MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a87149f1eb2e9481b34b25bab3165e23e01dbf96eddb8571b5d30d20860bd6b1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: a87149f1eb2e9481b34b25bab3165e23e01dbf96eddb8571b5d30d20860bd6b1
SHA3-384 hash: 0cc107ba179dae75d9b205f5a8dc56f7347c684fc4d984ab1fcc43b2a865efe3f6302c3a2850c9bd076a465526a80d18
SHA1 hash: 4a1f2aa86ad7baf26992359fe143b484d25922a5
MD5 hash: df3162b9c6aaeb315ad75e27baa4b4df
humanhash: pluto-salami-black-october
File name:kla.sh
Download: download sample
Signature Mirai
File size:5'029 bytes
First seen:2026-05-06 19:21:28 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:2RKhEcfEnsTE111mC1mkPnJtbTrDVpfXRlP9:2M+
TLSH T14AA15CC9139358707CE29C276169C814F6D9B68AADC54F4190DCF4F9A4CCF09BE42AB3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.32.41.16/bins/px8674717f8eab3eeb56bf59bb12fc976ad4b31fc7a16c1761d2b8c040eb676debb1 Miraielf mirai opendir ua-wget x86
http://89.32.41.16/bins/pmips37733e5966cf4129c79c419725fbc2f7bcdac446683d966107bb3065d959422f Miraielf mips mirai opendir ua-wget
http://89.32.41.16/bins/pmpsl3af414ef65da7494da9604e1a1dcf1a2a92234a4c8fd2fa11bb292970ea4282e Miraielf mips mirai opendir ua-wget
http://89.32.41.16/bins/parm826a786afce30c67495d60799ae38d1604bea4732476253a3aab81e1dd5d44f0 Miraielf mirai ua-wget
http://89.32.41.16/bins/parm5f8a25095fbd2531cd653e77dd00d4ec5b1978dc75b85619c1c877fca97c91adb Miraielf mirai ua-wget
http://89.32.41.16/bins/parm69fa6d2fd9142a363ae55e41e63bd8c979b402ed3536f1a786f5b86490238c5ee Miraiarm elf mirai opendir ua-wget
http://89.32.41.16/bins/parm7603afabe0bd67f9c66c1680b0e8c1c2d2b319053aeaf41a8b2380530ebf3719c Miraielf mirai ua-wget
http://89.32.41.16/bins/pm68kn/an/aelf ua-wget
http://89.32.41.16/bins/psh4dde65e9db0231051abe658d6edda8e5e4fc08e7d67d22abf40ed8476bc8af42f Miraielf mirai opendir SuperH ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-06T16:26:00Z UTC
Last seen:
2026-05-06T19:32:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=55560206-1b00-0000-b2ee-72d1f50a0000 pid=2805 /usr/bin/sudo guuid=ac353308-1b00-0000-b2ee-72d1fc0a0000 pid=2812 /tmp/sample.bin guuid=55560206-1b00-0000-b2ee-72d1f50a0000 pid=2805->guuid=ac353308-1b00-0000-b2ee-72d1fc0a0000 pid=2812 execve guuid=73c81709-1b00-0000-b2ee-72d1fe0a0000 pid=2814 /usr/bin/cp guuid=ac353308-1b00-0000-b2ee-72d1fc0a0000 pid=2812->guuid=73c81709-1b00-0000-b2ee-72d1fe0a0000 pid=2814 execve guuid=2f67b611-1b00-0000-b2ee-72d10f0b0000 pid=2831 /usr/bin/wget net send-data write-file guuid=ac353308-1b00-0000-b2ee-72d1fc0a0000 pid=2812->guuid=2f67b611-1b00-0000-b2ee-72d10f0b0000 pid=2831 execve guuid=1d82c126-1b00-0000-b2ee-72d11d0b0000 pid=2845 /usr/bin/curl net send-data write-file guuid=ac353308-1b00-0000-b2ee-72d1fc0a0000 pid=2812->guuid=1d82c126-1b00-0000-b2ee-72d11d0b0000 pid=2845 execve guuid=aed91d44-1b00-0000-b2ee-72d1570b0000 pid=2903 /usr/bin/chmod guuid=ac353308-1b00-0000-b2ee-72d1fc0a0000 pid=2812->guuid=aed91d44-1b00-0000-b2ee-72d1570b0000 pid=2903 execve guuid=da9e8f44-1b00-0000-b2ee-72d1590b0000 pid=2905 /tmp/robben delete-file net guuid=ac353308-1b00-0000-b2ee-72d1fc0a0000 pid=2812->guuid=da9e8f44-1b00-0000-b2ee-72d1590b0000 pid=2905 execve guuid=0579de45-1b00-0000-b2ee-72d15e0b0000 pid=2910 /usr/bin/wget net send-data write-file guuid=ac353308-1b00-0000-b2ee-72d1fc0a0000 pid=2812->guuid=0579de45-1b00-0000-b2ee-72d15e0b0000 pid=2910 execve guuid=2ab18f53-1b00-0000-b2ee-72d17a0b0000 pid=2938 /usr/bin/curl net send-data write-file guuid=ac353308-1b00-0000-b2ee-72d1fc0a0000 pid=2812->guuid=2ab18f53-1b00-0000-b2ee-72d17a0b0000 pid=2938 execve guuid=51f64a65-1b00-0000-b2ee-72d1920b0000 pid=2962 /usr/bin/chmod guuid=ac353308-1b00-0000-b2ee-72d1fc0a0000 pid=2812->guuid=51f64a65-1b00-0000-b2ee-72d1920b0000 pid=2962 execve guuid=4a8bca65-1b00-0000-b2ee-72d1940b0000 pid=2964 /tmp/robben delete-file net guuid=ac353308-1b00-0000-b2ee-72d1fc0a0000 pid=2812->guuid=4a8bca65-1b00-0000-b2ee-72d1940b0000 pid=2964 execve ed1ae445-8403-522d-9c55-b54488c1ab36 89.32.41.16:80 guuid=2f67b611-1b00-0000-b2ee-72d10f0b0000 pid=2831->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 135B guuid=1d82c126-1b00-0000-b2ee-72d11d0b0000 pid=2845->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 84B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=da9e8f44-1b00-0000-b2ee-72d1590b0000 pid=2905->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d1dacb45-1b00-0000-b2ee-72d15d0b0000 pid=2909 /tmp/robben net send-data zombie guuid=da9e8f44-1b00-0000-b2ee-72d1590b0000 pid=2905->guuid=d1dacb45-1b00-0000-b2ee-72d15d0b0000 pid=2909 clone guuid=d1dacb45-1b00-0000-b2ee-72d15d0b0000 pid=2909->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con db3fcbe4-2900-592c-9283-947c75e52652 89.32.41.16:18129 guuid=d1dacb45-1b00-0000-b2ee-72d15d0b0000 pid=2909->db3fcbe4-2900-592c-9283-947c75e52652 send: 12B guuid=3512e345-1b00-0000-b2ee-72d15f0b0000 pid=2911 /tmp/robben guuid=d1dacb45-1b00-0000-b2ee-72d15d0b0000 pid=2909->guuid=3512e345-1b00-0000-b2ee-72d15f0b0000 pid=2911 clone guuid=f368f845-1b00-0000-b2ee-72d1600b0000 pid=2912 /tmp/robben guuid=d1dacb45-1b00-0000-b2ee-72d15d0b0000 pid=2909->guuid=f368f845-1b00-0000-b2ee-72d1600b0000 pid=2912 clone guuid=6ae90346-1b00-0000-b2ee-72d1610b0000 pid=2913 /tmp/robben guuid=d1dacb45-1b00-0000-b2ee-72d15d0b0000 pid=2909->guuid=6ae90346-1b00-0000-b2ee-72d1610b0000 pid=2913 clone guuid=0579de45-1b00-0000-b2ee-72d15e0b0000 pid=2910->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 135B guuid=2ab18f53-1b00-0000-b2ee-72d17a0b0000 pid=2938->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 84B guuid=4a8bca65-1b00-0000-b2ee-72d1940b0000 pid=2964->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 0637bfa0-18a1-551d-95eb-ed76e272eef1 0.0.0.0:18129 guuid=4a8bca65-1b00-0000-b2ee-72d1940b0000 pid=2964->0637bfa0-18a1-551d-95eb-ed76e272eef1 con
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-05-06 19:22:40 UTC
File Type:
Text (Shell)
AV detection:
7 of 23 (30.43%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Family: Mirai
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh a87149f1eb2e9481b34b25bab3165e23e01dbf96eddb8571b5d30d20860bd6b1

(this sample)

  
Delivery method
Distributed via web download

Comments