MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b5cbe6aee544051356e59abcde8d5e24fb74c8dde2852bd6599c3c7dec8beeaa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: b5cbe6aee544051356e59abcde8d5e24fb74c8dde2852bd6599c3c7dec8beeaa
SHA3-384 hash: e43421a88136103767b33aeea3a54ba3587209fa95d674ab4ac5eaead950dc90302e92fa75092c652618c77ce5fe85a6
SHA1 hash: f61eaaf301d5d2b0a05a8b544ff6dfc559dd36da
MD5 hash: c150ee208feb8856cbd1b41aeed68c21
humanhash: maine-romeo-ack-oregon
File name:t
Download: download sample
Signature Mirai
File size:748 bytes
First seen:2026-07-25 02:08:54 UTC
Last seen:2026-07-26 13:48:58 UTC
File type: sh
MIME type:text/plain
ssdeep 12:RRJZDxRAHWRWYBRIWOxRIWNHWRWYBRwxRbHWRWYBRA5IjDxRA5IMHWRWYBRfDxRP:3JZbiWZInIOWZgjWZA52A5hWZfbqWt
TLSH T1E4014CAFC05140D22F94F528B9520A3471045ACB39E78A8C9C4E3DBA15ED988F938E54
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://205.237.110.232/gigatex/mips7ae90d4fbada82f98d951dd3d081208e700b57eacc1a5de3b6349d4b24c1a88a Miraielf mirai ua-wget
http://205.237.110.232/gigatex/mpsln/an/aelf mirai ua-wget
http://205.237.110.232/gigatex/arm1b914dea47de55d28d56bef8068b3ea5c0a901e4d8b181db0e51148dfc670de2 Miraielf mirai ua-wget
http://205.237.110.232/gigatex/arm59fc7c1415d9a5c5343aa39ce761a8b381e7248c4e5fc38e014c652dd68222cb2 Miraielf mirai ua-wget
http://205.237.110.232/gigatex/arm7a1cdc3cadcb555302659c170e7a91e4d6e855640c1ad07c2a8239524694f6410 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
538
# of downloads :
8
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox downloader evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2026-07-25T00:18:00Z UTC
Last seen:
2026-07-25T09:39:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=2a4873ce-1600-0000-5699-65bf830c0000 pid=3203 /usr/bin/sudo guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205 /tmp/sample.bin guuid=2a4873ce-1600-0000-5699-65bf830c0000 pid=3203->guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205 execve guuid=8548e0d1-1600-0000-5699-65bf860c0000 pid=3206 /usr/bin/dash guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=8548e0d1-1600-0000-5699-65bf860c0000 pid=3206 clone guuid=a4c3e8d8-1600-0000-5699-65bf880c0000 pid=3208 /usr/bin/chmod guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=a4c3e8d8-1600-0000-5699-65bf880c0000 pid=3208 execve guuid=2fc42cd9-1600-0000-5699-65bf890c0000 pid=3209 /usr/bin/dash guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=2fc42cd9-1600-0000-5699-65bf890c0000 pid=3209 clone guuid=bbb3c7d9-1600-0000-5699-65bf8b0c0000 pid=3211 /usr/bin/rm delete-file guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=bbb3c7d9-1600-0000-5699-65bf8b0c0000 pid=3211 execve guuid=7acd0bda-1600-0000-5699-65bf8c0c0000 pid=3212 /usr/bin/dash guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=7acd0bda-1600-0000-5699-65bf8c0c0000 pid=3212 clone guuid=8c8af5de-1600-0000-5699-65bf970c0000 pid=3223 /usr/bin/chmod guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=8c8af5de-1600-0000-5699-65bf970c0000 pid=3223 execve guuid=a84a3fdf-1600-0000-5699-65bf990c0000 pid=3225 /usr/bin/dash guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=a84a3fdf-1600-0000-5699-65bf990c0000 pid=3225 clone guuid=0a22e1df-1600-0000-5699-65bf9c0c0000 pid=3228 /usr/bin/rm delete-file guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=0a22e1df-1600-0000-5699-65bf9c0c0000 pid=3228 execve guuid=cd3898e0-1600-0000-5699-65bf9e0c0000 pid=3230 /usr/bin/dash guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=cd3898e0-1600-0000-5699-65bf9e0c0000 pid=3230 clone guuid=7df8bbe5-1600-0000-5699-65bfaa0c0000 pid=3242 /usr/bin/chmod guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=7df8bbe5-1600-0000-5699-65bfaa0c0000 pid=3242 execve guuid=719fede5-1600-0000-5699-65bfac0c0000 pid=3244 /usr/bin/dash guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=719fede5-1600-0000-5699-65bfac0c0000 pid=3244 clone guuid=356f6ae6-1600-0000-5699-65bfaf0c0000 pid=3247 /usr/bin/rm delete-file guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=356f6ae6-1600-0000-5699-65bfaf0c0000 pid=3247 execve guuid=c031a4e6-1600-0000-5699-65bfb10c0000 pid=3249 /usr/bin/dash guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=c031a4e6-1600-0000-5699-65bfb10c0000 pid=3249 clone guuid=225751eb-1600-0000-5699-65bfbe0c0000 pid=3262 /usr/bin/chmod guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=225751eb-1600-0000-5699-65bfbe0c0000 pid=3262 execve guuid=915d9eeb-1600-0000-5699-65bfbf0c0000 pid=3263 /usr/bin/dash guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=915d9eeb-1600-0000-5699-65bfbf0c0000 pid=3263 clone guuid=858e65ec-1600-0000-5699-65bfc30c0000 pid=3267 /usr/bin/rm delete-file guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=858e65ec-1600-0000-5699-65bfc30c0000 pid=3267 execve guuid=1f65b4ec-1600-0000-5699-65bfc50c0000 pid=3269 /usr/bin/dash guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=1f65b4ec-1600-0000-5699-65bfc50c0000 pid=3269 clone guuid=ff20abf1-1600-0000-5699-65bfd00c0000 pid=3280 /usr/bin/chmod guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=ff20abf1-1600-0000-5699-65bfd00c0000 pid=3280 execve guuid=554210f2-1600-0000-5699-65bfd20c0000 pid=3282 /usr/bin/dash guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=554210f2-1600-0000-5699-65bfd20c0000 pid=3282 clone guuid=2cb191f2-1600-0000-5699-65bfd50c0000 pid=3285 /usr/bin/rm delete-file guuid=440c8dd1-1600-0000-5699-65bf850c0000 pid=3205->guuid=2cb191f2-1600-0000-5699-65bfd50c0000 pid=3285 execve guuid=b34ceed1-1600-0000-5699-65bf870c0000 pid=3207 /usr/bin/wget net send-data write-file guuid=8548e0d1-1600-0000-5699-65bf860c0000 pid=3206->guuid=b34ceed1-1600-0000-5699-65bf870c0000 pid=3207 execve fa76a0f2-99b2-55a3-830c-43db003be0f4 205.237.110.232:80 guuid=b34ceed1-1600-0000-5699-65bf870c0000 pid=3207->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 142B guuid=b1f013da-1600-0000-5699-65bf8d0c0000 pid=3213 /usr/bin/wget net send-data write-file guuid=7acd0bda-1600-0000-5699-65bf8c0c0000 pid=3212->guuid=b1f013da-1600-0000-5699-65bf8d0c0000 pid=3213 execve guuid=b1f013da-1600-0000-5699-65bf8d0c0000 pid=3213->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 142B guuid=78afa0e0-1600-0000-5699-65bf9f0c0000 pid=3231 /usr/bin/wget net send-data write-file guuid=cd3898e0-1600-0000-5699-65bf9e0c0000 pid=3230->guuid=78afa0e0-1600-0000-5699-65bf9f0c0000 pid=3231 execve guuid=78afa0e0-1600-0000-5699-65bf9f0c0000 pid=3231->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 141B guuid=bdc7aee6-1600-0000-5699-65bfb20c0000 pid=3250 /usr/bin/wget net send-data write-file guuid=c031a4e6-1600-0000-5699-65bfb10c0000 pid=3249->guuid=bdc7aee6-1600-0000-5699-65bfb20c0000 pid=3250 execve guuid=bdc7aee6-1600-0000-5699-65bfb20c0000 pid=3250->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 142B guuid=a28dc4ec-1600-0000-5699-65bfc60c0000 pid=3270 /usr/bin/wget net send-data write-file guuid=1f65b4ec-1600-0000-5699-65bfc50c0000 pid=3269->guuid=a28dc4ec-1600-0000-5699-65bfc60c0000 pid=3270 execve guuid=a28dc4ec-1600-0000-5699-65bfc60c0000 pid=3270->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 142B
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-25 11:08:45 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b5cbe6aee544051356e59abcde8d5e24fb74c8dde2852bd6599c3c7dec8beeaa

(this sample)

  
Delivery method
Distributed via web download

Comments