MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aeda42b413fe50a381d97e1108aa336ee6be8489888b2c2db4ebeddbdd4392f0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: aeda42b413fe50a381d97e1108aa336ee6be8489888b2c2db4ebeddbdd4392f0
SHA3-384 hash: 293d18e84c8e62f004a2ef484df409ac5efaf8734e00aebc0313a07324ea96de935d2b669957017997fa3d4890f932ab
SHA1 hash: c86726d6daeb5c25151887bb35caf291acdf4330
MD5 hash: 1fb4b632cb59507f74e03b1a730ccd39
humanhash: nineteen-six-grey-muppet
File name:c.sh
Download: download sample
Signature Mirai
File size:1'017 bytes
First seen:2025-12-25 19:18:58 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:oZXWsJWWW3bGNWWWtMNWWW2u8NIl5ONWWWLa0LK3NWWW1tODOmNWWWjpiVNWWWZL:m0T8NI7pKfDsiz+WA3t7dUP27
TLSH T18D1151CE31911FB75A089F0CF577802855C3A8D8FD626DD1A3161C384CDB72DB528AB6
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.156.152.90/bins/arme0844b0cdf611d8a7521ff37ca40ab691a2c2c3e28a4b9571ff9456d5b5a2b77 Miraielf ua-wget
http://94.156.152.90/bins/arm5f6fbf730c614f55b266174036c98d1827bc602c3c830ccff25454272c694b91f Miraielf ua-wget
http://94.156.152.90/bins/arm646588e27520d4ff181d33bc7ff021903d1ecd13f376657f5db7af180ca2e3ac6 Miraielf mirai ua-wget
http://94.156.152.90/bins/arm7c05ee431ce3abe70afdbf9710b0ab3864ecdd8de9f8697c077f956a39bdf8217 Miraielf ua-wget
http://94.156.152.90/bins/m68k0fc0c0aa10d7f989ee6709c50908144d95b2c62ad512419f690652c906db8ed5 Miraielf mirai ua-wget
http://94.156.152.90/bins/mips0f8f041acce3852c7ee78caffddcb4e941206b3c5b905bb5e6c061285ce08852 Miraielf ua-wget
http://94.156.152.90/bins/mpsld80d236e16bfef3dd5b8aacb4aff4226616be790c3b5dc2325af73e71d61441c Miraielf mirai ua-wget
http://94.156.152.90/bins/ppc14d5f0267f0ca1c67bdd8e3075ee3598e2ae7444c7f87bab0b862b3b5ee6ced7 Miraielf ua-wget
http://94.156.152.90/bins/sh4439b5691344326a2b67d18c5414f27c50d2b5be2bba021a6c74fbd718fd956ce Miraielf ua-wget
http://94.156.152.90/bins/spc2951437574f0b44b68855462c650bc1d7b10fbaf36ed86e7a45faec38b87ee6e Miraielf ua-wget
http://94.156.152.90/bins/x8603ecda01330d867752a09c2e6118fed74a061d4f5222d492ab43640e0d36e6c4 Miraielf mirai ua-wget
http://94.156.152.90/bins/x86_64c0fe3a9a893f48296e27f62bb47a35480d0255c5df46d2185963ce8552004535 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-25T16:38:00Z UTC
Last seen:
2025-12-27T12:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=f52c1099-1a00-0000-a0aa-cdc7640a0000 pid=2660 /usr/bin/sudo guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667 /tmp/sample.bin guuid=f52c1099-1a00-0000-a0aa-cdc7640a0000 pid=2660->guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667 execve guuid=1e6fc29c-1a00-0000-a0aa-cdc76f0a0000 pid=2671 /usr/bin/curl net send-data write-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=1e6fc29c-1a00-0000-a0aa-cdc76f0a0000 pid=2671 execve guuid=e52f26b3-1a00-0000-a0aa-cdc7a40a0000 pid=2724 /usr/bin/chmod guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=e52f26b3-1a00-0000-a0aa-cdc7a40a0000 pid=2724 execve guuid=ae6abcb3-1a00-0000-a0aa-cdc7a60a0000 pid=2726 /usr/bin/bash guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=ae6abcb3-1a00-0000-a0aa-cdc7a60a0000 pid=2726 clone guuid=ab536eb4-1a00-0000-a0aa-cdc7aa0a0000 pid=2730 /usr/bin/curl net send-data write-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=ab536eb4-1a00-0000-a0aa-cdc7aa0a0000 pid=2730 execve guuid=37dbc4c3-1a00-0000-a0aa-cdc7c80a0000 pid=2760 /usr/bin/chmod guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=37dbc4c3-1a00-0000-a0aa-cdc7c80a0000 pid=2760 execve guuid=03240ec4-1a00-0000-a0aa-cdc7c90a0000 pid=2761 /usr/bin/bash guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=03240ec4-1a00-0000-a0aa-cdc7c90a0000 pid=2761 clone guuid=67d03fc5-1a00-0000-a0aa-cdc7cd0a0000 pid=2765 /usr/bin/curl net send-data write-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=67d03fc5-1a00-0000-a0aa-cdc7cd0a0000 pid=2765 execve guuid=e0f254db-1a00-0000-a0aa-cdc7eb0a0000 pid=2795 /usr/bin/chmod guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=e0f254db-1a00-0000-a0aa-cdc7eb0a0000 pid=2795 execve guuid=8d89d3db-1a00-0000-a0aa-cdc7ec0a0000 pid=2796 /usr/bin/bash guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=8d89d3db-1a00-0000-a0aa-cdc7ec0a0000 pid=2796 clone guuid=8d8402dd-1a00-0000-a0aa-cdc7f10a0000 pid=2801 /usr/bin/curl net send-data write-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=8d8402dd-1a00-0000-a0aa-cdc7f10a0000 pid=2801 execve guuid=c4f482ef-1a00-0000-a0aa-cdc7080b0000 pid=2824 /usr/bin/chmod guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=c4f482ef-1a00-0000-a0aa-cdc7080b0000 pid=2824 execve guuid=f4050ff0-1a00-0000-a0aa-cdc70b0b0000 pid=2827 /usr/bin/bash guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=f4050ff0-1a00-0000-a0aa-cdc70b0b0000 pid=2827 clone guuid=7899e6f0-1a00-0000-a0aa-cdc7100b0000 pid=2832 /usr/bin/curl net send-data write-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=7899e6f0-1a00-0000-a0aa-cdc7100b0000 pid=2832 execve guuid=93c07201-1b00-0000-a0aa-cdc7200b0000 pid=2848 /usr/bin/chmod guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=93c07201-1b00-0000-a0aa-cdc7200b0000 pid=2848 execve guuid=0c9cba01-1b00-0000-a0aa-cdc7220b0000 pid=2850 /usr/bin/bash guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=0c9cba01-1b00-0000-a0aa-cdc7220b0000 pid=2850 clone guuid=15564602-1b00-0000-a0aa-cdc7250b0000 pid=2853 /usr/bin/curl net send-data write-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=15564602-1b00-0000-a0aa-cdc7250b0000 pid=2853 execve guuid=0d832923-1b00-0000-a0aa-cdc7700b0000 pid=2928 /usr/bin/chmod guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=0d832923-1b00-0000-a0aa-cdc7700b0000 pid=2928 execve guuid=a0df9923-1b00-0000-a0aa-cdc7710b0000 pid=2929 /usr/bin/bash guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=a0df9923-1b00-0000-a0aa-cdc7710b0000 pid=2929 clone guuid=ad7b8124-1b00-0000-a0aa-cdc7740b0000 pid=2932 /usr/bin/curl net send-data write-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=ad7b8124-1b00-0000-a0aa-cdc7740b0000 pid=2932 execve guuid=1b05ce34-1b00-0000-a0aa-cdc7920b0000 pid=2962 /usr/bin/chmod guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=1b05ce34-1b00-0000-a0aa-cdc7920b0000 pid=2962 execve guuid=63062435-1b00-0000-a0aa-cdc7940b0000 pid=2964 /usr/bin/bash guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=63062435-1b00-0000-a0aa-cdc7940b0000 pid=2964 clone guuid=595cad37-1b00-0000-a0aa-cdc7980b0000 pid=2968 /usr/bin/curl net send-data write-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=595cad37-1b00-0000-a0aa-cdc7980b0000 pid=2968 execve guuid=182c764e-1b00-0000-a0aa-cdc7bb0b0000 pid=3003 /usr/bin/chmod guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=182c764e-1b00-0000-a0aa-cdc7bb0b0000 pid=3003 execve guuid=c45fe14e-1b00-0000-a0aa-cdc7bd0b0000 pid=3005 /usr/bin/bash guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=c45fe14e-1b00-0000-a0aa-cdc7bd0b0000 pid=3005 clone guuid=ad569c4f-1b00-0000-a0aa-cdc7c10b0000 pid=3009 /usr/bin/curl net send-data write-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=ad569c4f-1b00-0000-a0aa-cdc7c10b0000 pid=3009 execve guuid=df096260-1b00-0000-a0aa-cdc7e20b0000 pid=3042 /usr/bin/chmod guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=df096260-1b00-0000-a0aa-cdc7e20b0000 pid=3042 execve guuid=ed08ad60-1b00-0000-a0aa-cdc7e40b0000 pid=3044 /usr/bin/bash guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=ed08ad60-1b00-0000-a0aa-cdc7e40b0000 pid=3044 clone guuid=c0e97861-1b00-0000-a0aa-cdc7e80b0000 pid=3048 /usr/bin/curl net send-data write-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=c0e97861-1b00-0000-a0aa-cdc7e80b0000 pid=3048 execve guuid=174e1373-1b00-0000-a0aa-cdc7140c0000 pid=3092 /usr/bin/chmod guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=174e1373-1b00-0000-a0aa-cdc7140c0000 pid=3092 execve guuid=93b27473-1b00-0000-a0aa-cdc7150c0000 pid=3093 /usr/bin/bash guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=93b27473-1b00-0000-a0aa-cdc7150c0000 pid=3093 clone guuid=c8c34474-1b00-0000-a0aa-cdc7190c0000 pid=3097 /usr/bin/curl net send-data write-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=c8c34474-1b00-0000-a0aa-cdc7190c0000 pid=3097 execve guuid=1046d582-1b00-0000-a0aa-cdc7400c0000 pid=3136 /usr/bin/chmod guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=1046d582-1b00-0000-a0aa-cdc7400c0000 pid=3136 execve guuid=cfab4383-1b00-0000-a0aa-cdc7420c0000 pid=3138 /tmp/x86 net guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=cfab4383-1b00-0000-a0aa-cdc7420c0000 pid=3138 execve guuid=505305fb-1b00-0000-a0aa-cdc7ec0c0000 pid=3308 /usr/bin/curl net send-data write-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=505305fb-1b00-0000-a0aa-cdc7ec0c0000 pid=3308 execve guuid=1eb8ed0c-1c00-0000-a0aa-cdc7090d0000 pid=3337 /usr/bin/chmod guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=1eb8ed0c-1c00-0000-a0aa-cdc7090d0000 pid=3337 execve guuid=df78450d-1c00-0000-a0aa-cdc70b0d0000 pid=3339 /tmp/x86_64 net guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=df78450d-1c00-0000-a0aa-cdc70b0d0000 pid=3339 execve guuid=8c54e384-1c00-0000-a0aa-cdc7050e0000 pid=3589 /usr/bin/rm delete-file guuid=f069889b-1a00-0000-a0aa-cdc76b0a0000 pid=2667->guuid=8c54e384-1c00-0000-a0aa-cdc7050e0000 pid=3589 execve e217ae65-493d-53f3-ad87-163d1acdbb8a 94.156.152.90:80 guuid=1e6fc29c-1a00-0000-a0aa-cdc76f0a0000 pid=2671->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 85B guuid=ab536eb4-1a00-0000-a0aa-cdc7aa0a0000 pid=2730->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 86B guuid=67d03fc5-1a00-0000-a0aa-cdc7cd0a0000 pid=2765->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 86B guuid=8d8402dd-1a00-0000-a0aa-cdc7f10a0000 pid=2801->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 86B guuid=7899e6f0-1a00-0000-a0aa-cdc7100b0000 pid=2832->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 86B guuid=15564602-1b00-0000-a0aa-cdc7250b0000 pid=2853->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 86B guuid=ad7b8124-1b00-0000-a0aa-cdc7740b0000 pid=2932->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 86B guuid=595cad37-1b00-0000-a0aa-cdc7980b0000 pid=2968->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 85B guuid=ad569c4f-1b00-0000-a0aa-cdc7c10b0000 pid=3009->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 85B guuid=c0e97861-1b00-0000-a0aa-cdc7e80b0000 pid=3048->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 85B guuid=c8c34474-1b00-0000-a0aa-cdc7190c0000 pid=3097->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 85B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=cfab4383-1b00-0000-a0aa-cdc7420c0000 pid=3138->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=56488883-1b00-0000-a0aa-cdc7440c0000 pid=3140 /tmp/x86 guuid=cfab4383-1b00-0000-a0aa-cdc7420c0000 pid=3138->guuid=56488883-1b00-0000-a0aa-cdc7440c0000 pid=3140 clone guuid=7b4332bf-1b00-0000-a0aa-cdc7b00c0000 pid=3248 /tmp/x86 guuid=cfab4383-1b00-0000-a0aa-cdc7420c0000 pid=3138->guuid=7b4332bf-1b00-0000-a0aa-cdc7b00c0000 pid=3248 clone guuid=c804e2fa-1b00-0000-a0aa-cdc7e90c0000 pid=3305 /tmp/x86 guuid=cfab4383-1b00-0000-a0aa-cdc7420c0000 pid=3138->guuid=c804e2fa-1b00-0000-a0aa-cdc7e90c0000 pid=3305 clone guuid=4416effa-1b00-0000-a0aa-cdc7ea0c0000 pid=3306 /tmp/x86 dns net send-data zombie guuid=cfab4383-1b00-0000-a0aa-cdc7420c0000 pid=3138->guuid=4416effa-1b00-0000-a0aa-cdc7ea0c0000 pid=3306 clone guuid=4416effa-1b00-0000-a0aa-cdc7ea0c0000 pid=3306->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 2090B 6272d858-80a1-5f9b-be28-4d6aceb31fbd niggabot.windy.my.id:23 guuid=4416effa-1b00-0000-a0aa-cdc7ea0c0000 pid=3306->6272d858-80a1-5f9b-be28-4d6aceb31fbd con guuid=507104fb-1b00-0000-a0aa-cdc7eb0c0000 pid=3307 /tmp/x86 guuid=4416effa-1b00-0000-a0aa-cdc7ea0c0000 pid=3306->guuid=507104fb-1b00-0000-a0aa-cdc7eb0c0000 pid=3307 clone guuid=f39fc636-1c00-0000-a0aa-cdc74a0d0000 pid=3402 /tmp/x86 guuid=4416effa-1b00-0000-a0aa-cdc7ea0c0000 pid=3306->guuid=f39fc636-1c00-0000-a0aa-cdc74a0d0000 pid=3402 clone guuid=412b7272-1c00-0000-a0aa-cdc7e00d0000 pid=3552 /tmp/x86 guuid=4416effa-1b00-0000-a0aa-cdc7ea0c0000 pid=3306->guuid=412b7272-1c00-0000-a0aa-cdc7e00d0000 pid=3552 clone guuid=505305fb-1b00-0000-a0aa-cdc7ec0c0000 pid=3308->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 88B guuid=df78450d-1c00-0000-a0aa-cdc70b0d0000 pid=3339->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6bed640d-1c00-0000-a0aa-cdc70c0d0000 pid=3340 /tmp/x86_64 guuid=df78450d-1c00-0000-a0aa-cdc70b0d0000 pid=3339->guuid=6bed640d-1c00-0000-a0aa-cdc70c0d0000 pid=3340 clone guuid=58ec0949-1c00-0000-a0aa-cdc7770d0000 pid=3447 /tmp/x86_64 guuid=df78450d-1c00-0000-a0aa-cdc70b0d0000 pid=3339->guuid=58ec0949-1c00-0000-a0aa-cdc7770d0000 pid=3447 clone guuid=ff9eb284-1c00-0000-a0aa-cdc7020e0000 pid=3586 /tmp/x86_64 guuid=df78450d-1c00-0000-a0aa-cdc70b0d0000 pid=3339->guuid=ff9eb284-1c00-0000-a0aa-cdc7020e0000 pid=3586 clone guuid=5372be84-1c00-0000-a0aa-cdc7030e0000 pid=3587 /tmp/x86_64 dns net send-data zombie guuid=df78450d-1c00-0000-a0aa-cdc70b0d0000 pid=3339->guuid=5372be84-1c00-0000-a0aa-cdc7030e0000 pid=3587 clone guuid=5372be84-1c00-0000-a0aa-cdc7030e0000 pid=3587->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1520B guuid=5372be84-1c00-0000-a0aa-cdc7030e0000 pid=3587->6272d858-80a1-5f9b-be28-4d6aceb31fbd con guuid=cff6d084-1c00-0000-a0aa-cdc7040e0000 pid=3588 /tmp/x86_64 guuid=5372be84-1c00-0000-a0aa-cdc7030e0000 pid=3587->guuid=cff6d084-1c00-0000-a0aa-cdc7040e0000 pid=3588 clone guuid=860b83c0-1c00-0000-a0aa-cdc78c0e0000 pid=3724 /tmp/x86_64 guuid=5372be84-1c00-0000-a0aa-cdc7030e0000 pid=3587->guuid=860b83c0-1c00-0000-a0aa-cdc78c0e0000 pid=3724 clone guuid=806b28fc-1c00-0000-a0aa-cdc74c0f0000 pid=3916 /tmp/x86_64 guuid=5372be84-1c00-0000-a0aa-cdc7030e0000 pid=3587->guuid=806b28fc-1c00-0000-a0aa-cdc74c0f0000 pid=3916 clone
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-12-25 19:20:22 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh aeda42b413fe50a381d97e1108aa336ee6be8489888b2c2db4ebeddbdd4392f0

(this sample)

  
Delivery method
Distributed via web download

Comments