MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 91e00fc87168c9d1ca27ce8a87625015f480011d8f41d5e8e996ba341ff6cd7c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 91e00fc87168c9d1ca27ce8a87625015f480011d8f41d5e8e996ba341ff6cd7c
SHA3-384 hash: a44943313becd36bef2b160e32acd432ae321daeed9be828a304566fc4056f4f8b9577955c6f486ef9336ee793f951de
SHA1 hash: 9799f025ad384d6e5dfcdb3edfe1b5f119ea6145
MD5 hash: 2681250a50d924d5cd3cdd0a6e55ffb5
humanhash: quiet-arkansas-nine-oven
File name:wget.sh
Download: download sample
Signature Mirai
File size:1'160 bytes
First seen:2025-06-30 15:41:46 UTC
Last seen:2025-07-01 05:55:44 UTC
File type: sh
MIME type:text/plain
ssdeep 24:O+N+e+GNI6s+vKB+gN+L+f8+Qu+Y+QR+j+m3C+oxn:d5KN+5uwUx
TLSH T197211DBF07115027C01DDED230694610828A8283B86C4BB97BDE4CB76E84EC6EC49E5B
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.87.244/00101010101001/morte.arm0e1c862fb7b3927bbf3f71b5c83949151be2dfedd584eb482c173ce2e851dd3f Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.arm5a67885abc3a05d82c9083e3df77c227e91f38aa242bc9988caf35b3a447ca596 Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.arm661dfc5c73839259cb55254701e29c43307b89acaecf4c14b51be5d209ce80d5b Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.arm795d5407a92ac4b36ed3d0f10b3fb494fed6ae21491b9f5fce152b85b78fb2e12 Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.m68k7c5e6035418ce9f52bdb00eaff5e23d3d7a41f7a75554249c6cf6e44ce34ae3f Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.mipsb4d52619e506d97e60184c38b62b2b88461afd363d0744ccbebf3e26cdcb6bc3 Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.mpslf4d2edf5cb22fd836842fb0c277395557f3a1329cc90c280cc12839c3e6fd72c Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.ppc437732d5bde3a06c54a001342f0ad3735088bc10d3aaeb69d038520c3a00a9db Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.sh4e0fadfca7d4f0704722720c739c817d05fa639fdbb6edbd961d0083f73342c80 Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.spcb98844c282ecfff203dabee396106d9726de54c4821bd35208239f7621d774b9 Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.x864fef063a9f02ba436aa8231ae6e68833cc7007d4acd4c911b0742fc6edb7f3e0 Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.x86_645f40e73a84e77e83a454da3ee487429836e3bdec4ceffc19d0d26c4901a911dd Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
4
# of downloads :
78
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
downloader ransomware mirai agent
Status:
terminated
Behavior Graph:
%3 guuid=8f95cfb6-1800-0000-e327-32686e0a0000 pid=2670 /usr/bin/sudo guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678 /tmp/sample.bin guuid=8f95cfb6-1800-0000-e327-32686e0a0000 pid=2670->guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678 execve guuid=4c3bcdb8-1800-0000-e327-3268780a0000 pid=2680 /usr/bin/wget net send-data write-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=4c3bcdb8-1800-0000-e327-3268780a0000 pid=2680 execve guuid=20956abd-1800-0000-e327-3268870a0000 pid=2695 /usr/bin/chmod guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=20956abd-1800-0000-e327-3268870a0000 pid=2695 execve guuid=ec95b8bd-1800-0000-e327-3268890a0000 pid=2697 /usr/bin/dash guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=ec95b8bd-1800-0000-e327-3268890a0000 pid=2697 clone guuid=5cc762be-1800-0000-e327-32688d0a0000 pid=2701 /usr/bin/wget net send-data write-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=5cc762be-1800-0000-e327-32688d0a0000 pid=2701 execve guuid=509989c1-1800-0000-e327-3268980a0000 pid=2712 /usr/bin/chmod guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=509989c1-1800-0000-e327-3268980a0000 pid=2712 execve guuid=1e6cfdc1-1800-0000-e327-32689a0a0000 pid=2714 /usr/bin/dash guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=1e6cfdc1-1800-0000-e327-32689a0a0000 pid=2714 clone guuid=5e70cfc2-1800-0000-e327-32689f0a0000 pid=2719 /usr/bin/wget net send-data write-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=5e70cfc2-1800-0000-e327-32689f0a0000 pid=2719 execve guuid=9a3630c7-1800-0000-e327-3268a90a0000 pid=2729 /usr/bin/chmod guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=9a3630c7-1800-0000-e327-3268a90a0000 pid=2729 execve guuid=e54f82c7-1800-0000-e327-3268ab0a0000 pid=2731 /usr/bin/dash guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=e54f82c7-1800-0000-e327-3268ab0a0000 pid=2731 clone guuid=1cd217c8-1800-0000-e327-3268af0a0000 pid=2735 /usr/bin/wget net send-data write-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=1cd217c8-1800-0000-e327-3268af0a0000 pid=2735 execve guuid=76ee7fcb-1800-0000-e327-3268b90a0000 pid=2745 /usr/bin/chmod guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=76ee7fcb-1800-0000-e327-3268b90a0000 pid=2745 execve guuid=6c93bdcb-1800-0000-e327-3268bb0a0000 pid=2747 /usr/bin/dash guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=6c93bdcb-1800-0000-e327-3268bb0a0000 pid=2747 clone guuid=ab3c39cc-1800-0000-e327-3268be0a0000 pid=2750 /usr/bin/wget net send-data write-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=ab3c39cc-1800-0000-e327-3268be0a0000 pid=2750 execve guuid=09fdaecf-1800-0000-e327-3268c70a0000 pid=2759 /usr/bin/chmod guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=09fdaecf-1800-0000-e327-3268c70a0000 pid=2759 execve guuid=ca7ceccf-1800-0000-e327-3268c90a0000 pid=2761 /usr/bin/dash guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=ca7ceccf-1800-0000-e327-3268c90a0000 pid=2761 clone guuid=8ebf6ad0-1800-0000-e327-3268cd0a0000 pid=2765 /usr/bin/wget net send-data write-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=8ebf6ad0-1800-0000-e327-3268cd0a0000 pid=2765 execve guuid=5b731dd5-1800-0000-e327-3268d00a0000 pid=2768 /usr/bin/chmod guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=5b731dd5-1800-0000-e327-3268d00a0000 pid=2768 execve guuid=b97a7ad5-1800-0000-e327-3268d10a0000 pid=2769 /usr/bin/dash guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=b97a7ad5-1800-0000-e327-3268d10a0000 pid=2769 clone guuid=c9cb2ad6-1800-0000-e327-3268d40a0000 pid=2772 /usr/bin/wget net send-data write-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=c9cb2ad6-1800-0000-e327-3268d40a0000 pid=2772 execve guuid=b2225cda-1800-0000-e327-3268dc0a0000 pid=2780 /usr/bin/chmod guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=b2225cda-1800-0000-e327-3268dc0a0000 pid=2780 execve guuid=c4a1c9da-1800-0000-e327-3268df0a0000 pid=2783 /usr/bin/dash guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=c4a1c9da-1800-0000-e327-3268df0a0000 pid=2783 clone guuid=f2bb7fdb-1800-0000-e327-3268e40a0000 pid=2788 /usr/bin/wget net send-data write-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=f2bb7fdb-1800-0000-e327-3268e40a0000 pid=2788 execve guuid=067b30df-1800-0000-e327-3268ec0a0000 pid=2796 /usr/bin/chmod guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=067b30df-1800-0000-e327-3268ec0a0000 pid=2796 execve guuid=b08a7adf-1800-0000-e327-3268ee0a0000 pid=2798 /usr/bin/dash guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=b08a7adf-1800-0000-e327-3268ee0a0000 pid=2798 clone guuid=0e5f7fdf-1800-0000-e327-3268ef0a0000 pid=2799 /usr/bin/wget net send-data write-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=0e5f7fdf-1800-0000-e327-3268ef0a0000 pid=2799 execve guuid=c7cbfce2-1800-0000-e327-3268f40a0000 pid=2804 /usr/bin/chmod guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=c7cbfce2-1800-0000-e327-3268f40a0000 pid=2804 execve guuid=264f37e3-1800-0000-e327-3268f60a0000 pid=2806 /usr/bin/dash guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=264f37e3-1800-0000-e327-3268f60a0000 pid=2806 clone guuid=5817d2e3-1800-0000-e327-3268f90a0000 pid=2809 /usr/bin/wget net send-data write-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=5817d2e3-1800-0000-e327-3268f90a0000 pid=2809 execve guuid=87da1fe7-1800-0000-e327-3268020b0000 pid=2818 /usr/bin/chmod guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=87da1fe7-1800-0000-e327-3268020b0000 pid=2818 execve guuid=628d7ee7-1800-0000-e327-3268040b0000 pid=2820 /usr/bin/dash guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=628d7ee7-1800-0000-e327-3268040b0000 pid=2820 clone guuid=874e22e8-1800-0000-e327-3268080b0000 pid=2824 /usr/bin/wget net send-data write-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=874e22e8-1800-0000-e327-3268080b0000 pid=2824 execve guuid=5bbfe7ed-1800-0000-e327-32680b0b0000 pid=2827 /usr/bin/chmod guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=5bbfe7ed-1800-0000-e327-32680b0b0000 pid=2827 execve guuid=478538ee-1800-0000-e327-32680c0b0000 pid=2828 /home/sandbox/morte.x86 net guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=478538ee-1800-0000-e327-32680c0b0000 pid=2828 execve guuid=3b3ddf1c-1a00-0000-e327-3268230d0000 pid=3363 /usr/bin/wget net send-data write-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=3b3ddf1c-1a00-0000-e327-3268230d0000 pid=3363 execve guuid=b658f920-1a00-0000-e327-32682b0d0000 pid=3371 /usr/bin/chmod guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=b658f920-1a00-0000-e327-32682b0d0000 pid=3371 execve guuid=b44a5f21-1a00-0000-e327-32682d0d0000 pid=3373 /home/sandbox/morte.x86_64 mprotect-exec net guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=b44a5f21-1a00-0000-e327-32682d0d0000 pid=3373 execve guuid=0242139a-1a00-0000-e327-3268060e0000 pid=3590 /usr/bin/rm delete-file guuid=ae3a89b8-1800-0000-e327-3268760a0000 pid=2678->guuid=0242139a-1a00-0000-e327-3268060e0000 pid=3590 execve ad49dc11-8491-5478-bc0d-f4c61eb1e83c 196.251.87.244:80 guuid=4c3bcdb8-1800-0000-e327-3268780a0000 pid=2680->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 153B guuid=5cc762be-1800-0000-e327-32688d0a0000 pid=2701->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 154B guuid=5e70cfc2-1800-0000-e327-32689f0a0000 pid=2719->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 154B guuid=1cd217c8-1800-0000-e327-3268af0a0000 pid=2735->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 154B guuid=ab3c39cc-1800-0000-e327-3268be0a0000 pid=2750->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 154B guuid=8ebf6ad0-1800-0000-e327-3268cd0a0000 pid=2765->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 154B guuid=c9cb2ad6-1800-0000-e327-3268d40a0000 pid=2772->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 154B guuid=f2bb7fdb-1800-0000-e327-3268e40a0000 pid=2788->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 153B guuid=0e5f7fdf-1800-0000-e327-3268ef0a0000 pid=2799->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 153B guuid=5817d2e3-1800-0000-e327-3268f90a0000 pid=2809->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 153B guuid=874e22e8-1800-0000-e327-3268080b0000 pid=2824->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 153B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=478538ee-1800-0000-e327-32680c0b0000 pid=2828->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5c1579ef-1800-0000-e327-32680f0b0000 pid=2831 /home/sandbox/morte.x86 guuid=478538ee-1800-0000-e327-32680c0b0000 pid=2828->guuid=5c1579ef-1800-0000-e327-32680f0b0000 pid=2831 clone guuid=e259b21c-1a00-0000-e327-3268200d0000 pid=3360 /home/sandbox/morte.x86 guuid=478538ee-1800-0000-e327-32680c0b0000 pid=2828->guuid=e259b21c-1a00-0000-e327-3268200d0000 pid=3360 clone guuid=8d10cd1c-1a00-0000-e327-3268220d0000 pid=3362 /home/sandbox/morte.x86 net send-data zombie guuid=478538ee-1800-0000-e327-32680c0b0000 pid=2828->guuid=8d10cd1c-1a00-0000-e327-3268220d0000 pid=3362 clone guuid=847281ef-1800-0000-e327-3268100b0000 pid=2832 /home/sandbox/morte.x86 guuid=5c1579ef-1800-0000-e327-32680f0b0000 pid=2831->guuid=847281ef-1800-0000-e327-3268100b0000 pid=2832 clone guuid=ca7385ef-1800-0000-e327-3268110b0000 pid=2833 /home/sandbox/morte.x86 dns net send-data zombie guuid=5c1579ef-1800-0000-e327-32680f0b0000 pid=2831->guuid=ca7385ef-1800-0000-e327-3268110b0000 pid=2833 clone guuid=ca7385ef-1800-0000-e327-3268110b0000 pid=2833->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 266B cde57c6f-9471-534c-ab4c-ef00b6d437db motre.jbvpshosti.com:12121 guuid=ca7385ef-1800-0000-e327-3268110b0000 pid=2833->cde57c6f-9471-534c-ab4c-ef00b6d437db send: 39B guuid=8d10cd1c-1a00-0000-e327-3268220d0000 pid=3362->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 975B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=8d10cd1c-1a00-0000-e327-3268220d0000 pid=3362->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 4B 1a0d40e3-a555-5529-8898-ec43b4a3614b motre.jbvpshosti.com:80 guuid=3b3ddf1c-1a00-0000-e327-3268230d0000 pid=3363->1a0d40e3-a555-5529-8898-ec43b4a3614b send: 156B guuid=b44a5f21-1a00-0000-e327-32682d0d0000 pid=3373->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=b44a5f21-1a00-0000-e327-32682d0d0000 pid=3373->f77ebf5e-2af7-5b09-86f4-388588a8b445 con
Threat name:
Win32.Trojan.Alevaul
Status:
Malicious
First seen:
2025-06-30 14:32:22 UTC
File Type:
Text (Shell)
AV detection:
12 of 38 (31.58%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 91e00fc87168c9d1ca27ce8a87625015f480011d8f41d5e8e996ba341ff6cd7c

(this sample)

Comments