MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 96bbe280b9b8bcace06dacb11ecc83f9f94c6e74d301d2e02e00ccf33179fb76. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 96bbe280b9b8bcace06dacb11ecc83f9f94c6e74d301d2e02e00ccf33179fb76
SHA3-384 hash: f75f6c07e2323be3fb1d55ad4e8e6f9a0ec3a16fa20812733ec37a7a60cce4440a93ff65e153784cadc3495e5d87affe
SHA1 hash: 13e5f3c585c81f76241c031a2121a72ec3dc144c
MD5 hash: a192c62b5efe6d5ed51e7754dabb8696
humanhash: hot-east-freddie-steak
File name:c.sh
Download: download sample
Signature Mirai
File size:1'330 bytes
First seen:2026-07-02 04:30:03 UTC
Last seen:2026-07-03 03:22:07 UTC
File type: sh
MIME type:text/plain
ssdeep 24:3J3T5iHlwibV5Plwjy51NIplwi55xlw3KCk5Qlwcj5hlwVU5j8lwcj5llwJQ5plf:F4F7RrPqjFQ+IvRLZafR/d7D0ZypDzx
TLSH T1F8213E8D23ACB1311DCEC916731EC2EA39E295D2A4E40934B274DC34C6BBA8A3113F61
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://141.11.88.128/bins/vcimanagement.arm5a4f83d9146cf4afc6eccab55e67b464d76ec6ec5343df55a5f98e59b57b8503 Miraiarm elf mirai ua-wget
http://141.11.88.128/bins/vcimanagement.arm519fcb0877dd3375c036c5f3093bf1960d75710de97958cff8ad8a14f63ab9369 Miraiarm elf mirai ua-wget
http://141.11.88.128/bins/vcimanagement.arm660cbc151ef10a9e7309638ea2d90c7da8a72af4c590308bca61f08243b64715f Miraiarm elf mirai ua-wget
http://141.11.88.128/bins/vcimanagement.arm7c80a916d945db5fc67e2b566eeb1910c1be2ececd0434cd6dedcf1da9a17f921 Miraiarm elf mirai ua-wget
http://141.11.88.128/bins/vcimanagement.m68k9f04177030da8125b2a23b471e5027c4ad48bded9f7ff64733051a8ad7f2a6e3 Miraielf m68k mirai ua-wget
http://141.11.88.128/bins/vcimanagement.mips01467634dee8365d372e015ba94b8998d9ea0aceb2831092ca55bbbe5796cb39 Miraielf mips mirai ua-wget
http://141.11.88.128/bins/vcimanagement.mpslba1b8d49b09ae2635326a9995e5dbaf10cef2dfed2c53de0ecc271c5a1089581 Miraielf mips mirai ua-wget
http://141.11.88.128/bins/vcimanagement.ppc54166148dad002881957d42c2b793285bf6534a60c1c6becc1da218b1e5d31ac Miraielf mirai PowerPC ua-wget
http://141.11.88.128/bins/vcimanagement.sh41214d108e59c54c3f6f548ccdeab6be49ffbf71b68957834878282686e745e96 Miraielf mirai SuperH ua-wget
http://141.11.88.128/bins/vcimanagement.spcf5344149c1197d65c74f5594fd9e569b34605cd10e7e3cd5bc5ee17f003c2e66 Miraielf mirai sparc ua-wget
http://141.11.88.128/bins/vcimanagement.x86f2fb50c771143507eeb3a5753bab53a8c87c4dbefe35adfa65dfb1a98e1c7639 Miraielf mirai ua-wget x86
http://141.11.88.128/bins/vcimanagement.x86_64n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
70
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader mirai
Verdict:
Malicious
File Type:
text
First seen:
2026-07-02T01:36:00Z UTC
Last seen:
2026-07-04T00:45:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.cl
Status:
terminated
Behavior Graph:
%3 guuid=ffe44b83-1e00-0000-1cbe-c176cf0b0000 pid=3023 /usr/bin/sudo guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031 /tmp/sample.bin guuid=ffe44b83-1e00-0000-1cbe-c176cf0b0000 pid=3023->guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031 execve guuid=90f46085-1e00-0000-1cbe-c176d80b0000 pid=3032 /usr/bin/curl net send-data guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=90f46085-1e00-0000-1cbe-c176d80b0000 pid=3032 execve guuid=c5a5a48b-1e00-0000-1cbe-c176ec0b0000 pid=3052 /usr/bin/chmod guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=c5a5a48b-1e00-0000-1cbe-c176ec0b0000 pid=3052 execve guuid=1cc1ee8b-1e00-0000-1cbe-c176ed0b0000 pid=3053 /usr/bin/dash guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=1cc1ee8b-1e00-0000-1cbe-c176ed0b0000 pid=3053 clone guuid=7c13fd8b-1e00-0000-1cbe-c176ee0b0000 pid=3054 /usr/bin/curl net send-data guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=7c13fd8b-1e00-0000-1cbe-c176ee0b0000 pid=3054 execve guuid=315a5691-1e00-0000-1cbe-c176fe0b0000 pid=3070 /usr/bin/chmod guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=315a5691-1e00-0000-1cbe-c176fe0b0000 pid=3070 execve guuid=013f9791-1e00-0000-1cbe-c176000c0000 pid=3072 /usr/bin/dash guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=013f9791-1e00-0000-1cbe-c176000c0000 pid=3072 clone guuid=0801a491-1e00-0000-1cbe-c176010c0000 pid=3073 /usr/bin/curl net send-data guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=0801a491-1e00-0000-1cbe-c176010c0000 pid=3073 execve guuid=576c2b97-1e00-0000-1cbe-c176110c0000 pid=3089 /usr/bin/chmod guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=576c2b97-1e00-0000-1cbe-c176110c0000 pid=3089 execve guuid=34d78197-1e00-0000-1cbe-c176130c0000 pid=3091 /usr/bin/dash guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=34d78197-1e00-0000-1cbe-c176130c0000 pid=3091 clone guuid=59059297-1e00-0000-1cbe-c176140c0000 pid=3092 /usr/bin/curl net send-data guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=59059297-1e00-0000-1cbe-c176140c0000 pid=3092 execve guuid=a679349e-1e00-0000-1cbe-c176270c0000 pid=3111 /usr/bin/chmod guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=a679349e-1e00-0000-1cbe-c176270c0000 pid=3111 execve guuid=62ae7b9e-1e00-0000-1cbe-c176280c0000 pid=3112 /usr/bin/dash guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=62ae7b9e-1e00-0000-1cbe-c176280c0000 pid=3112 clone guuid=5c92939e-1e00-0000-1cbe-c1762a0c0000 pid=3114 /usr/bin/curl net send-data guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=5c92939e-1e00-0000-1cbe-c1762a0c0000 pid=3114 execve guuid=04327ea6-1e00-0000-1cbe-c1763e0c0000 pid=3134 /usr/bin/chmod guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=04327ea6-1e00-0000-1cbe-c1763e0c0000 pid=3134 execve guuid=e8dae4a6-1e00-0000-1cbe-c1763f0c0000 pid=3135 /usr/bin/dash guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=e8dae4a6-1e00-0000-1cbe-c1763f0c0000 pid=3135 clone guuid=3f50f5a6-1e00-0000-1cbe-c176400c0000 pid=3136 /usr/bin/curl net send-data guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=3f50f5a6-1e00-0000-1cbe-c176400c0000 pid=3136 execve guuid=cc127ead-1e00-0000-1cbe-c176440c0000 pid=3140 /usr/bin/chmod guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=cc127ead-1e00-0000-1cbe-c176440c0000 pid=3140 execve guuid=1403caad-1e00-0000-1cbe-c176460c0000 pid=3142 /usr/bin/dash guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=1403caad-1e00-0000-1cbe-c176460c0000 pid=3142 clone guuid=fb7bd5ad-1e00-0000-1cbe-c176470c0000 pid=3143 /usr/bin/curl net send-data guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=fb7bd5ad-1e00-0000-1cbe-c176470c0000 pid=3143 execve guuid=ac97a7b3-1e00-0000-1cbe-c176540c0000 pid=3156 /usr/bin/chmod guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=ac97a7b3-1e00-0000-1cbe-c176540c0000 pid=3156 execve guuid=60581fb4-1e00-0000-1cbe-c176570c0000 pid=3159 /usr/bin/dash guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=60581fb4-1e00-0000-1cbe-c176570c0000 pid=3159 clone guuid=96332cb4-1e00-0000-1cbe-c176580c0000 pid=3160 /usr/bin/curl net send-data guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=96332cb4-1e00-0000-1cbe-c176580c0000 pid=3160 execve guuid=96ba7cb9-1e00-0000-1cbe-c176630c0000 pid=3171 /usr/bin/chmod guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=96ba7cb9-1e00-0000-1cbe-c176630c0000 pid=3171 execve guuid=79e2bdb9-1e00-0000-1cbe-c176650c0000 pid=3173 /usr/bin/dash guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=79e2bdb9-1e00-0000-1cbe-c176650c0000 pid=3173 clone guuid=a32fc5b9-1e00-0000-1cbe-c176660c0000 pid=3174 /usr/bin/curl net send-data guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=a32fc5b9-1e00-0000-1cbe-c176660c0000 pid=3174 execve guuid=c5666cbf-1e00-0000-1cbe-c1766e0c0000 pid=3182 /usr/bin/chmod guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=c5666cbf-1e00-0000-1cbe-c1766e0c0000 pid=3182 execve guuid=5381d4bf-1e00-0000-1cbe-c1766f0c0000 pid=3183 /usr/bin/dash guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=5381d4bf-1e00-0000-1cbe-c1766f0c0000 pid=3183 clone guuid=8c38f6bf-1e00-0000-1cbe-c176700c0000 pid=3184 /usr/bin/curl net send-data guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=8c38f6bf-1e00-0000-1cbe-c176700c0000 pid=3184 execve guuid=99397ecd-1e00-0000-1cbe-c176710c0000 pid=3185 /usr/bin/chmod guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=99397ecd-1e00-0000-1cbe-c176710c0000 pid=3185 execve guuid=faeadfcd-1e00-0000-1cbe-c176720c0000 pid=3186 /usr/bin/dash guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=faeadfcd-1e00-0000-1cbe-c176720c0000 pid=3186 clone guuid=f735efcd-1e00-0000-1cbe-c176730c0000 pid=3187 /usr/bin/curl net send-data guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=f735efcd-1e00-0000-1cbe-c176730c0000 pid=3187 execve guuid=8f648ad4-1e00-0000-1cbe-c176750c0000 pid=3189 /usr/bin/chmod guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=8f648ad4-1e00-0000-1cbe-c176750c0000 pid=3189 execve guuid=1d4813d5-1e00-0000-1cbe-c176760c0000 pid=3190 /usr/bin/dash guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=1d4813d5-1e00-0000-1cbe-c176760c0000 pid=3190 clone guuid=09ef26d5-1e00-0000-1cbe-c176770c0000 pid=3191 /usr/bin/curl net send-data guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=09ef26d5-1e00-0000-1cbe-c176770c0000 pid=3191 execve guuid=5225c8dd-1e00-0000-1cbe-c176860c0000 pid=3206 /usr/bin/chmod guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=5225c8dd-1e00-0000-1cbe-c176860c0000 pid=3206 execve guuid=3ce147de-1e00-0000-1cbe-c176870c0000 pid=3207 /usr/bin/dash guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=3ce147de-1e00-0000-1cbe-c176870c0000 pid=3207 clone guuid=d14c56de-1e00-0000-1cbe-c176880c0000 pid=3208 /usr/bin/rm delete-file guuid=90622685-1e00-0000-1cbe-c176d70b0000 pid=3031->guuid=d14c56de-1e00-0000-1cbe-c176880c0000 pid=3208 execve 4df54c33-6c61-5e89-864b-33049e03647e 141.11.88.128:80 guuid=90f46085-1e00-0000-1cbe-c176d80b0000 pid=3032->4df54c33-6c61-5e89-864b-33049e03647e send: 99B guuid=7c13fd8b-1e00-0000-1cbe-c176ee0b0000 pid=3054->4df54c33-6c61-5e89-864b-33049e03647e send: 100B guuid=0801a491-1e00-0000-1cbe-c176010c0000 pid=3073->4df54c33-6c61-5e89-864b-33049e03647e send: 100B guuid=59059297-1e00-0000-1cbe-c176140c0000 pid=3092->4df54c33-6c61-5e89-864b-33049e03647e send: 100B guuid=5c92939e-1e00-0000-1cbe-c1762a0c0000 pid=3114->4df54c33-6c61-5e89-864b-33049e03647e send: 100B guuid=3f50f5a6-1e00-0000-1cbe-c176400c0000 pid=3136->4df54c33-6c61-5e89-864b-33049e03647e send: 100B guuid=fb7bd5ad-1e00-0000-1cbe-c176470c0000 pid=3143->4df54c33-6c61-5e89-864b-33049e03647e send: 100B guuid=96332cb4-1e00-0000-1cbe-c176580c0000 pid=3160->4df54c33-6c61-5e89-864b-33049e03647e send: 99B guuid=a32fc5b9-1e00-0000-1cbe-c176660c0000 pid=3174->4df54c33-6c61-5e89-864b-33049e03647e send: 99B guuid=8c38f6bf-1e00-0000-1cbe-c176700c0000 pid=3184->4df54c33-6c61-5e89-864b-33049e03647e send: 99B guuid=f735efcd-1e00-0000-1cbe-c176730c0000 pid=3187->4df54c33-6c61-5e89-864b-33049e03647e send: 99B guuid=09ef26d5-1e00-0000-1cbe-c176770c0000 pid=3191->4df54c33-6c61-5e89-864b-33049e03647e send: 102B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-07-02 04:32:30 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 96bbe280b9b8bcace06dacb11ecc83f9f94c6e74d301d2e02e00ccf33179fb76

(this sample)

  
Delivery method
Distributed via web download

Comments