MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b2c013e1a80e6f3fc846031ed7e79dea445cb81615062df1f2cb36c813b9ec20. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b2c013e1a80e6f3fc846031ed7e79dea445cb81615062df1f2cb36c813b9ec20
SHA3-384 hash: b20dae1f3583fb7502102ca07c6781e2aa43c7b7bbd89f24e0a790d8b60c272979de458ce4d74273a361b6cad547efd1
SHA1 hash: 314c9fb6fed26a538acb06a837560b5ea8cd9908
MD5 hash: ec8f376ec3e0cd7c2fff0e9cb5a5b13e
humanhash: lamp-steak-lima-october
File name:sh
Download: download sample
Signature Mirai
File size:263 bytes
First seen:2025-08-24 06:38:37 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:/VJ+pUKUF2RVYs5CYwwqwIlp3FsDKVKAOXqIKa03IKq1IEE1IKBKW:/VJ+jREY1TWgAsONI08W
TLSH T1D5D02E4DF80208B7F0388CB8B6EB3694E60FA20A3B0A95CE0984202BE4F0C70A060453
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Status:
terminated
Behavior Graph:
%3 guuid=8f64af6b-1900-0000-38af-1774240f0000 pid=3876 /usr/bin/sudo guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886 /tmp/sample.bin guuid=8f64af6b-1900-0000-38af-1774240f0000 pid=3876->guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886 execve guuid=0bb7736d-1900-0000-38af-17742f0f0000 pid=3887 /usr/bin/wget net send-data write-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=0bb7736d-1900-0000-38af-17742f0f0000 pid=3887 execve guuid=181b8682-1900-0000-38af-17746e0f0000 pid=3950 /usr/bin/chmod guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=181b8682-1900-0000-38af-17746e0f0000 pid=3950 execve guuid=173bce82-1900-0000-38af-1774720f0000 pid=3954 /usr/bin/dash guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=173bce82-1900-0000-38af-1774720f0000 pid=3954 clone guuid=ab557a84-1900-0000-38af-17747a0f0000 pid=3962 /usr/bin/rm delete-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=ab557a84-1900-0000-38af-17747a0f0000 pid=3962 execve guuid=ea42cd84-1900-0000-38af-17747c0f0000 pid=3964 /usr/bin/wget net send-data write-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=ea42cd84-1900-0000-38af-17747c0f0000 pid=3964 execve guuid=c9742999-1900-0000-38af-1774be0f0000 pid=4030 /usr/bin/chmod guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=c9742999-1900-0000-38af-1774be0f0000 pid=4030 execve guuid=9c118199-1900-0000-38af-1774c20f0000 pid=4034 /usr/bin/dash guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=9c118199-1900-0000-38af-1774c20f0000 pid=4034 clone guuid=695b569b-1900-0000-38af-1774c90f0000 pid=4041 /usr/bin/rm delete-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=695b569b-1900-0000-38af-1774c90f0000 pid=4041 execve guuid=fda9979b-1900-0000-38af-1774cb0f0000 pid=4043 /usr/bin/wget net send-data write-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=fda9979b-1900-0000-38af-1774cb0f0000 pid=4043 execve guuid=6551efb0-1900-0000-38af-177405100000 pid=4101 /usr/bin/chmod guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=6551efb0-1900-0000-38af-177405100000 pid=4101 execve guuid=a6bf7db1-1900-0000-38af-177406100000 pid=4102 /usr/bin/dash guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=a6bf7db1-1900-0000-38af-177406100000 pid=4102 clone guuid=d8537cb2-1900-0000-38af-17740b100000 pid=4107 /usr/bin/rm delete-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=d8537cb2-1900-0000-38af-17740b100000 pid=4107 execve guuid=a012f5b2-1900-0000-38af-17740c100000 pid=4108 /usr/bin/wget net send-data write-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=a012f5b2-1900-0000-38af-17740c100000 pid=4108 execve guuid=2c7237c8-1900-0000-38af-177449100000 pid=4169 /usr/bin/chmod guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=2c7237c8-1900-0000-38af-177449100000 pid=4169 execve guuid=7d9a98c8-1900-0000-38af-17744a100000 pid=4170 /usr/bin/dash guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=7d9a98c8-1900-0000-38af-17744a100000 pid=4170 clone guuid=a52c82c9-1900-0000-38af-17744c100000 pid=4172 /usr/bin/rm delete-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=a52c82c9-1900-0000-38af-17744c100000 pid=4172 execve guuid=e49ae7c9-1900-0000-38af-17744d100000 pid=4173 /usr/bin/wget net send-data write-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=e49ae7c9-1900-0000-38af-17744d100000 pid=4173 execve guuid=03acffde-1900-0000-38af-177482100000 pid=4226 /usr/bin/chmod guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=03acffde-1900-0000-38af-177482100000 pid=4226 execve guuid=44205fdf-1900-0000-38af-177484100000 pid=4228 /usr/bin/dash guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=44205fdf-1900-0000-38af-177484100000 pid=4228 clone guuid=49ffd2e0-1900-0000-38af-177489100000 pid=4233 /usr/bin/rm delete-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=49ffd2e0-1900-0000-38af-177489100000 pid=4233 execve guuid=290741e1-1900-0000-38af-17748b100000 pid=4235 /usr/bin/wget net send-data write-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=290741e1-1900-0000-38af-17748b100000 pid=4235 execve guuid=38d059fb-1900-0000-38af-1774de100000 pid=4318 /usr/bin/chmod guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=38d059fb-1900-0000-38af-1774de100000 pid=4318 execve guuid=1a3dbefb-1900-0000-38af-1774e0100000 pid=4320 /usr/bin/dash guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=1a3dbefb-1900-0000-38af-1774e0100000 pid=4320 clone guuid=ffeb94fc-1900-0000-38af-1774e3100000 pid=4323 /usr/bin/rm delete-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=ffeb94fc-1900-0000-38af-1774e3100000 pid=4323 execve guuid=9e2aebfc-1900-0000-38af-1774e5100000 pid=4325 /usr/bin/wget net send-data write-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=9e2aebfc-1900-0000-38af-1774e5100000 pid=4325 execve guuid=58c2b411-1a00-0000-38af-177416110000 pid=4374 /usr/bin/chmod guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=58c2b411-1a00-0000-38af-177416110000 pid=4374 execve guuid=869a0812-1a00-0000-38af-177418110000 pid=4376 /usr/bin/dash guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=869a0812-1a00-0000-38af-177418110000 pid=4376 clone guuid=df3ebd12-1a00-0000-38af-17741b110000 pid=4379 /usr/bin/rm delete-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=df3ebd12-1a00-0000-38af-17741b110000 pid=4379 execve guuid=9d671213-1a00-0000-38af-17741d110000 pid=4381 /usr/bin/wget net send-data write-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=9d671213-1a00-0000-38af-17741d110000 pid=4381 execve guuid=4d451928-1a00-0000-38af-177455110000 pid=4437 /usr/bin/chmod guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=4d451928-1a00-0000-38af-177455110000 pid=4437 execve guuid=c9457028-1a00-0000-38af-177457110000 pid=4439 /usr/bin/dash guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=c9457028-1a00-0000-38af-177457110000 pid=4439 clone guuid=d95c3a29-1a00-0000-38af-17745c110000 pid=4444 /usr/bin/rm delete-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=d95c3a29-1a00-0000-38af-17745c110000 pid=4444 execve guuid=7d8ff929-1a00-0000-38af-17745d110000 pid=4445 /usr/bin/wget net send-data write-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=7d8ff929-1a00-0000-38af-17745d110000 pid=4445 execve guuid=db1e0a40-1a00-0000-38af-1774a3110000 pid=4515 /usr/bin/chmod guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=db1e0a40-1a00-0000-38af-1774a3110000 pid=4515 execve guuid=73696640-1a00-0000-38af-1774a8110000 pid=4520 /tmp/cron.resgod guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=73696640-1a00-0000-38af-1774a8110000 pid=4520 execve guuid=5a457840-1a00-0000-38af-1774aa110000 pid=4522 /usr/bin/rm delete-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=5a457840-1a00-0000-38af-1774aa110000 pid=4522 execve guuid=6fbfd140-1a00-0000-38af-1774ab110000 pid=4523 /usr/bin/wget net send-data write-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=6fbfd140-1a00-0000-38af-1774ab110000 pid=4523 execve guuid=f9e9ac55-1a00-0000-38af-1774c7110000 pid=4551 /usr/bin/chmod guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=f9e9ac55-1a00-0000-38af-1774c7110000 pid=4551 execve guuid=5b690d56-1a00-0000-38af-1774c8110000 pid=4552 /usr/bin/dash guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=5b690d56-1a00-0000-38af-1774c8110000 pid=4552 clone guuid=f40d2557-1a00-0000-38af-1774cd110000 pid=4557 /usr/bin/rm delete-file guuid=44dc436d-1900-0000-38af-17742e0f0000 pid=3886->guuid=f40d2557-1a00-0000-38af-1774cd110000 pid=4557 execve 9df19bce-d755-5940-91ff-d0e847757959 109.205.213.5:80 guuid=0bb7736d-1900-0000-38af-17742f0f0000 pid=3887->9df19bce-d755-5940-91ff-d0e847757959 send: 140B guuid=ea42cd84-1900-0000-38af-17747c0f0000 pid=3964->9df19bce-d755-5940-91ff-d0e847757959 send: 140B guuid=fda9979b-1900-0000-38af-1774cb0f0000 pid=4043->9df19bce-d755-5940-91ff-d0e847757959 send: 139B guuid=a012f5b2-1900-0000-38af-17740c100000 pid=4108->9df19bce-d755-5940-91ff-d0e847757959 send: 140B guuid=e49ae7c9-1900-0000-38af-17744d100000 pid=4173->9df19bce-d755-5940-91ff-d0e847757959 send: 140B guuid=290741e1-1900-0000-38af-17748b100000 pid=4235->9df19bce-d755-5940-91ff-d0e847757959 send: 140B guuid=9e2aebfc-1900-0000-38af-1774e5100000 pid=4325->9df19bce-d755-5940-91ff-d0e847757959 send: 139B guuid=9d671213-1a00-0000-38af-17741d110000 pid=4381->9df19bce-d755-5940-91ff-d0e847757959 send: 139B guuid=7d8ff929-1a00-0000-38af-17745d110000 pid=4445->9df19bce-d755-5940-91ff-d0e847757959 send: 139B guuid=51547240-1a00-0000-38af-1774a9110000 pid=4521 /tmp/cron.resgod zombie guuid=73696640-1a00-0000-38af-1774a8110000 pid=4520->guuid=51547240-1a00-0000-38af-1774a9110000 pid=4521 clone guuid=859ad440-1a00-0000-38af-1774ac110000 pid=4524 /tmp/cron.resgod net zombie guuid=51547240-1a00-0000-38af-1774a9110000 pid=4521->guuid=859ad440-1a00-0000-38af-1774ac110000 pid=4524 clone guuid=6fbfd140-1a00-0000-38af-1774ab110000 pid=4523->9df19bce-d755-5940-91ff-d0e847757959 send: 139B 562c4cc4-28e6-5da6-967b-aacce467146a 109.205.213.5:1412 guuid=859ad440-1a00-0000-38af-1774ac110000 pid=4524->562c4cc4-28e6-5da6-967b-aacce467146a con
Threat name:
Linux.Worm.MiraiB
Status:
Malicious
First seen:
2025-08-24 07:09:37 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b2c013e1a80e6f3fc846031ed7e79dea445cb81615062df1f2cb36c813b9ec20

(this sample)

  
Delivery method
Distributed via web download

Comments