MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa2525e7323f152f0be40c7d4dc0c8fc11f8800ada449a72e11c66a1b3a2bec1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: aa2525e7323f152f0be40c7d4dc0c8fc11f8800ada449a72e11c66a1b3a2bec1
SHA3-384 hash: c77787259297619c09c2561e99f1f9105aff66aac6f44752b8f1760f2bbf89081f5bf201ed3703c08286db763017784a
SHA1 hash: 1a5149be7cd5e6e7192842be7792ba2694078023
MD5 hash: 82f12ba8d9596b11e8cc6511d82322cf
humanhash: lion-coffee-beryllium-glucose
File name:c.sh
Download: download sample
Signature Mirai
File size:874 bytes
First seen:2026-04-07 11:40:01 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:3J3FEbE9UEfNIxE1EIKWOnGk8FHDIlnz7M77HR:PEbE9dcE1EIdOGkkclnzYnx
TLSH T16111A0CE12957FB2570C8F6CF23A805C6E82A5E2F5730582B01F44B45DD8348B654FEA
Magika txt
Reporter BlinkzSec
URLMalware sample (SHA256 hash)SignatureTags
http://94.156.152.233/bins/narmd72769153376557c9fef0be797771a3dbf2b748e229459ea42eb42f24a4ba1fc Miraielf mirai ua-wget
http://94.156.152.233/bins/narm520f0d750693f4bd1ec3e0479f4a6d7b5fbb087ccc852881fb356d6a247eb1b70 Miraielf mirai ua-wget
http://94.156.152.233/bins/narm6010e9519a33344bc8d60513baa0f8751f1846a7f1cb69712f10c25cc66ebff95 Miraielf mirai ua-wget
http://94.156.152.233/bins/narm7fb23d25776eba426752a7733dc5828d1c149696b0a7926cb579239efadd55bbf Miraielf mirai ua-wget
http://94.156.152.233/bins/nm68k644a2f95c8b2df0374b694ea3577822b51b6031ebb86a9a82c4501211ef42b9a Miraielf mirai ua-wget
http://94.156.152.233/bins/nmips22698b276f1330cc5bba78d3f16381a1ecc6b200a92b936ae63fe714439f31a5 Miraielf mirai ua-wget
http://94.156.152.233/bins/nmpsle65d632f973d01bc21af09c7c4a6fa549d2de676a01c63c2ea7c97b3eaf115af Miraielf mirai ua-wget
http://94.156.152.233/bins/nppcddbf3d2f7f177fdc92852e146d43dfcab6dac117c27378cdd91d4be3a222bfa9 Miraielf mirai ua-wget
http://94.156.152.233/bins/nsh423e4e5a25b2ea7c3a014f6334581cfe8e996d6eb4447653a187aba94846daa03 Miraielf mirai ua-wget
http://94.156.152.233/bins/nspcn/an/aelf ua-wget
http://94.156.152.233/bins/nx862bbb387226de2faa8f60eaa2988e6a9a05c6d41b191ef0f24f029b184f260677 Miraielf mirai ua-wget
http://94.156.152.233/bins/nx86_649d36aecf683aea4077b365d5136374eb3a58b79e208f86a8a5885d7534b33ea6 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
CZ CZ
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-07T09:02:00Z UTC
Last seen:
2026-04-07T09:17:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=853fbcc1-1a00-0000-250e-947d050b0000 pid=2821 /usr/bin/sudo guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828 /tmp/sample.bin guuid=853fbcc1-1a00-0000-250e-947d050b0000 pid=2821->guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828 execve guuid=76dc3ac5-1a00-0000-250e-947d0e0b0000 pid=2830 /usr/bin/curl net send-data guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=76dc3ac5-1a00-0000-250e-947d0e0b0000 pid=2830 execve guuid=af5bb6f0-1a00-0000-250e-947d230b0000 pid=2851 /usr/bin/chmod guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=af5bb6f0-1a00-0000-250e-947d230b0000 pid=2851 execve guuid=862432f1-1a00-0000-250e-947d240b0000 pid=2852 /usr/bin/dash guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=862432f1-1a00-0000-250e-947d240b0000 pid=2852 clone guuid=3c8b50f1-1a00-0000-250e-947d250b0000 pid=2853 /usr/bin/curl net send-data guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=3c8b50f1-1a00-0000-250e-947d250b0000 pid=2853 execve guuid=d2e2210b-1b00-0000-250e-947d630b0000 pid=2915 /usr/bin/chmod guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=d2e2210b-1b00-0000-250e-947d630b0000 pid=2915 execve guuid=56787c0b-1b00-0000-250e-947d650b0000 pid=2917 /usr/bin/dash guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=56787c0b-1b00-0000-250e-947d650b0000 pid=2917 clone guuid=cf57820b-1b00-0000-250e-947d660b0000 pid=2918 /usr/bin/curl net send-data guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=cf57820b-1b00-0000-250e-947d660b0000 pid=2918 execve guuid=d14a1f23-1b00-0000-250e-947d890b0000 pid=2953 /usr/bin/chmod guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=d14a1f23-1b00-0000-250e-947d890b0000 pid=2953 execve guuid=9c3a6823-1b00-0000-250e-947d8a0b0000 pid=2954 /usr/bin/dash guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=9c3a6823-1b00-0000-250e-947d8a0b0000 pid=2954 clone guuid=f9576d23-1b00-0000-250e-947d8c0b0000 pid=2956 /usr/bin/curl net send-data guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=f9576d23-1b00-0000-250e-947d8c0b0000 pid=2956 execve guuid=68ba0d37-1b00-0000-250e-947dad0b0000 pid=2989 /usr/bin/chmod guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=68ba0d37-1b00-0000-250e-947dad0b0000 pid=2989 execve guuid=5b229937-1b00-0000-250e-947daf0b0000 pid=2991 /usr/bin/dash guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=5b229937-1b00-0000-250e-947daf0b0000 pid=2991 clone guuid=d75eb537-1b00-0000-250e-947db10b0000 pid=2993 /usr/bin/curl net send-data guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=d75eb537-1b00-0000-250e-947db10b0000 pid=2993 execve guuid=edf29250-1b00-0000-250e-947ddd0b0000 pid=3037 /usr/bin/chmod guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=edf29250-1b00-0000-250e-947ddd0b0000 pid=3037 execve guuid=5dde1b51-1b00-0000-250e-947ddf0b0000 pid=3039 /usr/bin/dash guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=5dde1b51-1b00-0000-250e-947ddf0b0000 pid=3039 clone guuid=65003351-1b00-0000-250e-947de00b0000 pid=3040 /usr/bin/curl net send-data guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=65003351-1b00-0000-250e-947de00b0000 pid=3040 execve guuid=f5e12d70-1b00-0000-250e-947d200c0000 pid=3104 /usr/bin/chmod guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=f5e12d70-1b00-0000-250e-947d200c0000 pid=3104 execve guuid=e85cc270-1b00-0000-250e-947d220c0000 pid=3106 /usr/bin/dash guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=e85cc270-1b00-0000-250e-947d220c0000 pid=3106 clone guuid=6fe4da70-1b00-0000-250e-947d230c0000 pid=3107 /usr/bin/curl net send-data guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=6fe4da70-1b00-0000-250e-947d230c0000 pid=3107 execve guuid=8e9f398d-1b00-0000-250e-947d690c0000 pid=3177 /usr/bin/chmod guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=8e9f398d-1b00-0000-250e-947d690c0000 pid=3177 execve guuid=a2fa918d-1b00-0000-250e-947d6a0c0000 pid=3178 /usr/bin/dash guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=a2fa918d-1b00-0000-250e-947d6a0c0000 pid=3178 clone guuid=1dd4a88d-1b00-0000-250e-947d6b0c0000 pid=3179 /usr/bin/curl net send-data guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=1dd4a88d-1b00-0000-250e-947d6b0c0000 pid=3179 execve guuid=f993caa6-1b00-0000-250e-947d870c0000 pid=3207 /usr/bin/chmod guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=f993caa6-1b00-0000-250e-947d870c0000 pid=3207 execve guuid=5b1579a7-1b00-0000-250e-947d880c0000 pid=3208 /usr/bin/dash guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=5b1579a7-1b00-0000-250e-947d880c0000 pid=3208 clone guuid=2a9487a7-1b00-0000-250e-947d890c0000 pid=3209 /usr/bin/curl net send-data guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=2a9487a7-1b00-0000-250e-947d890c0000 pid=3209 execve guuid=8bfb31c3-1b00-0000-250e-947dae0c0000 pid=3246 /usr/bin/chmod guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=8bfb31c3-1b00-0000-250e-947dae0c0000 pid=3246 execve guuid=dfe895c3-1b00-0000-250e-947daf0c0000 pid=3247 /usr/bin/dash guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=dfe895c3-1b00-0000-250e-947daf0c0000 pid=3247 clone guuid=c901b3c3-1b00-0000-250e-947db00c0000 pid=3248 /usr/bin/curl net send-data guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=c901b3c3-1b00-0000-250e-947db00c0000 pid=3248 execve guuid=2707d6ce-1b00-0000-250e-947db20c0000 pid=3250 /usr/bin/chmod guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=2707d6ce-1b00-0000-250e-947db20c0000 pid=3250 execve guuid=603862cf-1b00-0000-250e-947db30c0000 pid=3251 /usr/bin/dash guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=603862cf-1b00-0000-250e-947db30c0000 pid=3251 clone guuid=ac227bcf-1b00-0000-250e-947db40c0000 pid=3252 /usr/bin/curl net send-data guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=ac227bcf-1b00-0000-250e-947db40c0000 pid=3252 execve guuid=af96c4e7-1b00-0000-250e-947dd50c0000 pid=3285 /usr/bin/chmod guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=af96c4e7-1b00-0000-250e-947dd50c0000 pid=3285 execve guuid=765d7ae8-1b00-0000-250e-947dd70c0000 pid=3287 /usr/bin/dash guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=765d7ae8-1b00-0000-250e-947dd70c0000 pid=3287 clone guuid=06e388e8-1b00-0000-250e-947dd80c0000 pid=3288 /usr/bin/curl net send-data guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=06e388e8-1b00-0000-250e-947dd80c0000 pid=3288 execve guuid=6826cd04-1c00-0000-250e-947d0a0d0000 pid=3338 /usr/bin/chmod guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=6826cd04-1c00-0000-250e-947d0a0d0000 pid=3338 execve guuid=32110905-1c00-0000-250e-947d0c0d0000 pid=3340 /usr/bin/dash guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=32110905-1c00-0000-250e-947d0c0d0000 pid=3340 clone guuid=cf391e05-1c00-0000-250e-947d0d0d0000 pid=3341 /usr/bin/rm delete-file guuid=7a8b96c4-1a00-0000-250e-947d0c0b0000 pid=2828->guuid=cf391e05-1c00-0000-250e-947d0d0d0000 pid=3341 execve 72af6dc9-e0e7-5186-a050-4a3a967dfc62 94.156.152.233:80 guuid=76dc3ac5-1a00-0000-250e-947d0e0b0000 pid=2830->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 87B guuid=3c8b50f1-1a00-0000-250e-947d250b0000 pid=2853->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 88B guuid=cf57820b-1b00-0000-250e-947d660b0000 pid=2918->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 88B guuid=f9576d23-1b00-0000-250e-947d8c0b0000 pid=2956->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 88B guuid=d75eb537-1b00-0000-250e-947db10b0000 pid=2993->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 88B guuid=65003351-1b00-0000-250e-947de00b0000 pid=3040->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 88B guuid=6fe4da70-1b00-0000-250e-947d230c0000 pid=3107->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 88B guuid=1dd4a88d-1b00-0000-250e-947d6b0c0000 pid=3179->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 87B guuid=2a9487a7-1b00-0000-250e-947d890c0000 pid=3209->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 87B guuid=c901b3c3-1b00-0000-250e-947db00c0000 pid=3248->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 87B guuid=ac227bcf-1b00-0000-250e-947db40c0000 pid=3252->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 87B guuid=06e388e8-1b00-0000-250e-947dd80c0000 pid=3288->72af6dc9-e0e7-5186-a050-4a3a967dfc62 send: 90B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Trojan.Vigorf
Status:
Malicious
First seen:
2026-04-07 11:35:17 UTC
File Type:
Text (Shell)
AV detection:
15 of 38 (39.47%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Mirai

sh aa2525e7323f152f0be40c7d4dc0c8fc11f8800ada449a72e11c66a1b3a2bec1

(this sample)

Comments