MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9d1ab055be08d3344bb03be42fba162d3704e6d689651926b6f578531fecb154. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 9d1ab055be08d3344bb03be42fba162d3704e6d689651926b6f578531fecb154
SHA3-384 hash: 201262fb4ce833f4da63168c5e6a392a5e4902eed7f7bc55081db7d89511b826f80c634f76a71a84157641ec8945b5ac
SHA1 hash: 81d84a3b25d49a8fe3245831b0baf3f194fe02f7
MD5 hash: a06a4d62b8dc13631f556986ad0a97a8
humanhash: diet-mike-spaghetti-low
File name:wget2.sh
Download: download sample
Signature Mirai
File size:765 bytes
First seen:2025-10-24 22:58:33 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:ARax2eR4+RhNIjlT3RqiKl2RIKp6SRT9214KFG103rLKb8PnpslaUv:iaxh4shNIpNHKl7q6gy+GpslaUv
TLSH T1EB017DFF1026162D07158E45A0F948046127DBD39278DF5AA884E9335EE65653037F87
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.62/parm7c01428857d884a78abe394e614c0d7abd7461cd108e98b4ddd63854c757fb17 Miraielf mirai
http://213.209.143.62/parm5e4018a1ddcdeb20037a38cf58e9ec6f258361cceb4103a84a776a5a8d99d15be Miraielf mirai
http://213.209.143.62/parm63bfeda53dd0c1edc62f6fbaa4d0fcb7611e9fd9fa96e8dcece7952f9c38ea853 Miraielf mirai
http://213.209.143.62/parm7bf0b7a3bab54d71d6ec17e19e603671f36325ba0701499edda0163a35fad3fa7 Miraielf mirai
http://213.209.143.62/psh4ca4dde73976d4362ee9aea2b31da9d8abde5d8e5131bb0696ba609cc78dd4065 Miraielf mirai
http://213.209.143.62/pppc3674367e3f816a5ab8522f3248b610042007d6f46a83fe93cead77ef34abcc46 Miraielf mirai
http://213.209.143.62/pmips598b78f568444238799098a8c4e8eb9f572cb48920fa0732abfc60920064d59e Miraielf mirai
http://213.209.143.62/pmpsle880433ef7af8450edfd99bc8993d1757db0d8b8ba9a55c63d37e1779141e302 Miraielf mirai
http://213.209.143.62/pspc30bb3dc856c0b73e0e467eb55c98dd736f545e2d6aa2f73e81985f1a7768b541 Miraielf mirai
http://213.209.143.62/px8630bb3dc856c0b73e0e467eb55c98dd736f545e2d6aa2f73e81985f1a7768b541 Miraielf mirai
http://213.209.143.62/px86_6430bb3dc856c0b73e0e467eb55c98dd736f545e2d6aa2f73e81985f1a7768b541 Miraielf mirai
http://213.209.143.62/pi58630bb3dc856c0b73e0e467eb55c98dd736f545e2d6aa2f73e81985f1a7768b541 Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
ps1
First seen:
2025-10-24T20:52:00Z UTC
Last seen:
2025-10-24T21:47:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=69f5a577-1900-0000-b7f5-bac90c0a0000 pid=2572 /usr/bin/sudo guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580 /tmp/sample.bin guuid=69f5a577-1900-0000-b7f5-bac90c0a0000 pid=2572->guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580 execve guuid=3fc8157a-1900-0000-b7f5-bac9160a0000 pid=2582 /usr/bin/wget net send-data write-file guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=3fc8157a-1900-0000-b7f5-bac9160a0000 pid=2582 execve guuid=5c4ec57e-1900-0000-b7f5-bac9240a0000 pid=2596 /usr/bin/chmod guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=5c4ec57e-1900-0000-b7f5-bac9240a0000 pid=2596 execve guuid=2295047f-1900-0000-b7f5-bac9260a0000 pid=2598 /usr/bin/dash guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=2295047f-1900-0000-b7f5-bac9260a0000 pid=2598 clone guuid=e891ee7f-1900-0000-b7f5-bac92a0a0000 pid=2602 /usr/bin/wget net send-data write-file guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=e891ee7f-1900-0000-b7f5-bac92a0a0000 pid=2602 execve guuid=51eb6583-1900-0000-b7f5-bac9340a0000 pid=2612 /usr/bin/chmod guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=51eb6583-1900-0000-b7f5-bac9340a0000 pid=2612 execve guuid=c920ae83-1900-0000-b7f5-bac9360a0000 pid=2614 /usr/bin/dash guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=c920ae83-1900-0000-b7f5-bac9360a0000 pid=2614 clone guuid=87e65384-1900-0000-b7f5-bac9390a0000 pid=2617 /usr/bin/wget net send-data write-file guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=87e65384-1900-0000-b7f5-bac9390a0000 pid=2617 execve guuid=d63c5f89-1900-0000-b7f5-bac9480a0000 pid=2632 /usr/bin/chmod guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=d63c5f89-1900-0000-b7f5-bac9480a0000 pid=2632 execve guuid=3473a789-1900-0000-b7f5-bac94a0a0000 pid=2634 /usr/bin/dash guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=3473a789-1900-0000-b7f5-bac94a0a0000 pid=2634 clone guuid=770c598a-1900-0000-b7f5-bac94e0a0000 pid=2638 /usr/bin/wget net send-data write-file guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=770c598a-1900-0000-b7f5-bac94e0a0000 pid=2638 execve guuid=78ea808e-1900-0000-b7f5-bac95b0a0000 pid=2651 /usr/bin/chmod guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=78ea808e-1900-0000-b7f5-bac95b0a0000 pid=2651 execve guuid=6af9c18e-1900-0000-b7f5-bac95c0a0000 pid=2652 /usr/bin/dash guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=6af9c18e-1900-0000-b7f5-bac95c0a0000 pid=2652 clone guuid=53724e90-1900-0000-b7f5-bac9630a0000 pid=2659 /usr/bin/wget net send-data write-file guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=53724e90-1900-0000-b7f5-bac9630a0000 pid=2659 execve guuid=fb4c9e94-1900-0000-b7f5-bac9710a0000 pid=2673 /usr/bin/chmod guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=fb4c9e94-1900-0000-b7f5-bac9710a0000 pid=2673 execve guuid=93e6df94-1900-0000-b7f5-bac9730a0000 pid=2675 /usr/bin/dash guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=93e6df94-1900-0000-b7f5-bac9730a0000 pid=2675 clone guuid=503b7595-1900-0000-b7f5-bac9770a0000 pid=2679 /usr/bin/wget net send-data write-file guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=503b7595-1900-0000-b7f5-bac9770a0000 pid=2679 execve guuid=94963f99-1900-0000-b7f5-bac9810a0000 pid=2689 /usr/bin/chmod guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=94963f99-1900-0000-b7f5-bac9810a0000 pid=2689 execve guuid=7ed88299-1900-0000-b7f5-bac9830a0000 pid=2691 /usr/bin/dash guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=7ed88299-1900-0000-b7f5-bac9830a0000 pid=2691 clone guuid=38d09699-1900-0000-b7f5-bac9840a0000 pid=2692 /usr/bin/wget net send-data write-file guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=38d09699-1900-0000-b7f5-bac9840a0000 pid=2692 execve guuid=3321579d-1900-0000-b7f5-bac98f0a0000 pid=2703 /usr/bin/chmod guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=3321579d-1900-0000-b7f5-bac98f0a0000 pid=2703 execve guuid=1c039c9d-1900-0000-b7f5-bac9910a0000 pid=2705 /usr/bin/dash guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=1c039c9d-1900-0000-b7f5-bac9910a0000 pid=2705 clone guuid=22f91a9f-1900-0000-b7f5-bac9960a0000 pid=2710 /usr/bin/wget net send-data write-file guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=22f91a9f-1900-0000-b7f5-bac9960a0000 pid=2710 execve guuid=a4c9fda2-1900-0000-b7f5-bac9a10a0000 pid=2721 /usr/bin/chmod guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=a4c9fda2-1900-0000-b7f5-bac9a10a0000 pid=2721 execve guuid=478552a3-1900-0000-b7f5-bac9a20a0000 pid=2722 /usr/bin/dash guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=478552a3-1900-0000-b7f5-bac9a20a0000 pid=2722 clone guuid=e69812a4-1900-0000-b7f5-bac9a60a0000 pid=2726 /usr/bin/wget net send-data write-file guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=e69812a4-1900-0000-b7f5-bac9a60a0000 pid=2726 execve guuid=49476aaa-1900-0000-b7f5-bac9b50a0000 pid=2741 /usr/bin/chmod guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=49476aaa-1900-0000-b7f5-bac9b50a0000 pid=2741 execve guuid=38580bab-1900-0000-b7f5-bac9b80a0000 pid=2744 /usr/bin/dash guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=38580bab-1900-0000-b7f5-bac9b80a0000 pid=2744 clone guuid=0411f1ac-1900-0000-b7f5-bac9be0a0000 pid=2750 /usr/bin/wget net send-data write-file guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=0411f1ac-1900-0000-b7f5-bac9be0a0000 pid=2750 execve guuid=e15a50b0-1900-0000-b7f5-bac9c90a0000 pid=2761 /usr/bin/chmod guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=e15a50b0-1900-0000-b7f5-bac9c90a0000 pid=2761 execve guuid=97fa9ab0-1900-0000-b7f5-bac9ca0a0000 pid=2762 /home/sandbox/px86 delete-file net guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=97fa9ab0-1900-0000-b7f5-bac9ca0a0000 pid=2762 execve guuid=7978e1b0-1900-0000-b7f5-bac9cc0a0000 pid=2764 /usr/bin/wget net send-data write-file guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=7978e1b0-1900-0000-b7f5-bac9cc0a0000 pid=2764 execve guuid=48567ab5-1900-0000-b7f5-bac9d80a0000 pid=2776 /usr/bin/chmod guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=48567ab5-1900-0000-b7f5-bac9d80a0000 pid=2776 execve guuid=0f04b3b5-1900-0000-b7f5-bac9da0a0000 pid=2778 /home/sandbox/px86_64 delete-file net guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=0f04b3b5-1900-0000-b7f5-bac9da0a0000 pid=2778 execve guuid=4ae234e0-1a00-0000-b7f5-bac9b80c0000 pid=3256 /usr/bin/wget net send-data guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=4ae234e0-1a00-0000-b7f5-bac9b80c0000 pid=3256 execve guuid=3409e4e5-1a00-0000-b7f5-bac9bb0c0000 pid=3259 /usr/bin/chmod guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=3409e4e5-1a00-0000-b7f5-bac9bb0c0000 pid=3259 execve guuid=1ce1e3e6-1a00-0000-b7f5-bac9bc0c0000 pid=3260 /usr/bin/dash guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=1ce1e3e6-1a00-0000-b7f5-bac9bc0c0000 pid=3260 clone guuid=107508e7-1a00-0000-b7f5-bac9bd0c0000 pid=3261 /usr/bin/rm delete-file guuid=86ebdc79-1900-0000-b7f5-bac9140a0000 pid=2580->guuid=107508e7-1a00-0000-b7f5-bac9bd0c0000 pid=3261 execve eaaaaddb-f5f1-5090-9f4d-096f63c93adc 213.209.143.62:80 guuid=3fc8157a-1900-0000-b7f5-bac9160a0000 pid=2582->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 133B guuid=e891ee7f-1900-0000-b7f5-bac92a0a0000 pid=2602->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 134B guuid=87e65384-1900-0000-b7f5-bac9390a0000 pid=2617->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 134B guuid=770c598a-1900-0000-b7f5-bac94e0a0000 pid=2638->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 134B guuid=53724e90-1900-0000-b7f5-bac9630a0000 pid=2659->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 133B guuid=503b7595-1900-0000-b7f5-bac9770a0000 pid=2679->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 133B guuid=38d09699-1900-0000-b7f5-bac9840a0000 pid=2692->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 134B guuid=22f91a9f-1900-0000-b7f5-bac9960a0000 pid=2710->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 134B guuid=e69812a4-1900-0000-b7f5-bac9a60a0000 pid=2726->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 133B guuid=0411f1ac-1900-0000-b7f5-bac9be0a0000 pid=2750->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 133B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=97fa9ab0-1900-0000-b7f5-bac9ca0a0000 pid=2762->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fc9ddbb0-1900-0000-b7f5-bac9cb0a0000 pid=2763 /home/sandbox/px86 net send-data zombie guuid=97fa9ab0-1900-0000-b7f5-bac9ca0a0000 pid=2762->guuid=fc9ddbb0-1900-0000-b7f5-bac9cb0a0000 pid=2763 clone guuid=fc9ddbb0-1900-0000-b7f5-bac9cb0a0000 pid=2763->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 945d0657-1e29-5b8e-a636-09ef913aa214 213.209.143.62:18129 guuid=fc9ddbb0-1900-0000-b7f5-bac9cb0a0000 pid=2763->945d0657-1e29-5b8e-a636-09ef913aa214 send: 9B guuid=7366eab0-1900-0000-b7f5-bac9cd0a0000 pid=2765 /home/sandbox/px86 guuid=fc9ddbb0-1900-0000-b7f5-bac9cb0a0000 pid=2763->guuid=7366eab0-1900-0000-b7f5-bac9cd0a0000 pid=2765 clone guuid=25b0f0b0-1900-0000-b7f5-bac9ce0a0000 pid=2766 /home/sandbox/px86 guuid=fc9ddbb0-1900-0000-b7f5-bac9cb0a0000 pid=2763->guuid=25b0f0b0-1900-0000-b7f5-bac9ce0a0000 pid=2766 clone guuid=7978e1b0-1900-0000-b7f5-bac9cc0a0000 pid=2764->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 136B guuid=0f04b3b5-1900-0000-b7f5-bac9da0a0000 pid=2778->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 0637bfa0-18a1-551d-95eb-ed76e272eef1 0.0.0.0:18129 guuid=0f04b3b5-1900-0000-b7f5-bac9da0a0000 pid=2778->0637bfa0-18a1-551d-95eb-ed76e272eef1 con guuid=76de2ce0-1a00-0000-b7f5-bac9b70c0000 pid=3255 /home/sandbox/px86_64 net send-data zombie guuid=0f04b3b5-1900-0000-b7f5-bac9da0a0000 pid=2778->guuid=76de2ce0-1a00-0000-b7f5-bac9b70c0000 pid=3255 clone guuid=76de2ce0-1a00-0000-b7f5-bac9b70c0000 pid=3255->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=76de2ce0-1a00-0000-b7f5-bac9b70c0000 pid=3255->945d0657-1e29-5b8e-a636-09ef913aa214 send: 11B guuid=244e40e0-1a00-0000-b7f5-bac9b90c0000 pid=3257 /home/sandbox/px86_64 guuid=76de2ce0-1a00-0000-b7f5-bac9b70c0000 pid=3255->guuid=244e40e0-1a00-0000-b7f5-bac9b90c0000 pid=3257 clone guuid=0fab43e0-1a00-0000-b7f5-bac9ba0c0000 pid=3258 /home/sandbox/px86_64 guuid=76de2ce0-1a00-0000-b7f5-bac9b70c0000 pid=3255->guuid=0fab43e0-1a00-0000-b7f5-bac9ba0c0000 pid=3258 clone guuid=4ae234e0-1a00-0000-b7f5-bac9b80c0000 pid=3256->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 134B
Threat name:
Document-HTML.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-10-24 23:00:50 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 9d1ab055be08d3344bb03be42fba162d3704e6d689651926b6f578531fecb154

(this sample)

  
Delivery method
Distributed via web download

Comments