MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b46706417b0f1b6475ba53adb39054ace8e5f438d9f64a622c78b2e18fdffabe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b46706417b0f1b6475ba53adb39054ace8e5f438d9f64a622c78b2e18fdffabe
SHA3-384 hash: a09dfb7219fa8fb9d68e5343f1bfd047c19e46d048a59a07716f664bd2de541b51330f17a657600bb13abfd4a1ef97b1
SHA1 hash: ade1ab798bc2c2099ca594f567b0a5d551b8f4fa
MD5 hash: 1fde86e44e271ca3c16c5c74aac890e5
humanhash: november-vegan-single-beer
File name:c.sh
Download: download sample
Signature Mirai
File size:1'085 bytes
First seen:2025-11-12 00:30:27 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3HqxHoaLxHWNIQQAxH7vK2HxHtKAxHbHxHqxHg5xHoHxHIcAxHu3AxHJzAUn:3J3BNIeK7q8SuAdn
TLSH T1651112F82065512A23186B11B06E89396CF7F7E260329DF0907FE42361CB2917722F76
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.62/UnHAnaAW.arm22902a825f4b5e45d050e75fd997518f670dcc1ed147719e025a97334e1fcd91 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.62/UnHAnaAW.arm54bab044accc55cd8b091514d74bfb44eaaea95272ee653e93948925e24b25c7a Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.62/UnHAnaAW.arm69f32df4b92beb06bfed9f04284c434379715cfcba0a62fa6bd568928c146dfd4 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.62/UnHAnaAW.arm751bb3572999cd4a4b25fd0cc06b061674df3373767c789ceff16b677a2e4bdc5 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.62/UnHAnaAW.sh4139cf5e5c3b4a3175dfda683eaefe4e6bd5310afa3d6d679363a224a6c69feea Miraielf geofenced mirai opendir SuperH ua-wget USA
http://213.209.143.62/UnHAnaAW.ppc74e244774df73843123066181b2bb2ee1b7a62fedc22e6e936adc6e21307e42c Miraielf geofenced mirai opendir PowerPC ua-wget USA
http://213.209.143.62/UnHAnaAW.mips1aeffd0f72ac38ac1af0f86a925957eb88cff0184d6628b48ee9f452dcf8ce9c Miraielf geofenced mips mirai opendir ua-wget USA
http://213.209.143.62/UnHAnaAW.mpslf91fa8a4c5e27570471adaa1d53a68ad32a4c38f8f9f12d74bbf5614b3baaf14 Miraielf geofenced mips mirai opendir ua-wget USA
http://213.209.143.62/UnHAnaAW.spcb19d8245d8adeb27944deefd2ae7662e4bda0c3098c964e94b5326acbec78755 Miraielf geofenced mirai opendir sparc ua-wget USA
http://213.209.143.62/UnHAnaAW.x8642efa473fa16cd174a1394892b7163f4e47c0434d1138d120135451514465617 Miraielf geofenced mirai opendir ua-wget USA x86
http://213.209.143.62/UnHAnaAW.x86_645c4b64e559c1332e9f65c611909524c68ad73d63878cd6e36602c17303d0985b Miraielf geofenced mirai opendir ua-wget USA x86
http://213.209.143.62/UnHAnaAW.i586n/an/aelf

Intelligence


File Origin
# of uploads :
1
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-11-11T23:15:00Z UTC
Last seen:
2025-11-12T00:36:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=7e33adcc-1800-0000-49bd-3ba180070000 pid=1920 /usr/bin/sudo guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925 /tmp/sample.bin guuid=7e33adcc-1800-0000-49bd-3ba180070000 pid=1920->guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925 execve guuid=dfb350cf-1800-0000-49bd-3ba188070000 pid=1928 /usr/bin/curl net send-data guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=dfb350cf-1800-0000-49bd-3ba188070000 pid=1928 execve guuid=26a7cfd9-1800-0000-49bd-3ba199070000 pid=1945 /usr/bin/chmod guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=26a7cfd9-1800-0000-49bd-3ba199070000 pid=1945 execve guuid=f5b05dda-1800-0000-49bd-3ba19b070000 pid=1947 /usr/bin/dash guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=f5b05dda-1800-0000-49bd-3ba19b070000 pid=1947 clone guuid=e6db75da-1800-0000-49bd-3ba19c070000 pid=1948 /usr/bin/curl net send-data guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=e6db75da-1800-0000-49bd-3ba19c070000 pid=1948 execve guuid=30bf0ce3-1800-0000-49bd-3ba1a5070000 pid=1957 /usr/bin/chmod guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=30bf0ce3-1800-0000-49bd-3ba1a5070000 pid=1957 execve guuid=bb5956e3-1800-0000-49bd-3ba1a6070000 pid=1958 /usr/bin/dash guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=bb5956e3-1800-0000-49bd-3ba1a6070000 pid=1958 clone guuid=247e63e3-1800-0000-49bd-3ba1a7070000 pid=1959 /usr/bin/curl net send-data guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=247e63e3-1800-0000-49bd-3ba1a7070000 pid=1959 execve guuid=c40cc9e8-1800-0000-49bd-3ba1b1070000 pid=1969 /usr/bin/chmod guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=c40cc9e8-1800-0000-49bd-3ba1b1070000 pid=1969 execve guuid=eb6b68e9-1800-0000-49bd-3ba1b2070000 pid=1970 /usr/bin/dash guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=eb6b68e9-1800-0000-49bd-3ba1b2070000 pid=1970 clone guuid=fe9990e9-1800-0000-49bd-3ba1b3070000 pid=1971 /usr/bin/curl net send-data guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=fe9990e9-1800-0000-49bd-3ba1b3070000 pid=1971 execve guuid=1e2dd4f4-1800-0000-49bd-3ba1c5070000 pid=1989 /usr/bin/chmod guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=1e2dd4f4-1800-0000-49bd-3ba1c5070000 pid=1989 execve guuid=5f5335f5-1800-0000-49bd-3ba1c6070000 pid=1990 /usr/bin/dash guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=5f5335f5-1800-0000-49bd-3ba1c6070000 pid=1990 clone guuid=db133cf5-1800-0000-49bd-3ba1c7070000 pid=1991 /usr/bin/curl net send-data guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=db133cf5-1800-0000-49bd-3ba1c7070000 pid=1991 execve guuid=948ff2fa-1800-0000-49bd-3ba1c8070000 pid=1992 /usr/bin/chmod guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=948ff2fa-1800-0000-49bd-3ba1c8070000 pid=1992 execve guuid=61b055fb-1800-0000-49bd-3ba1c9070000 pid=1993 /usr/bin/dash guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=61b055fb-1800-0000-49bd-3ba1c9070000 pid=1993 clone guuid=03c274fb-1800-0000-49bd-3ba1ca070000 pid=1994 /usr/bin/curl net send-data guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=03c274fb-1800-0000-49bd-3ba1ca070000 pid=1994 execve guuid=2b113501-1900-0000-49bd-3ba1d3070000 pid=2003 /usr/bin/chmod guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=2b113501-1900-0000-49bd-3ba1d3070000 pid=2003 execve guuid=62398201-1900-0000-49bd-3ba1d4070000 pid=2004 /usr/bin/dash guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=62398201-1900-0000-49bd-3ba1d4070000 pid=2004 clone guuid=40379201-1900-0000-49bd-3ba1d5070000 pid=2005 /usr/bin/curl net send-data guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=40379201-1900-0000-49bd-3ba1d5070000 pid=2005 execve guuid=1f0a5a0a-1900-0000-49bd-3ba1e4070000 pid=2020 /usr/bin/chmod guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=1f0a5a0a-1900-0000-49bd-3ba1e4070000 pid=2020 execve guuid=51f1c70a-1900-0000-49bd-3ba1e5070000 pid=2021 /usr/bin/dash guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=51f1c70a-1900-0000-49bd-3ba1e5070000 pid=2021 clone guuid=9a44d50a-1900-0000-49bd-3ba1e6070000 pid=2022 /usr/bin/curl net send-data guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=9a44d50a-1900-0000-49bd-3ba1e6070000 pid=2022 execve guuid=8205e710-1900-0000-49bd-3ba1f0070000 pid=2032 /usr/bin/chmod guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=8205e710-1900-0000-49bd-3ba1f0070000 pid=2032 execve guuid=6a8f2f11-1900-0000-49bd-3ba1f2070000 pid=2034 /usr/bin/dash guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=6a8f2f11-1900-0000-49bd-3ba1f2070000 pid=2034 clone guuid=60903c11-1900-0000-49bd-3ba1f3070000 pid=2035 /usr/bin/curl net send-data guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=60903c11-1900-0000-49bd-3ba1f3070000 pid=2035 execve guuid=bec16918-1900-0000-49bd-3ba103080000 pid=2051 /usr/bin/chmod guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=bec16918-1900-0000-49bd-3ba103080000 pid=2051 execve guuid=3915d518-1900-0000-49bd-3ba104080000 pid=2052 /usr/bin/dash guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=3915d518-1900-0000-49bd-3ba104080000 pid=2052 clone guuid=1db0e118-1900-0000-49bd-3ba105080000 pid=2053 /usr/bin/curl net send-data guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=1db0e118-1900-0000-49bd-3ba105080000 pid=2053 execve guuid=5e98511e-1900-0000-49bd-3ba112080000 pid=2066 /usr/bin/chmod guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=5e98511e-1900-0000-49bd-3ba112080000 pid=2066 execve guuid=94669c1e-1900-0000-49bd-3ba113080000 pid=2067 /usr/bin/dash guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=94669c1e-1900-0000-49bd-3ba113080000 pid=2067 clone guuid=5488ac1e-1900-0000-49bd-3ba115080000 pid=2069 /usr/bin/curl net send-data guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=5488ac1e-1900-0000-49bd-3ba115080000 pid=2069 execve guuid=18edf522-1900-0000-49bd-3ba11f080000 pid=2079 /usr/bin/chmod guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=18edf522-1900-0000-49bd-3ba11f080000 pid=2079 execve guuid=03e44523-1900-0000-49bd-3ba121080000 pid=2081 /usr/bin/dash guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=03e44523-1900-0000-49bd-3ba121080000 pid=2081 clone guuid=79934b23-1900-0000-49bd-3ba122080000 pid=2082 /usr/bin/curl net send-data guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=79934b23-1900-0000-49bd-3ba122080000 pid=2082 execve guuid=ce8d3f27-1900-0000-49bd-3ba12d080000 pid=2093 /usr/bin/chmod guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=ce8d3f27-1900-0000-49bd-3ba12d080000 pid=2093 execve guuid=0fcd7c27-1900-0000-49bd-3ba12e080000 pid=2094 /usr/bin/dash guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=0fcd7c27-1900-0000-49bd-3ba12e080000 pid=2094 clone guuid=ab268427-1900-0000-49bd-3ba12f080000 pid=2095 /usr/bin/rm delete-file guuid=9040ecce-1800-0000-49bd-3ba185070000 pid=1925->guuid=ab268427-1900-0000-49bd-3ba12f080000 pid=2095 execve eaaaaddb-f5f1-5090-9f4d-096f63c93adc 213.209.143.62:80 guuid=dfb350cf-1800-0000-49bd-3ba188070000 pid=1928->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 90B guuid=e6db75da-1800-0000-49bd-3ba19c070000 pid=1948->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B guuid=247e63e3-1800-0000-49bd-3ba1a7070000 pid=1959->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B guuid=fe9990e9-1800-0000-49bd-3ba1b3070000 pid=1971->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B guuid=db133cf5-1800-0000-49bd-3ba1c7070000 pid=1991->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 90B guuid=03c274fb-1800-0000-49bd-3ba1ca070000 pid=1994->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 90B guuid=40379201-1900-0000-49bd-3ba1d5070000 pid=2005->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B guuid=9a44d50a-1900-0000-49bd-3ba1e6070000 pid=2022->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B guuid=60903c11-1900-0000-49bd-3ba1f3070000 pid=2035->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 90B guuid=1db0e118-1900-0000-49bd-3ba105080000 pid=2053->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 90B guuid=5488ac1e-1900-0000-49bd-3ba115080000 pid=2069->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 93B guuid=79934b23-1900-0000-49bd-3ba122080000 pid=2082->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-11-12 00:30:42 UTC
File Type:
Text
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b46706417b0f1b6475ba53adb39054ace8e5f438d9f64a622c78b2e18fdffabe

(this sample)

  
Delivery method
Distributed via web download

Comments