MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9069e3de3de3894c0800ea0b0c01b19efc237033b7c6d1df04aa6bd7eadbf2c3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 9069e3de3de3894c0800ea0b0c01b19efc237033b7c6d1df04aa6bd7eadbf2c3
SHA3-384 hash: 314640832e26c7349c75b04a65f13ca54c59e68716338e08fe9f583bbb0bfd51be27e62e4d21aa0d99d4816e8ca7d52f
SHA1 hash: 9ed2f9c902927b456ee97a505d207a521e25e208
MD5 hash: 58e62ae3b5e8563c4abdf7501c0f715f
humanhash: three-snake-twenty-batman
File name:c.sh
Download: download sample
Signature Mirai
File size:1'118 bytes
First seen:2025-12-20 16:57:05 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3bQr3bQ18gdbQtNI2nbQexKdGSbQhbQnDvbQdW/9dsbQdRJR8RzSR7bQSa5aS3:3J3bULiVmNI2lKdh6ejA+32d+4qAjn
TLSH T1A1212CBC07B1A9425E449F48E46BD0CB911EACF9B5AFD912E0771C3D809432B30E5676
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://141.98.10.91/bins/sumrak.arma8e657d363b5dc97a9e887e8686306ea0acc346c0b4b1eaf97e23cf2504a028b Miraimirai opendir
http://141.98.10.91/bins/sumrak.arm5fe42c0e128ed02574179e239ec54ac6b3979c77912af2c287c79cf7cdad837d9 Miraimirai opendir
http://141.98.10.91/bins/sumrak.arm6c7c544bd12f4e96efe9522e2b1eec9e1aaca2963f1af9d6d825a77e23055ca4d Miraimirai opendir
http://141.98.10.91/bins/sumrak.arm70eaf8243e73a2f2de8164be8c565e3fb343a382ed4e850290d043621b87d6671 Miraimirai opendir
http://141.98.10.91/bins/sumrak.sh466c60404acaf2b67f97fc3cd57d8436641d88574c388ae6403729eb83ffeaaca Miraimirai opendir
http://141.98.10.91/bins/sumrak.arcn/an/aelf ua-wget
http://141.98.10.91/bins/sumrak.mips020b5d89315667708d7d91af70bbc3bdbbf9a2abc19282644def144a7c54d538 Miraimirai opendir
http://141.98.10.91/bins/sumrak.mipseln/an/aelf ua-wget
http://141.98.10.91/bins/sumrak.sparcn/an/aelf ua-wget
http://141.98.10.91/bins/sumrak.x86_645d763d962556094f1524a6e3202365c6d7611c4988772e5f26f136cd19becdc2 Miraimirai opendir
http://141.98.10.91/bins/sumrak.i6868f18c738a20bf65a34ab2c701c018eefe824bb2ff912a2b3907804de87af7f6c Miraimirai opendir
http://141.98.10.91/bins/sumrak.i5860b265a89f89abed68d47200ed1f27f4f1d68af668103176085e362fa8979f1e9 Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-20T15:10:00Z UTC
Last seen:
2025-12-21T02:00:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=612e3616-1a00-0000-1935-f8cff3080000 pid=2291 /usr/bin/sudo guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294 /tmp/sample.bin guuid=612e3616-1a00-0000-1935-f8cff3080000 pid=2291->guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294 execve guuid=deb7001a-1a00-0000-1935-f8cff7080000 pid=2295 /usr/bin/curl net send-data guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=deb7001a-1a00-0000-1935-f8cff7080000 pid=2295 execve guuid=c07d9b70-1a00-0000-1935-f8cf9a090000 pid=2458 /usr/bin/chmod guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=c07d9b70-1a00-0000-1935-f8cf9a090000 pid=2458 execve guuid=d388ea70-1a00-0000-1935-f8cf9b090000 pid=2459 /usr/bin/dash guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=d388ea70-1a00-0000-1935-f8cf9b090000 pid=2459 clone guuid=dd0dfc70-1a00-0000-1935-f8cf9c090000 pid=2460 /usr/bin/curl net send-data guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=dd0dfc70-1a00-0000-1935-f8cf9c090000 pid=2460 execve guuid=dda9e97a-1a00-0000-1935-f8cfb3090000 pid=2483 /usr/bin/chmod guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=dda9e97a-1a00-0000-1935-f8cfb3090000 pid=2483 execve guuid=6f223d7b-1a00-0000-1935-f8cfb5090000 pid=2485 /usr/bin/dash guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=6f223d7b-1a00-0000-1935-f8cfb5090000 pid=2485 clone guuid=2e1e4a7b-1a00-0000-1935-f8cfb6090000 pid=2486 /usr/bin/curl net send-data guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=2e1e4a7b-1a00-0000-1935-f8cfb6090000 pid=2486 execve guuid=ab2a988b-1a00-0000-1935-f8cfd7090000 pid=2519 /usr/bin/chmod guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=ab2a988b-1a00-0000-1935-f8cfd7090000 pid=2519 execve guuid=abe1dc8b-1a00-0000-1935-f8cfd9090000 pid=2521 /usr/bin/dash guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=abe1dc8b-1a00-0000-1935-f8cfd9090000 pid=2521 clone guuid=767af38b-1a00-0000-1935-f8cfda090000 pid=2522 /usr/bin/curl net send-data guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=767af38b-1a00-0000-1935-f8cfda090000 pid=2522 execve guuid=91155397-1a00-0000-1935-f8cff4090000 pid=2548 /usr/bin/chmod guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=91155397-1a00-0000-1935-f8cff4090000 pid=2548 execve guuid=3ed7ad97-1a00-0000-1935-f8cff5090000 pid=2549 /usr/bin/dash guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=3ed7ad97-1a00-0000-1935-f8cff5090000 pid=2549 clone guuid=58b9b997-1a00-0000-1935-f8cff6090000 pid=2550 /usr/bin/curl net send-data guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=58b9b997-1a00-0000-1935-f8cff6090000 pid=2550 execve guuid=f0ead5a9-1a00-0000-1935-f8cf250a0000 pid=2597 /usr/bin/chmod guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=f0ead5a9-1a00-0000-1935-f8cf250a0000 pid=2597 execve guuid=fed830aa-1a00-0000-1935-f8cf270a0000 pid=2599 /usr/bin/dash guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=fed830aa-1a00-0000-1935-f8cf270a0000 pid=2599 clone guuid=35273caa-1a00-0000-1935-f8cf280a0000 pid=2600 /usr/bin/curl net send-data guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=35273caa-1a00-0000-1935-f8cf280a0000 pid=2600 execve guuid=e2a53bb2-1a00-0000-1935-f8cf3d0a0000 pid=2621 /usr/bin/chmod guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=e2a53bb2-1a00-0000-1935-f8cf3d0a0000 pid=2621 execve guuid=e5648eb2-1a00-0000-1935-f8cf3f0a0000 pid=2623 /usr/bin/dash guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=e5648eb2-1a00-0000-1935-f8cf3f0a0000 pid=2623 clone guuid=ce4b98b2-1a00-0000-1935-f8cf400a0000 pid=2624 /usr/bin/curl net send-data guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=ce4b98b2-1a00-0000-1935-f8cf400a0000 pid=2624 execve guuid=5efc16be-1a00-0000-1935-f8cf5e0a0000 pid=2654 /usr/bin/chmod guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=5efc16be-1a00-0000-1935-f8cf5e0a0000 pid=2654 execve guuid=e56c58be-1a00-0000-1935-f8cf600a0000 pid=2656 /usr/bin/dash guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=e56c58be-1a00-0000-1935-f8cf600a0000 pid=2656 clone guuid=d0905ebe-1a00-0000-1935-f8cf610a0000 pid=2657 /usr/bin/curl net send-data guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=d0905ebe-1a00-0000-1935-f8cf610a0000 pid=2657 execve guuid=d20b6bc4-1a00-0000-1935-f8cf720a0000 pid=2674 /usr/bin/chmod guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=d20b6bc4-1a00-0000-1935-f8cf720a0000 pid=2674 execve guuid=3e27b2c4-1a00-0000-1935-f8cf740a0000 pid=2676 /usr/bin/dash guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=3e27b2c4-1a00-0000-1935-f8cf740a0000 pid=2676 clone guuid=88f1bdc4-1a00-0000-1935-f8cf750a0000 pid=2677 /usr/bin/curl net send-data guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=88f1bdc4-1a00-0000-1935-f8cf750a0000 pid=2677 execve guuid=a963a7ca-1a00-0000-1935-f8cf840a0000 pid=2692 /usr/bin/chmod guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=a963a7ca-1a00-0000-1935-f8cf840a0000 pid=2692 execve guuid=6757f6ca-1a00-0000-1935-f8cf860a0000 pid=2694 /usr/bin/dash guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=6757f6ca-1a00-0000-1935-f8cf860a0000 pid=2694 clone guuid=8c8e03cb-1a00-0000-1935-f8cf870a0000 pid=2695 /usr/bin/curl net send-data guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=8c8e03cb-1a00-0000-1935-f8cf870a0000 pid=2695 execve guuid=badf37d8-1a00-0000-1935-f8cfab0a0000 pid=2731 /usr/bin/chmod guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=badf37d8-1a00-0000-1935-f8cfab0a0000 pid=2731 execve guuid=d41c99d8-1a00-0000-1935-f8cfad0a0000 pid=2733 /usr/bin/dash guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=d41c99d8-1a00-0000-1935-f8cfad0a0000 pid=2733 clone guuid=94bda4d8-1a00-0000-1935-f8cfae0a0000 pid=2734 /usr/bin/curl net send-data guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=94bda4d8-1a00-0000-1935-f8cfae0a0000 pid=2734 execve guuid=b2609ee2-1a00-0000-1935-f8cfcb0a0000 pid=2763 /usr/bin/chmod guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=b2609ee2-1a00-0000-1935-f8cfcb0a0000 pid=2763 execve guuid=e12cefe2-1a00-0000-1935-f8cfcd0a0000 pid=2765 /usr/bin/dash guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=e12cefe2-1a00-0000-1935-f8cfcd0a0000 pid=2765 clone guuid=5e7afde2-1a00-0000-1935-f8cfce0a0000 pid=2766 /usr/bin/curl net send-data guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=5e7afde2-1a00-0000-1935-f8cfce0a0000 pid=2766 execve guuid=9b32bfec-1a00-0000-1935-f8cfe80a0000 pid=2792 /usr/bin/chmod guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=9b32bfec-1a00-0000-1935-f8cfe80a0000 pid=2792 execve guuid=6e3b31ed-1a00-0000-1935-f8cfe90a0000 pid=2793 /usr/bin/dash guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=6e3b31ed-1a00-0000-1935-f8cfe90a0000 pid=2793 clone guuid=455a6ded-1a00-0000-1935-f8cfea0a0000 pid=2794 /usr/bin/rm delete-file guuid=f03fc119-1a00-0000-1935-f8cff6080000 pid=2294->guuid=455a6ded-1a00-0000-1935-f8cfea0a0000 pid=2794 execve df7b537f-758f-5cbd-9393-addaae2cab06 141.98.10.91:80 guuid=deb7001a-1a00-0000-1935-f8cff7080000 pid=2295->df7b537f-758f-5cbd-9393-addaae2cab06 send: 91B guuid=dd0dfc70-1a00-0000-1935-f8cf9c090000 pid=2460->df7b537f-758f-5cbd-9393-addaae2cab06 send: 92B guuid=2e1e4a7b-1a00-0000-1935-f8cfb6090000 pid=2486->df7b537f-758f-5cbd-9393-addaae2cab06 send: 92B guuid=767af38b-1a00-0000-1935-f8cfda090000 pid=2522->df7b537f-758f-5cbd-9393-addaae2cab06 send: 92B guuid=58b9b997-1a00-0000-1935-f8cff6090000 pid=2550->df7b537f-758f-5cbd-9393-addaae2cab06 send: 91B guuid=35273caa-1a00-0000-1935-f8cf280a0000 pid=2600->df7b537f-758f-5cbd-9393-addaae2cab06 send: 91B guuid=ce4b98b2-1a00-0000-1935-f8cf400a0000 pid=2624->df7b537f-758f-5cbd-9393-addaae2cab06 send: 92B guuid=d0905ebe-1a00-0000-1935-f8cf610a0000 pid=2657->df7b537f-758f-5cbd-9393-addaae2cab06 send: 94B guuid=88f1bdc4-1a00-0000-1935-f8cf750a0000 pid=2677->df7b537f-758f-5cbd-9393-addaae2cab06 send: 93B guuid=8c8e03cb-1a00-0000-1935-f8cf870a0000 pid=2695->df7b537f-758f-5cbd-9393-addaae2cab06 send: 94B guuid=94bda4d8-1a00-0000-1935-f8cfae0a0000 pid=2734->df7b537f-758f-5cbd-9393-addaae2cab06 send: 92B guuid=5e7afde2-1a00-0000-1935-f8cfce0a0000 pid=2766->df7b537f-758f-5cbd-9393-addaae2cab06 send: 92B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-20 16:58:28 UTC
File Type:
Text (Shell)
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 9069e3de3de3894c0800ea0b0c01b19efc237033b7c6d1df04aa6bd7eadbf2c3

(this sample)

Comments