🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b2c96866f5b990bfdcbcf07c913a4a0b99da60e56ee80753d0c3d1097f4ee578. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: b2c96866f5b990bfdcbcf07c913a4a0b99da60e56ee80753d0c3d1097f4ee578
SHA3-384 hash: 806fd36da82850148067d46d623d7317c2044fd2ba4a9badc3c283353baccdba2d8412065cea6b55d06c273ff022a70a
SHA1 hash: 3c63f1d5da7b566d6382f7f50ebc31b55d3b0d8c
MD5 hash: b28cfddcd242c3f509c1e3bbbc60ea79
humanhash: black-apart-berlin-island
File name:zy.sh
Download: download sample
Signature Mirai
File size:985 bytes
First seen:2025-08-23 07:52:32 UTC
Last seen:2025-08-23 14:45:37 UTC
File type: sh
MIME type:text/plain
ssdeep 24:GIbr5zOt+MB09WH0ektgk07ktgK0Bktgm70Bktgl00ktv:jr5CEA09ikkkckLYkCkd
TLSH T15A119ECC5A62AC72EDA96E88B7224428D0CDC4D5318FCDC4E2C94537D4DD5043593B7A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.51.126.131/v/armv4le333d6098ba7af114b4e8b290f0e587592067b8e153798bf4763262d2074ad96 Miraielf mirai ua-wget
http://158.51.126.131/v/armv5l79d810e67c7bd6c6669214c1c4b631829d90726886b4167a232813d8434ef3f7 Miraielf mirai ua-wget
http://158.51.126.131/v/armv7lc3788d92bfc3a08dbcca4476832c46b099bcad182c56cdbccf837eb0edb6cd77 Miraielf mirai ua-wget
http://158.51.126.131/v/mipsd4e2e83716082a12346f565d13cc06546a099a05725f194c135f7b3839473a6c Miraielf mirai ua-wget
http://158.51.126.131/v/mipsel8db391280f5fda83a9dc476d69d093827bb72b3a90c3112679855eacabb996e1 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
ps1
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=72d3b17c-1a00-0000-47db-ac86b60b0000 pid=2998 /usr/bin/sudo guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004 /tmp/sample.bin guuid=72d3b17c-1a00-0000-47db-ac86b60b0000 pid=2998->guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004 execve guuid=57e6fd80-1a00-0000-47db-ac86be0b0000 pid=3006 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=57e6fd80-1a00-0000-47db-ac86be0b0000 pid=3006 clone guuid=0cdd2882-1a00-0000-47db-ac86c60b0000 pid=3014 /usr/bin/rm delete-file guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=0cdd2882-1a00-0000-47db-ac86c60b0000 pid=3014 execve guuid=3d636882-1a00-0000-47db-ac86c80b0000 pid=3016 /usr/bin/rm delete-file guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=3d636882-1a00-0000-47db-ac86c80b0000 pid=3016 execve guuid=6d5bbc82-1a00-0000-47db-ac86c90b0000 pid=3017 /usr/bin/rm delete-file guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=6d5bbc82-1a00-0000-47db-ac86c90b0000 pid=3017 execve guuid=39caff82-1a00-0000-47db-ac86cb0b0000 pid=3019 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=39caff82-1a00-0000-47db-ac86cb0b0000 pid=3019 clone guuid=61364b84-1a00-0000-47db-ac86d00b0000 pid=3024 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=61364b84-1a00-0000-47db-ac86d00b0000 pid=3024 clone guuid=37cf9784-1a00-0000-47db-ac86d20b0000 pid=3026 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=37cf9784-1a00-0000-47db-ac86d20b0000 pid=3026 clone guuid=f77803ac-1a00-0000-47db-ac863e0c0000 pid=3134 /usr/bin/chmod guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=f77803ac-1a00-0000-47db-ac863e0c0000 pid=3134 execve guuid=87dc4dac-1a00-0000-47db-ac86400c0000 pid=3136 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=87dc4dac-1a00-0000-47db-ac86400c0000 pid=3136 clone guuid=73dbe0ac-1a00-0000-47db-ac86430c0000 pid=3139 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=73dbe0ac-1a00-0000-47db-ac86430c0000 pid=3139 clone guuid=c52805dc-1a00-0000-47db-ac868b0c0000 pid=3211 /usr/bin/chmod guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=c52805dc-1a00-0000-47db-ac868b0c0000 pid=3211 execve guuid=38ad51dc-1a00-0000-47db-ac868d0c0000 pid=3213 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=38ad51dc-1a00-0000-47db-ac868d0c0000 pid=3213 clone guuid=f58211dd-1a00-0000-47db-ac86910c0000 pid=3217 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=f58211dd-1a00-0000-47db-ac86910c0000 pid=3217 clone guuid=32455a09-1b00-0000-47db-ac86b70c0000 pid=3255 /usr/bin/chmod guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=32455a09-1b00-0000-47db-ac86b70c0000 pid=3255 execve guuid=d600bb09-1b00-0000-47db-ac86b90c0000 pid=3257 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=d600bb09-1b00-0000-47db-ac86b90c0000 pid=3257 clone guuid=d6823b0c-1b00-0000-47db-ac86bc0c0000 pid=3260 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=d6823b0c-1b00-0000-47db-ac86bc0c0000 pid=3260 clone guuid=35e0a739-1b00-0000-47db-ac86000d0000 pid=3328 /usr/bin/chmod guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=35e0a739-1b00-0000-47db-ac86000d0000 pid=3328 execve guuid=ea15e539-1b00-0000-47db-ac86020d0000 pid=3330 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=ea15e539-1b00-0000-47db-ac86020d0000 pid=3330 clone guuid=d3e37f3a-1b00-0000-47db-ac86060d0000 pid=3334 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=d3e37f3a-1b00-0000-47db-ac86060d0000 pid=3334 clone guuid=8a8c2b66-1b00-0000-47db-ac864d0d0000 pid=3405 /usr/bin/chmod guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=8a8c2b66-1b00-0000-47db-ac864d0d0000 pid=3405 execve guuid=8d259766-1b00-0000-47db-ac864f0d0000 pid=3407 /usr/bin/dash guuid=53479680-1a00-0000-47db-ac86bc0b0000 pid=3004->guuid=8d259766-1b00-0000-47db-ac864f0d0000 pid=3407 clone guuid=8c4c0c81-1a00-0000-47db-ac86bf0b0000 pid=3007 /usr/bin/cat guuid=57e6fd80-1a00-0000-47db-ac86be0b0000 pid=3006->guuid=8c4c0c81-1a00-0000-47db-ac86bf0b0000 pid=3007 execve guuid=be371881-1a00-0000-47db-ac86c00b0000 pid=3008 /usr/bin/grep guuid=57e6fd80-1a00-0000-47db-ac86be0b0000 pid=3006->guuid=be371881-1a00-0000-47db-ac86c00b0000 pid=3008 execve guuid=3ea51d81-1a00-0000-47db-ac86c10b0000 pid=3009 /usr/bin/grep guuid=57e6fd80-1a00-0000-47db-ac86be0b0000 pid=3006->guuid=3ea51d81-1a00-0000-47db-ac86c10b0000 pid=3009 execve guuid=a3eb2581-1a00-0000-47db-ac86c20b0000 pid=3010 /usr/bin/grep guuid=57e6fd80-1a00-0000-47db-ac86be0b0000 pid=3006->guuid=a3eb2581-1a00-0000-47db-ac86c20b0000 pid=3010 execve guuid=ff913681-1a00-0000-47db-ac86c30b0000 pid=3011 /usr/bin/cut guuid=57e6fd80-1a00-0000-47db-ac86be0b0000 pid=3006->guuid=ff913681-1a00-0000-47db-ac86c30b0000 pid=3011 execve guuid=fa0c0883-1a00-0000-47db-ac86cc0b0000 pid=3020 /usr/bin/cp write-file guuid=39caff82-1a00-0000-47db-ac86cb0b0000 pid=3019->guuid=fa0c0883-1a00-0000-47db-ac86cc0b0000 pid=3020 execve guuid=d2095784-1a00-0000-47db-ac86d10b0000 pid=3025 /usr/bin/chmod guuid=61364b84-1a00-0000-47db-ac86d00b0000 pid=3024->guuid=d2095784-1a00-0000-47db-ac86d10b0000 pid=3025 execve guuid=23dfa084-1a00-0000-47db-ac86d30b0000 pid=3027 /usr/bin/curl net send-data write-file guuid=37cf9784-1a00-0000-47db-ac86d20b0000 pid=3026->guuid=23dfa084-1a00-0000-47db-ac86d30b0000 pid=3027 execve 2beca644-24da-5e18-bc49-c06b8c4a111d 158.51.126.131:80 guuid=23dfa084-1a00-0000-47db-ac86d30b0000 pid=3027->2beca644-24da-5e18-bc49-c06b8c4a111d send: 86B guuid=a664ebac-1a00-0000-47db-ac86440c0000 pid=3140 /usr/bin/curl net send-data write-file guuid=73dbe0ac-1a00-0000-47db-ac86430c0000 pid=3139->guuid=a664ebac-1a00-0000-47db-ac86440c0000 pid=3140 execve guuid=a664ebac-1a00-0000-47db-ac86440c0000 pid=3140->2beca644-24da-5e18-bc49-c06b8c4a111d send: 86B guuid=fc3a19dd-1a00-0000-47db-ac86920c0000 pid=3218 /usr/bin/curl net send-data write-file guuid=f58211dd-1a00-0000-47db-ac86910c0000 pid=3217->guuid=fc3a19dd-1a00-0000-47db-ac86920c0000 pid=3218 execve guuid=fc3a19dd-1a00-0000-47db-ac86920c0000 pid=3218->2beca644-24da-5e18-bc49-c06b8c4a111d send: 86B guuid=db654c0c-1b00-0000-47db-ac86bd0c0000 pid=3261 /usr/bin/curl net send-data write-file guuid=d6823b0c-1b00-0000-47db-ac86bc0c0000 pid=3260->guuid=db654c0c-1b00-0000-47db-ac86bd0c0000 pid=3261 execve guuid=db654c0c-1b00-0000-47db-ac86bd0c0000 pid=3261->2beca644-24da-5e18-bc49-c06b8c4a111d send: 84B guuid=0342893a-1b00-0000-47db-ac86070d0000 pid=3335 /usr/bin/curl net send-data write-file guuid=d3e37f3a-1b00-0000-47db-ac86060d0000 pid=3334->guuid=0342893a-1b00-0000-47db-ac86070d0000 pid=3335 execve guuid=0342893a-1b00-0000-47db-ac86070d0000 pid=3335->2beca644-24da-5e18-bc49-c06b8c4a111d send: 86B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-08-23 07:53:36 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b2c96866f5b990bfdcbcf07c913a4a0b99da60e56ee80753d0c3d1097f4ee578

(this sample)

  
Delivery method
Distributed via web download

Comments