MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a74faa3692e7b59e43b4c9d2c620510e544d5b3ac5a2ff5a9321a3d408bd97f3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: a74faa3692e7b59e43b4c9d2c620510e544d5b3ac5a2ff5a9321a3d408bd97f3
SHA3-384 hash: 02233d34303626edfd29ade4bb3458712536088a58e26c062196d5fd405e8775bcea3807639e5e5f4b06698a271398c0
SHA1 hash: 930f7232c46830480b9e938050f70bddfd08ac34
MD5 hash: 869fe1589f48c1f1de2bf4d98bde1e4d
humanhash: colorado-golf-robert-berlin
File name:123.sh
Download: download sample
Signature Mirai
File size:836 bytes
First seen:2025-08-06 05:48:51 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:yjJErl5kJTqBy4qsICWJhd4qsICPv4qoCWJoe4qod/l1esQ9M9wQN/wOy0:jznqt7gqtMwqo7Mqod/l1+MvN/Ly0
TLSH T13801BDF652A009732DC9883E71DB848D55BE30836821D6687F8D743C3B2755AADB06CF
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=14469838-1a00-0000-c4b9-249ca40a0000 pid=2724 /usr/bin/sudo guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730 /tmp/sample.bin guuid=14469838-1a00-0000-c4b9-249ca40a0000 pid=2724->guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730 execve guuid=8b78973c-1a00-0000-c4b9-249cac0a0000 pid=2732 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=8b78973c-1a00-0000-c4b9-249cac0a0000 pid=2732 execve guuid=70321f48-1a00-0000-c4b9-249cbb0a0000 pid=2747 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=70321f48-1a00-0000-c4b9-249cbb0a0000 pid=2747 execve guuid=b5176349-1a00-0000-c4b9-249cbe0a0000 pid=2750 /usr/bin/bash guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=b5176349-1a00-0000-c4b9-249cbe0a0000 pid=2750 clone guuid=bcfa6c49-1a00-0000-c4b9-249cbf0a0000 pid=2751 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=bcfa6c49-1a00-0000-c4b9-249cbf0a0000 pid=2751 execve guuid=7d062550-1a00-0000-c4b9-249cc60a0000 pid=2758 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=7d062550-1a00-0000-c4b9-249cc60a0000 pid=2758 execve guuid=9820ba50-1a00-0000-c4b9-249cc80a0000 pid=2760 /usr/bin/bash guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=9820ba50-1a00-0000-c4b9-249cc80a0000 pid=2760 clone guuid=bc0ee650-1a00-0000-c4b9-249cca0a0000 pid=2762 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=bc0ee650-1a00-0000-c4b9-249cca0a0000 pid=2762 execve guuid=3c75d657-1a00-0000-c4b9-249cd10a0000 pid=2769 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=3c75d657-1a00-0000-c4b9-249cd10a0000 pid=2769 execve guuid=4a86bc58-1a00-0000-c4b9-249cd20a0000 pid=2770 /usr/bin/bash guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=4a86bc58-1a00-0000-c4b9-249cd20a0000 pid=2770 clone guuid=c5e3ee58-1a00-0000-c4b9-249cd40a0000 pid=2772 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=c5e3ee58-1a00-0000-c4b9-249cd40a0000 pid=2772 execve guuid=286efe60-1a00-0000-c4b9-249ce10a0000 pid=2785 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=286efe60-1a00-0000-c4b9-249ce10a0000 pid=2785 execve guuid=a1655a61-1a00-0000-c4b9-249ce30a0000 pid=2787 /usr/bin/bash guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=a1655a61-1a00-0000-c4b9-249ce30a0000 pid=2787 clone guuid=e46f6861-1a00-0000-c4b9-249ce40a0000 pid=2788 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=e46f6861-1a00-0000-c4b9-249ce40a0000 pid=2788 execve guuid=7ff93467-1a00-0000-c4b9-249ce70a0000 pid=2791 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=7ff93467-1a00-0000-c4b9-249ce70a0000 pid=2791 execve guuid=e7d59067-1a00-0000-c4b9-249ce80a0000 pid=2792 /usr/bin/bash guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=e7d59067-1a00-0000-c4b9-249ce80a0000 pid=2792 clone guuid=689ca467-1a00-0000-c4b9-249ce90a0000 pid=2793 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=689ca467-1a00-0000-c4b9-249ce90a0000 pid=2793 execve guuid=87d3806d-1a00-0000-c4b9-249cf20a0000 pid=2802 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=87d3806d-1a00-0000-c4b9-249cf20a0000 pid=2802 execve guuid=6402ef6d-1a00-0000-c4b9-249cf40a0000 pid=2804 /usr/bin/bash guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=6402ef6d-1a00-0000-c4b9-249cf40a0000 pid=2804 clone guuid=6801006e-1a00-0000-c4b9-249cf50a0000 pid=2805 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=6801006e-1a00-0000-c4b9-249cf50a0000 pid=2805 execve guuid=6983f173-1a00-0000-c4b9-249c010b0000 pid=2817 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=6983f173-1a00-0000-c4b9-249c010b0000 pid=2817 execve guuid=28b95d74-1a00-0000-c4b9-249c030b0000 pid=2819 /usr/bin/bash guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=28b95d74-1a00-0000-c4b9-249c030b0000 pid=2819 clone guuid=c41d6b74-1a00-0000-c4b9-249c040b0000 pid=2820 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=c41d6b74-1a00-0000-c4b9-249c040b0000 pid=2820 execve guuid=c3badb7b-1a00-0000-c4b9-249c120b0000 pid=2834 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=c3badb7b-1a00-0000-c4b9-249c120b0000 pid=2834 execve guuid=a190297c-1a00-0000-c4b9-249c140b0000 pid=2836 /usr/bin/bash guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=a190297c-1a00-0000-c4b9-249c140b0000 pid=2836 clone guuid=979a357c-1a00-0000-c4b9-249c150b0000 pid=2837 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=979a357c-1a00-0000-c4b9-249c150b0000 pid=2837 execve guuid=1c70d981-1a00-0000-c4b9-249c1d0b0000 pid=2845 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=1c70d981-1a00-0000-c4b9-249c1d0b0000 pid=2845 execve guuid=12ea7282-1a00-0000-c4b9-249c1e0b0000 pid=2846 /usr/bin/bash guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=12ea7282-1a00-0000-c4b9-249c1e0b0000 pid=2846 clone guuid=629b7f82-1a00-0000-c4b9-249c1f0b0000 pid=2847 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=629b7f82-1a00-0000-c4b9-249c1f0b0000 pid=2847 execve guuid=ca842f87-1a00-0000-c4b9-249c220b0000 pid=2850 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=ca842f87-1a00-0000-c4b9-249c220b0000 pid=2850 execve guuid=97079387-1a00-0000-c4b9-249c230b0000 pid=2851 /usr/bin/bash guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=97079387-1a00-0000-c4b9-249c230b0000 pid=2851 clone guuid=835da287-1a00-0000-c4b9-249c240b0000 pid=2852 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=835da287-1a00-0000-c4b9-249c240b0000 pid=2852 execve guuid=975be68c-1a00-0000-c4b9-249c2f0b0000 pid=2863 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=975be68c-1a00-0000-c4b9-249c2f0b0000 pid=2863 execve guuid=cb2f568d-1a00-0000-c4b9-249c310b0000 pid=2865 /tmp/main_x86 delete-file net guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=cb2f568d-1a00-0000-c4b9-249c310b0000 pid=2865 execve guuid=16415f8d-1a00-0000-c4b9-249c330b0000 pid=2867 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=16415f8d-1a00-0000-c4b9-249c330b0000 pid=2867 execve guuid=e59cd092-1a00-0000-c4b9-249c420b0000 pid=2882 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=e59cd092-1a00-0000-c4b9-249c420b0000 pid=2882 execve guuid=1bf05b93-1a00-0000-c4b9-249c430b0000 pid=2883 /tmp/main_x86_64 guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=1bf05b93-1a00-0000-c4b9-249c430b0000 pid=2883 execve guuid=fd426693-1a00-0000-c4b9-249c440b0000 pid=2884 /usr/bin/wget net send-data write-file guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=fd426693-1a00-0000-c4b9-249c440b0000 pid=2884 execve guuid=28a6e49a-1a00-0000-c4b9-249c510b0000 pid=2897 /usr/bin/chmod guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=28a6e49a-1a00-0000-c4b9-249c510b0000 pid=2897 execve guuid=45d1319b-1a00-0000-c4b9-249c530b0000 pid=2899 /usr/bin/bash zombie guuid=b9cc2d3c-1a00-0000-c4b9-249caa0a0000 pid=2730->guuid=45d1319b-1a00-0000-c4b9-249c530b0000 pid=2899 clone 88b0cd47-b0bd-5918-aeb7-5f87fcd431ec 198.55.98.107:80 guuid=8b78973c-1a00-0000-c4b9-249cac0a0000 pid=2732->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 136B guuid=bcfa6c49-1a00-0000-c4b9-249cbf0a0000 pid=2751->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 137B guuid=bc0ee650-1a00-0000-c4b9-249cca0a0000 pid=2762->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 137B guuid=c5e3ee58-1a00-0000-c4b9-249cd40a0000 pid=2772->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 137B guuid=e46f6861-1a00-0000-c4b9-249ce40a0000 pid=2788->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 137B guuid=689ca467-1a00-0000-c4b9-249ce90a0000 pid=2793->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 137B guuid=6801006e-1a00-0000-c4b9-249cf50a0000 pid=2805->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 139B guuid=c41d6b74-1a00-0000-c4b9-249c040b0000 pid=2820->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 136B guuid=979a357c-1a00-0000-c4b9-249c150b0000 pid=2837->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 136B guuid=629b7f82-1a00-0000-c4b9-249c1f0b0000 pid=2847->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 136B guuid=835da287-1a00-0000-c4b9-249c240b0000 pid=2852->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=cb2f568d-1a00-0000-c4b9-249c310b0000 pid=2865->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=46a8868d-1a00-0000-c4b9-249c340b0000 pid=2868 /tmp/main_x86 net send-data zombie guuid=cb2f568d-1a00-0000-c4b9-249c310b0000 pid=2865->guuid=46a8868d-1a00-0000-c4b9-249c340b0000 pid=2868 clone guuid=16415f8d-1a00-0000-c4b9-249c330b0000 pid=2867->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 139B 987d245e-ab5e-597d-85aa-2452ac7a37b8 198.55.98.107:1995 guuid=46a8868d-1a00-0000-c4b9-249c340b0000 pid=2868->987d245e-ab5e-597d-85aa-2452ac7a37b8 send: 18B guuid=01359c8d-1a00-0000-c4b9-249c350b0000 pid=2869 /tmp/main_x86 guuid=46a8868d-1a00-0000-c4b9-249c340b0000 pid=2868->guuid=01359c8d-1a00-0000-c4b9-249c350b0000 pid=2869 clone guuid=fd426693-1a00-0000-c4b9-249c440b0000 pid=2884->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 140B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-08-06 05:49:39 UTC
File Type:
Text (Shell)
AV detection:
7 of 38 (18.42%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads process memory
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Mirai
Mirai family
Malware Config
C2 Extraction:
198.55.98.107
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh a74faa3692e7b59e43b4c9d2c620510e544d5b3ac5a2ff5a9321a3d408bd97f3

(this sample)

  
Delivery method
Distributed via web download

Comments