MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa7c4b33173492ca9432b6552c86c44a307e7b0c765407380c1c655eb37d26f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: aa7c4b33173492ca9432b6552c86c44a307e7b0c765407380c1c655eb37d26f2
SHA3-384 hash: d9dd8edbebd404dfc5c356a51d897951930895e0d3e7382bf9ca4032e59588dcc80c18236ec289e217d74a9b4afd2431
SHA1 hash: 30fd16a0f55746658d37809d8de7eeab5fa0570f
MD5 hash: c568715abe6061536410a771cadc3123
humanhash: stream-idaho-ceiling-delaware
File name:c.sh
Download: download sample
Signature Mirai
File size:892 bytes
First seen:2025-12-25 09:58:19 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3+Aw3XzuNIBS+5zoKSr50xHXf7M8x0l9AXQI9ovSTxy2aF6YShyrQbk:3J3+RCNIItKSrU3g8il9AR9tKWOQw
TLSH T14E11ACE821D0981B59EACC0C72E9801CA63BD0C579618B34ED79443744E72B86F6C7AD
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://190.123.46.72/bins/main_arm0b423d1b9e7a9e6719bf77dfa5363998d04f9edad2ee8e2de911c7ae995a391a Miraielf mirai ua-wget
http://190.123.46.72/bins/main_arm55d94992dac0b6d592f86b0d59af84c52168f05d7aa1713a0c4fd62820be71630 Miraielf mirai ua-wget
http://190.123.46.72/bins/main_arm65b1cf87888710837c0007fd20877644abec191d7fed82763a15b959d591444d4 Miraielf mirai ua-wget
http://190.123.46.72/bins/main_arm7cf40305398ee234528ebd18bb54b13e1bb94f90a501636857e25ba114bb1c9c6 Miraielf mirai ua-wget
http://190.123.46.72/bins/main_sh4fd893a3ee002cd623137b4f65fda5624232eb22e53f5fec40601bc26e7eed29a Miraielf mirai ua-wget
http://190.123.46.72/bins/main_m68k7cca33815eaccd864db722658cce4a234c32280e2ee7266c9fecd8601652c95f Miraielf mirai ua-wget
http://190.123.46.72/bins/main_mips261cbea15e9c316a7a13d6ee7c496feb4364d264355821dc03664c17f398bcd1 Miraielf mirai ua-wget
http://190.123.46.72/bins/main_mpsl2322a5098627d113e939e6ac7ddb5c80ed5e253a650c6b6e1737baa4617db415 Miraielf mirai ua-wget
http://190.123.46.72/bins/main_x86_646c22bec08f6ce62b43664b22028e033d496990b06a053c4aee5168b3af787c55 Miraielf mirai ua-wget
http://190.123.46.72/bins/main_ppcb1d611c59c43c5f2ae26da403ac6f4c59f721d91716cd5c07e3293351db8124c Miraielf mirai ua-wget
http://190.123.46.72/bins/main_x8605466e5727f528209cff95c2e7e2b197aa0fe4e312fd3709c13a1605c8cc2555 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
bash lolbin mirai
Status:
terminated
Behavior Graph:
%3 guuid=e752bddb-1800-0000-a99f-0719c6090000 pid=2502 /usr/bin/sudo guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509 /tmp/sample.bin guuid=e752bddb-1800-0000-a99f-0719c6090000 pid=2502->guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509 execve guuid=01c3efdd-1800-0000-a99f-0719cf090000 pid=2511 /usr/bin/curl net send-data guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=01c3efdd-1800-0000-a99f-0719cf090000 pid=2511 execve guuid=a0a7a811-1900-0000-a99f-0719530a0000 pid=2643 /usr/bin/chmod guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=a0a7a811-1900-0000-a99f-0719530a0000 pid=2643 execve guuid=f22d1d12-1900-0000-a99f-0719550a0000 pid=2645 /usr/bin/dash guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=f22d1d12-1900-0000-a99f-0719550a0000 pid=2645 clone guuid=b6692d12-1900-0000-a99f-0719560a0000 pid=2646 /usr/bin/curl net send-data guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=b6692d12-1900-0000-a99f-0719560a0000 pid=2646 execve guuid=9e8c8744-1900-0000-a99f-0719d20a0000 pid=2770 /usr/bin/chmod guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=9e8c8744-1900-0000-a99f-0719d20a0000 pid=2770 execve guuid=9fc29545-1900-0000-a99f-0719d30a0000 pid=2771 /usr/bin/dash guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=9fc29545-1900-0000-a99f-0719d30a0000 pid=2771 clone guuid=60aeae45-1900-0000-a99f-0719d40a0000 pid=2772 /usr/bin/curl net send-data guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=60aeae45-1900-0000-a99f-0719d40a0000 pid=2772 execve guuid=18916c84-1900-0000-a99f-07194f0b0000 pid=2895 /usr/bin/chmod guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=18916c84-1900-0000-a99f-07194f0b0000 pid=2895 execve guuid=e63abe84-1900-0000-a99f-0719500b0000 pid=2896 /usr/bin/dash guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=e63abe84-1900-0000-a99f-0719500b0000 pid=2896 clone guuid=741dd284-1900-0000-a99f-0719520b0000 pid=2898 /usr/bin/curl net send-data guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=741dd284-1900-0000-a99f-0719520b0000 pid=2898 execve guuid=350382bf-1900-0000-a99f-07198c0b0000 pid=2956 /usr/bin/chmod guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=350382bf-1900-0000-a99f-07198c0b0000 pid=2956 execve guuid=99ccf6bf-1900-0000-a99f-07198d0b0000 pid=2957 /usr/bin/dash guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=99ccf6bf-1900-0000-a99f-07198d0b0000 pid=2957 clone guuid=03e603c0-1900-0000-a99f-07198e0b0000 pid=2958 /usr/bin/curl net send-data guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=03e603c0-1900-0000-a99f-07198e0b0000 pid=2958 execve guuid=acd0e2f3-1900-0000-a99f-0719e10b0000 pid=3041 /usr/bin/chmod guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=acd0e2f3-1900-0000-a99f-0719e10b0000 pid=3041 execve guuid=13e45bf4-1900-0000-a99f-0719e30b0000 pid=3043 /usr/bin/dash guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=13e45bf4-1900-0000-a99f-0719e30b0000 pid=3043 clone guuid=4c966ef4-1900-0000-a99f-0719e40b0000 pid=3044 /usr/bin/curl net send-data guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=4c966ef4-1900-0000-a99f-0719e40b0000 pid=3044 execve guuid=10abf269-1a00-0000-a99f-07199b0c0000 pid=3227 /usr/bin/chmod guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=10abf269-1a00-0000-a99f-07199b0c0000 pid=3227 execve guuid=eeea926a-1a00-0000-a99f-07199d0c0000 pid=3229 /usr/bin/dash guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=eeea926a-1a00-0000-a99f-07199d0c0000 pid=3229 clone guuid=f8d9a76a-1a00-0000-a99f-07199e0c0000 pid=3230 /usr/bin/curl net send-data guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=f8d9a76a-1a00-0000-a99f-07199e0c0000 pid=3230 execve guuid=f85dbfe6-1a00-0000-a99f-07192a0d0000 pid=3370 /usr/bin/chmod guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=f85dbfe6-1a00-0000-a99f-07192a0d0000 pid=3370 execve guuid=86442ae7-1a00-0000-a99f-07192b0d0000 pid=3371 /usr/bin/dash guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=86442ae7-1a00-0000-a99f-07192b0d0000 pid=3371 clone guuid=7b263ee7-1a00-0000-a99f-07192c0d0000 pid=3372 /usr/bin/curl net send-data guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=7b263ee7-1a00-0000-a99f-07192c0d0000 pid=3372 execve guuid=f812b061-1b00-0000-a99f-0719070e0000 pid=3591 /usr/bin/chmod guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=f812b061-1b00-0000-a99f-0719070e0000 pid=3591 execve guuid=66641162-1b00-0000-a99f-0719090e0000 pid=3593 /usr/bin/dash guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=66641162-1b00-0000-a99f-0719090e0000 pid=3593 clone guuid=b88b1862-1b00-0000-a99f-07190a0e0000 pid=3594 /usr/bin/curl net send-data guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=b88b1862-1b00-0000-a99f-07190a0e0000 pid=3594 execve guuid=6950d8c8-1b00-0000-a99f-0719080f0000 pid=3848 /usr/bin/chmod guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=6950d8c8-1b00-0000-a99f-0719080f0000 pid=3848 execve guuid=9de96ec9-1b00-0000-a99f-0719090f0000 pid=3849 /usr/bin/dash guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=9de96ec9-1b00-0000-a99f-0719090f0000 pid=3849 clone guuid=baa796c9-1b00-0000-a99f-07190a0f0000 pid=3850 /usr/bin/curl net send-data guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=baa796c9-1b00-0000-a99f-07190a0f0000 pid=3850 execve guuid=f3dd5630-1c00-0000-a99f-071937100000 pid=4151 /usr/bin/chmod guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=f3dd5630-1c00-0000-a99f-071937100000 pid=4151 execve guuid=d33d9c30-1c00-0000-a99f-071938100000 pid=4152 /usr/bin/dash guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=d33d9c30-1c00-0000-a99f-071938100000 pid=4152 clone guuid=4cd6a130-1c00-0000-a99f-071939100000 pid=4153 /usr/bin/curl net send-data guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=4cd6a130-1c00-0000-a99f-071939100000 pid=4153 execve guuid=85daef7b-1c00-0000-a99f-071928110000 pid=4392 /usr/bin/chmod guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=85daef7b-1c00-0000-a99f-071928110000 pid=4392 execve guuid=89d6377c-1c00-0000-a99f-071929110000 pid=4393 /usr/bin/dash guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=89d6377c-1c00-0000-a99f-071929110000 pid=4393 clone guuid=7e9e437c-1c00-0000-a99f-07192b110000 pid=4395 /usr/bin/rm delete-file guuid=5b10badd-1800-0000-a99f-0719cd090000 pid=2509->guuid=7e9e437c-1c00-0000-a99f-07192b110000 pid=4395 execve dafb67d5-df68-55a8-a871-37e37b4e86bd 190.123.46.72:80 guuid=01c3efdd-1800-0000-a99f-0719cf090000 pid=2511->dafb67d5-df68-55a8-a871-37e37b4e86bd send: 90B guuid=b6692d12-1900-0000-a99f-0719560a0000 pid=2646->dafb67d5-df68-55a8-a871-37e37b4e86bd send: 91B guuid=60aeae45-1900-0000-a99f-0719d40a0000 pid=2772->dafb67d5-df68-55a8-a871-37e37b4e86bd send: 91B guuid=741dd284-1900-0000-a99f-0719520b0000 pid=2898->dafb67d5-df68-55a8-a871-37e37b4e86bd send: 91B guuid=03e603c0-1900-0000-a99f-07198e0b0000 pid=2958->dafb67d5-df68-55a8-a871-37e37b4e86bd send: 90B guuid=4c966ef4-1900-0000-a99f-0719e40b0000 pid=3044->dafb67d5-df68-55a8-a871-37e37b4e86bd send: 91B guuid=f8d9a76a-1a00-0000-a99f-07199e0c0000 pid=3230->dafb67d5-df68-55a8-a871-37e37b4e86bd send: 91B guuid=7b263ee7-1a00-0000-a99f-07192c0d0000 pid=3372->dafb67d5-df68-55a8-a871-37e37b4e86bd send: 91B guuid=b88b1862-1b00-0000-a99f-07190a0e0000 pid=3594->dafb67d5-df68-55a8-a871-37e37b4e86bd send: 93B guuid=baa796c9-1b00-0000-a99f-07190a0f0000 pid=3850->dafb67d5-df68-55a8-a871-37e37b4e86bd send: 90B guuid=4cd6a130-1c00-0000-a99f-071939100000 pid=4153->dafb67d5-df68-55a8-a871-37e37b4e86bd send: 90B
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-12-25 09:49:37 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh aa7c4b33173492ca9432b6552c86c44a307e7b0c765407380c1c655eb37d26f2

(this sample)

  
Delivery method
Distributed via web download

Comments