451ca6dcb3e728e4d3f10c561e89278093178b90c80f6e5 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
24
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=1ef49190-1a00-0000-a603-1c9a040a0000 pid=2564 /usr/bin/sudo guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572 /tmp/sample.bin guuid=1ef49190-1a00-0000-a603-1c9a040a0000 pid=2564->guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572 execve guuid=fd4b5993-1a00-0000-a603-1c9a0f0a0000 pid=2575 /usr/bin/wget net send-data write-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=fd4b5993-1a00-0000-a603-1c9a0f0a0000 pid=2575 execve guuid=de808999-1a00-0000-a603-1c9a210a0000 pid=2593 /usr/bin/chmod guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=de808999-1a00-0000-a603-1c9a210a0000 pid=2593 execve guuid=7fb5ca99-1a00-0000-a603-1c9a230a0000 pid=2595 /usr/bin/dash guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=7fb5ca99-1a00-0000-a603-1c9a230a0000 pid=2595 clone guuid=daf14e9a-1a00-0000-a603-1c9a260a0000 pid=2598 /usr/bin/wget net send-data write-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=daf14e9a-1a00-0000-a603-1c9a260a0000 pid=2598 execve guuid=94ab129f-1a00-0000-a603-1c9a340a0000 pid=2612 /usr/bin/chmod guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=94ab129f-1a00-0000-a603-1c9a340a0000 pid=2612 execve guuid=f6d55c9f-1a00-0000-a603-1c9a360a0000 pid=2614 /usr/bin/dash guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=f6d55c9f-1a00-0000-a603-1c9a360a0000 pid=2614 clone guuid=45f4ef9f-1a00-0000-a603-1c9a3a0a0000 pid=2618 /usr/bin/wget net send-data write-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=45f4ef9f-1a00-0000-a603-1c9a3a0a0000 pid=2618 execve guuid=a67ce2a6-1a00-0000-a603-1c9a4c0a0000 pid=2636 /usr/bin/chmod guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=a67ce2a6-1a00-0000-a603-1c9a4c0a0000 pid=2636 execve guuid=0c9052a7-1a00-0000-a603-1c9a4e0a0000 pid=2638 /usr/bin/dash guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=0c9052a7-1a00-0000-a603-1c9a4e0a0000 pid=2638 clone guuid=0dbc31a9-1a00-0000-a603-1c9a540a0000 pid=2644 /usr/bin/wget net send-data write-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=0dbc31a9-1a00-0000-a603-1c9a540a0000 pid=2644 execve guuid=5360c9af-1a00-0000-a603-1c9a670a0000 pid=2663 /usr/bin/chmod guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=5360c9af-1a00-0000-a603-1c9a670a0000 pid=2663 execve guuid=8a567bb0-1a00-0000-a603-1c9a6a0a0000 pid=2666 /usr/bin/dash guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=8a567bb0-1a00-0000-a603-1c9a6a0a0000 pid=2666 clone guuid=6b955fb1-1a00-0000-a603-1c9a6f0a0000 pid=2671 /usr/bin/wget net send-data write-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=6b955fb1-1a00-0000-a603-1c9a6f0a0000 pid=2671 execve guuid=8f252eb6-1a00-0000-a603-1c9a800a0000 pid=2688 /usr/bin/chmod guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=8f252eb6-1a00-0000-a603-1c9a800a0000 pid=2688 execve guuid=774b89b6-1a00-0000-a603-1c9a820a0000 pid=2690 /usr/bin/dash guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=774b89b6-1a00-0000-a603-1c9a820a0000 pid=2690 clone guuid=4a4736b7-1a00-0000-a603-1c9a850a0000 pid=2693 /usr/bin/wget net send-data write-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=4a4736b7-1a00-0000-a603-1c9a850a0000 pid=2693 execve guuid=a9914dbc-1a00-0000-a603-1c9a960a0000 pid=2710 /usr/bin/chmod guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=a9914dbc-1a00-0000-a603-1c9a960a0000 pid=2710 execve guuid=042ab4bc-1a00-0000-a603-1c9a980a0000 pid=2712 /usr/bin/dash guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=042ab4bc-1a00-0000-a603-1c9a980a0000 pid=2712 clone guuid=d20934bd-1a00-0000-a603-1c9a9c0a0000 pid=2716 /usr/bin/wget net send-data write-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=d20934bd-1a00-0000-a603-1c9a9c0a0000 pid=2716 execve guuid=2a8884c1-1a00-0000-a603-1c9aa90a0000 pid=2729 /usr/bin/chmod guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=2a8884c1-1a00-0000-a603-1c9aa90a0000 pid=2729 execve guuid=fd29c7c1-1a00-0000-a603-1c9aab0a0000 pid=2731 /usr/bin/dash guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=fd29c7c1-1a00-0000-a603-1c9aab0a0000 pid=2731 clone guuid=efd16dc3-1a00-0000-a603-1c9ab00a0000 pid=2736 /usr/bin/wget net send-data write-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=efd16dc3-1a00-0000-a603-1c9ab00a0000 pid=2736 execve guuid=4225b3c7-1a00-0000-a603-1c9abe0a0000 pid=2750 /usr/bin/chmod guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=4225b3c7-1a00-0000-a603-1c9abe0a0000 pid=2750 execve guuid=b1f318c8-1a00-0000-a603-1c9ac00a0000 pid=2752 /usr/bin/dash guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=b1f318c8-1a00-0000-a603-1c9ac00a0000 pid=2752 clone guuid=8dd2b8c9-1a00-0000-a603-1c9ac40a0000 pid=2756 /usr/bin/wget net send-data write-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=8dd2b8c9-1a00-0000-a603-1c9ac40a0000 pid=2756 execve guuid=2647dfcf-1a00-0000-a603-1c9ad30a0000 pid=2771 /usr/bin/chmod guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=2647dfcf-1a00-0000-a603-1c9ad30a0000 pid=2771 execve guuid=d92f5ad0-1a00-0000-a603-1c9ad50a0000 pid=2773 /usr/bin/dash guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=d92f5ad0-1a00-0000-a603-1c9ad50a0000 pid=2773 clone guuid=1b60dcd0-1a00-0000-a603-1c9ad80a0000 pid=2776 /usr/bin/wget net send-data write-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=1b60dcd0-1a00-0000-a603-1c9ad80a0000 pid=2776 execve guuid=4fe393d5-1a00-0000-a603-1c9ae00a0000 pid=2784 /usr/bin/chmod guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=4fe393d5-1a00-0000-a603-1c9ae00a0000 pid=2784 execve guuid=67edded5-1a00-0000-a603-1c9ae20a0000 pid=2786 /usr/bin/dash guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=67edded5-1a00-0000-a603-1c9ae20a0000 pid=2786 clone guuid=ab5862d6-1a00-0000-a603-1c9ae60a0000 pid=2790 /usr/bin/wget net send-data write-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=ab5862d6-1a00-0000-a603-1c9ae60a0000 pid=2790 execve guuid=410519db-1a00-0000-a603-1c9aef0a0000 pid=2799 /usr/bin/chmod guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=410519db-1a00-0000-a603-1c9aef0a0000 pid=2799 execve guuid=83938adb-1a00-0000-a603-1c9af00a0000 pid=2800 /home/sandbox/top1miku.x86 net guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=83938adb-1a00-0000-a603-1c9af00a0000 pid=2800 execve guuid=5805ecdb-1a00-0000-a603-1c9af20a0000 pid=2802 /usr/bin/wget net send-data write-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=5805ecdb-1a00-0000-a603-1c9af20a0000 pid=2802 execve guuid=c84636e3-1a00-0000-a603-1c9afd0a0000 pid=2813 /usr/bin/chmod guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=c84636e3-1a00-0000-a603-1c9afd0a0000 pid=2813 execve guuid=4a4998e3-1a00-0000-a603-1c9afe0a0000 pid=2814 /home/sandbox/top1miku.x86_64 net guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=4a4998e3-1a00-0000-a603-1c9afe0a0000 pid=2814 execve guuid=e83a7a0e-1c00-0000-a603-1c9a150d0000 pid=3349 /usr/bin/rm delete-file guuid=90940593-1a00-0000-a603-1c9a0c0a0000 pid=2572->guuid=e83a7a0e-1c00-0000-a603-1c9a150d0000 pid=3349 execve b4463e29-c6ee-5341-9c75-3bf4da178e37 196.251.66.32:80 guuid=fd4b5993-1a00-0000-a603-1c9a0f0a0000 pid=2575->b4463e29-c6ee-5341-9c75-3bf4da178e37 send: 146B guuid=daf14e9a-1a00-0000-a603-1c9a260a0000 pid=2598->b4463e29-c6ee-5341-9c75-3bf4da178e37 send: 147B guuid=45f4ef9f-1a00-0000-a603-1c9a3a0a0000 pid=2618->b4463e29-c6ee-5341-9c75-3bf4da178e37 send: 147B guuid=0dbc31a9-1a00-0000-a603-1c9a540a0000 pid=2644->b4463e29-c6ee-5341-9c75-3bf4da178e37 send: 147B guuid=6b955fb1-1a00-0000-a603-1c9a6f0a0000 pid=2671->b4463e29-c6ee-5341-9c75-3bf4da178e37 send: 147B guuid=4a4736b7-1a00-0000-a603-1c9a850a0000 pid=2693->b4463e29-c6ee-5341-9c75-3bf4da178e37 send: 147B guuid=d20934bd-1a00-0000-a603-1c9a9c0a0000 pid=2716->b4463e29-c6ee-5341-9c75-3bf4da178e37 send: 147B guuid=efd16dc3-1a00-0000-a603-1c9ab00a0000 pid=2736->b4463e29-c6ee-5341-9c75-3bf4da178e37 send: 146B guuid=8dd2b8c9-1a00-0000-a603-1c9ac40a0000 pid=2756->b4463e29-c6ee-5341-9c75-3bf4da178e37 send: 146B guuid=1b60dcd0-1a00-0000-a603-1c9ad80a0000 pid=2776->b4463e29-c6ee-5341-9c75-3bf4da178e37 send: 146B guuid=ab5862d6-1a00-0000-a603-1c9ae60a0000 pid=2790->b4463e29-c6ee-5341-9c75-3bf4da178e37 send: 146B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=83938adb-1a00-0000-a603-1c9af00a0000 pid=2800->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ad6fd6db-1a00-0000-a603-1c9af10a0000 pid=2801 /home/sandbox/top1miku.x86 net send-data zombie guuid=83938adb-1a00-0000-a603-1c9af00a0000 pid=2800->guuid=ad6fd6db-1a00-0000-a603-1c9af10a0000 pid=2801 clone guuid=ad6fd6db-1a00-0000-a603-1c9af10a0000 pid=2801->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con b07a7f29-f341-5457-ac66-92995794ff16 196.251.66.32:1302 guuid=ad6fd6db-1a00-0000-a603-1c9af10a0000 pid=2801->b07a7f29-f341-5457-ac66-92995794ff16 send: 48B guuid=4a0eefdb-1a00-0000-a603-1c9af30a0000 pid=2803 /home/sandbox/top1miku.x86 guuid=ad6fd6db-1a00-0000-a603-1c9af10a0000 pid=2801->guuid=4a0eefdb-1a00-0000-a603-1c9af30a0000 pid=2803 clone guuid=a31df8db-1a00-0000-a603-1c9af40a0000 pid=2804 /home/sandbox/top1miku.x86 guuid=ad6fd6db-1a00-0000-a603-1c9af10a0000 pid=2801->guuid=a31df8db-1a00-0000-a603-1c9af40a0000 pid=2804 clone guuid=5805ecdb-1a00-0000-a603-1c9af20a0000 pid=2802->b4463e29-c6ee-5341-9c75-3bf4da178e37 send: 149B guuid=4a4998e3-1a00-0000-a603-1c9afe0a0000 pid=2814->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 836dce14-4611-5ec0-94fd-a9232d5a3558 0.0.0.0:9473 guuid=4a4998e3-1a00-0000-a603-1c9afe0a0000 pid=2814->836dce14-4611-5ec0-94fd-a9232d5a3558 con guuid=0042720e-1c00-0000-a603-1c9a140d0000 pid=3348 /home/sandbox/top1miku.x86_64 net send-data zombie guuid=4a4998e3-1a00-0000-a603-1c9afe0a0000 pid=2814->guuid=0042720e-1c00-0000-a603-1c9a140d0000 pid=3348 clone guuid=0042720e-1c00-0000-a603-1c9a140d0000 pid=3348->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0042720e-1c00-0000-a603-1c9a140d0000 pid=3348->b07a7f29-f341-5457-ac66-92995794ff16 send: 206B guuid=8c807b0e-1c00-0000-a603-1c9a160d0000 pid=3350 /home/sandbox/top1miku.x86_64 guuid=0042720e-1c00-0000-a603-1c9a140d0000 pid=3348->guuid=8c807b0e-1c00-0000-a603-1c9a160d0000 pid=3350 clone guuid=088d880e-1c00-0000-a603-1c9a170d0000 pid=3351 /home/sandbox/top1miku.x86_64 guuid=0042720e-1c00-0000-a603-1c9a140d0000 pid=3348->guuid=088d880e-1c00-0000-a603-1c9a170d0000 pid=3351 clone
Threat name:
Document-HTML.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-07-09 08:50:36 UTC
File Type:
Text (Shell)
AV detection:
13 of 38 (34.21%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8df3986c1c1391c6e7e765c2ceca28e0d4286a2edf54119d352b38d35ec2f583

(this sample)

  
Delivery method
Distributed via web download

Comments