MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9bbcf28e456e57d463a3ad5673fb693e25cf4c4f6207272bca6951762d77f127. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 9bbcf28e456e57d463a3ad5673fb693e25cf4c4f6207272bca6951762d77f127
SHA3-384 hash: 03283aaa206ebd0df98de4cd1d147092c6fb0a52c87facebc9e50dd630c542af2a6169b3e287133e299233a0c47cf8de
SHA1 hash: d3075ebb82742060dd08723c3e4b94a36f091f2e
MD5 hash: 7479ee4211eff7b9958d236bac9759da
humanhash: whiskey-two-magnesium-arizona
File name:c.sh
Download: download sample
Signature Mirai
File size:828 bytes
First seen:2026-01-07 18:31:07 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3+qjQUQTNI1FAQgiKTQTiFqQNtonQVnQYhQvxGJv0jQIAQjXAUA:3J3PSNITK/tF4HA
TLSH T100016B9E01B8E3525B1CDE04B05ED61CBD4199C1B2F0CAC0F855AA79A8DED152258FAA
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://14.225.20.10/csk_arm3b6510ea58fedbd8be2f9edea9bdf23f2924091ee94a8b72fbabd17fd47ff86e Miraielf mirai ua-wget
http://14.225.20.10/csk_arm57e27d70ef08cc6a380ac6e92d312d7d14a0063b8f0043333771923165dd9add5 Miraielf mirai ua-wget
http://14.225.20.10/csk_arm6dba31f9c022880707c1687a193cb1ebf6470ec3daaa642d9566d60874f77dc16 Miraielf mirai ua-wget
http://14.225.20.10/csk_arm78a807fe858d9a6b452905606c974b345b2fad130fd352bf064ff68d04a958103 Miraielf mirai ua-wget
http://14.225.20.10/csk_m68k7679266043c5ba20bddb70235b099d41f550bdb8586dffe0a30cd55461add399 Miraielf mirai ua-wget
http://14.225.20.10/csk_mips7343d71bb7d0045d816b73fabc1429b8a2a6006e10f68ef0bd250ad9dff904f0 Miraielf mirai ua-wget
http://14.225.20.10/csk_mpsl005f565b1a2472c5c6d34e9ce8ae2058e15b91265e2e55ace274f1386c8bc3b1 Miraielf mirai ua-wget
http://14.225.20.10/csk_ppc3ee5f789d89a5c220552cf24d5c232d4ee7ba29c5707bf449837bcdc41ddc49c Miraielf mirai ua-wget
http://14.225.20.10/csk_spc048cf68470501740ac2efc1b2c6b193760f99494570b90ba4f1d74b534aec5f6 Miraielf mirai ua-wget
http://14.225.20.10/csk_x86088b1ec37bd2bd85f5ed2371e19cb852049eb8cae03e27cd6b1f270548a8e0ae Miraielf mirai ua-wget
http://14.225.20.10/csk_x86_64fa49458eeb48ee164b9963f4aebcabc26862899c4dcf26a8979321587221623b Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
ps1
First seen:
2026-01-07T15:41:00Z UTC
Last seen:
2026-01-09T11:10:00Z UTC
Hits:
~10
Detections:
HEUR:Backdoor.Linux.Mirai.cw HEUR:Backdoor.Linux.Mirai.b HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Backdoor.Linux.Mirai.hv HEUR:Backdoor.Linux.Mirai.h
Status:
terminated
Behavior Graph:
%3 guuid=242d5e89-1700-0000-af5c-e06db20b0000 pid=2994 /usr/bin/sudo guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997 /tmp/sample.bin guuid=242d5e89-1700-0000-af5c-e06db20b0000 pid=2994->guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997 execve guuid=ee1aad8b-1700-0000-af5c-e06db70b0000 pid=2999 /usr/bin/curl net send-data guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=ee1aad8b-1700-0000-af5c-e06db70b0000 pid=2999 execve guuid=1c6d58cd-1700-0000-af5c-e06d3a0c0000 pid=3130 /usr/bin/chmod guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=1c6d58cd-1700-0000-af5c-e06d3a0c0000 pid=3130 execve guuid=3c9fc3cd-1700-0000-af5c-e06d3b0c0000 pid=3131 /usr/bin/dash guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=3c9fc3cd-1700-0000-af5c-e06d3b0c0000 pid=3131 clone guuid=cc0dd9cd-1700-0000-af5c-e06d3d0c0000 pid=3133 /usr/bin/curl net send-data guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=cc0dd9cd-1700-0000-af5c-e06d3d0c0000 pid=3133 execve guuid=b2616605-1800-0000-af5c-e06d8f0c0000 pid=3215 /usr/bin/chmod guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=b2616605-1800-0000-af5c-e06d8f0c0000 pid=3215 execve guuid=bd67b605-1800-0000-af5c-e06d900c0000 pid=3216 /usr/bin/dash guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=bd67b605-1800-0000-af5c-e06d900c0000 pid=3216 clone guuid=04ddc705-1800-0000-af5c-e06d910c0000 pid=3217 /usr/bin/curl net send-data guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=04ddc705-1800-0000-af5c-e06d910c0000 pid=3217 execve guuid=ba4c3346-1800-0000-af5c-e06dd00c0000 pid=3280 /usr/bin/chmod guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=ba4c3346-1800-0000-af5c-e06dd00c0000 pid=3280 execve guuid=f3ee8346-1800-0000-af5c-e06dd10c0000 pid=3281 /usr/bin/dash guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=f3ee8346-1800-0000-af5c-e06dd10c0000 pid=3281 clone guuid=e66c9146-1800-0000-af5c-e06dd20c0000 pid=3282 /usr/bin/curl net send-data guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=e66c9146-1800-0000-af5c-e06dd20c0000 pid=3282 execve guuid=1d20ef96-1800-0000-af5c-e06d4a0d0000 pid=3402 /usr/bin/chmod guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=1d20ef96-1800-0000-af5c-e06d4a0d0000 pid=3402 execve guuid=64c66597-1800-0000-af5c-e06d4c0d0000 pid=3404 /usr/bin/dash guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=64c66597-1800-0000-af5c-e06d4c0d0000 pid=3404 clone guuid=42478197-1800-0000-af5c-e06d4d0d0000 pid=3405 /usr/bin/curl net send-data guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=42478197-1800-0000-af5c-e06d4d0d0000 pid=3405 execve guuid=005984d9-1800-0000-af5c-e06dc00d0000 pid=3520 /usr/bin/chmod guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=005984d9-1800-0000-af5c-e06dc00d0000 pid=3520 execve guuid=945affd9-1800-0000-af5c-e06dc10d0000 pid=3521 /usr/bin/dash guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=945affd9-1800-0000-af5c-e06dc10d0000 pid=3521 clone guuid=02f116da-1800-0000-af5c-e06dc20d0000 pid=3522 /usr/bin/curl net send-data guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=02f116da-1800-0000-af5c-e06dc20d0000 pid=3522 execve guuid=a5b0801b-1900-0000-af5c-e06d5a0e0000 pid=3674 /usr/bin/chmod guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=a5b0801b-1900-0000-af5c-e06d5a0e0000 pid=3674 execve guuid=3bddfa1b-1900-0000-af5c-e06d5b0e0000 pid=3675 /usr/bin/dash guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=3bddfa1b-1900-0000-af5c-e06d5b0e0000 pid=3675 clone guuid=b51d1a1c-1900-0000-af5c-e06d5c0e0000 pid=3676 /usr/bin/curl net send-data guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=b51d1a1c-1900-0000-af5c-e06d5c0e0000 pid=3676 execve guuid=e19a865f-1900-0000-af5c-e06d430f0000 pid=3907 /usr/bin/chmod guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=e19a865f-1900-0000-af5c-e06d430f0000 pid=3907 execve guuid=0344de5f-1900-0000-af5c-e06d470f0000 pid=3911 /usr/bin/dash guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=0344de5f-1900-0000-af5c-e06d470f0000 pid=3911 clone guuid=6218ea5f-1900-0000-af5c-e06d480f0000 pid=3912 /usr/bin/curl net send-data guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=6218ea5f-1900-0000-af5c-e06d480f0000 pid=3912 execve guuid=51c379a3-1900-0000-af5c-e06d4e100000 pid=4174 /usr/bin/chmod guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=51c379a3-1900-0000-af5c-e06d4e100000 pid=4174 execve guuid=ecead6a3-1900-0000-af5c-e06d4f100000 pid=4175 /usr/bin/dash guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=ecead6a3-1900-0000-af5c-e06d4f100000 pid=4175 clone guuid=7969f3a3-1900-0000-af5c-e06d50100000 pid=4176 /usr/bin/curl net send-data guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=7969f3a3-1900-0000-af5c-e06d50100000 pid=4176 execve guuid=7b628de4-1900-0000-af5c-e06d5e110000 pid=4446 /usr/bin/chmod guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=7b628de4-1900-0000-af5c-e06d5e110000 pid=4446 execve guuid=1b1af8e4-1900-0000-af5c-e06d61110000 pid=4449 /usr/bin/dash guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=1b1af8e4-1900-0000-af5c-e06d61110000 pid=4449 clone guuid=c1e60ae5-1900-0000-af5c-e06d62110000 pid=4450 /usr/bin/curl net send-data guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=c1e60ae5-1900-0000-af5c-e06d62110000 pid=4450 execve guuid=60ee1a27-1a00-0000-af5c-e06d3b120000 pid=4667 /usr/bin/chmod guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=60ee1a27-1a00-0000-af5c-e06d3b120000 pid=4667 execve guuid=adc2e427-1a00-0000-af5c-e06d3c120000 pid=4668 /usr/bin/dash guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=adc2e427-1a00-0000-af5c-e06d3c120000 pid=4668 clone guuid=94d8f827-1a00-0000-af5c-e06d3d120000 pid=4669 /usr/bin/curl net send-data guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=94d8f827-1a00-0000-af5c-e06d3d120000 pid=4669 execve guuid=facf316b-1a00-0000-af5c-e06d11130000 pid=4881 /usr/bin/chmod guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=facf316b-1a00-0000-af5c-e06d11130000 pid=4881 execve guuid=fa27916b-1a00-0000-af5c-e06d14130000 pid=4884 /usr/bin/dash guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=fa27916b-1a00-0000-af5c-e06d14130000 pid=4884 clone guuid=d16ba76b-1a00-0000-af5c-e06d15130000 pid=4885 /usr/bin/rm guuid=cf74668b-1700-0000-af5c-e06db50b0000 pid=2997->guuid=d16ba76b-1a00-0000-af5c-e06d15130000 pid=4885 execve 1620c7c4-e93d-516f-a8e7-a70e9d4dc287 14.225.20.10:80 guuid=ee1aad8b-1700-0000-af5c-e06db70b0000 pid=2999->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 83B guuid=cc0dd9cd-1700-0000-af5c-e06d3d0c0000 pid=3133->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 84B guuid=04ddc705-1800-0000-af5c-e06d910c0000 pid=3217->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 84B guuid=e66c9146-1800-0000-af5c-e06dd20c0000 pid=3282->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 84B guuid=42478197-1800-0000-af5c-e06d4d0d0000 pid=3405->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 84B guuid=02f116da-1800-0000-af5c-e06dc20d0000 pid=3522->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 84B guuid=b51d1a1c-1900-0000-af5c-e06d5c0e0000 pid=3676->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 84B guuid=6218ea5f-1900-0000-af5c-e06d480f0000 pid=3912->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 83B guuid=7969f3a3-1900-0000-af5c-e06d50100000 pid=4176->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 83B guuid=c1e60ae5-1900-0000-af5c-e06d62110000 pid=4450->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 83B guuid=94d8f827-1a00-0000-af5c-e06d3d120000 pid=4669->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 86B
Threat name:
Document-HTML.Trojan.Heuristic
Status:
Malicious
First seen:
2026-01-07 19:10:52 UTC
AV detection:
11 of 23 (47.83%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 9bbcf28e456e57d463a3ad5673fb693e25cf4c4f6207272bca6951762d77f127

(this sample)

  
Delivery method
Distributed via web download

Comments