MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb86434907dc86071af8122bb77f81ad1e3ee6934397aa43f77af62a988406b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: bb86434907dc86071af8122bb77f81ad1e3ee6934397aa43f77af62a988406b9
SHA3-384 hash: 1a3aa44c4592d802417f19abdd143add703a0db0f04c02f146ec5ee83859ff717ac35c90199d288e0629541e86b6d2ac
SHA1 hash: 7d41ec916c400b7a852823f5248871511bfe076b
MD5 hash: bda31a5a948d30f0ab0c88fb73bc771e
humanhash: july-enemy-item-west
File name:curl.sh
Download: download sample
Signature Mirai
File size:858 bytes
First seen:2025-06-20 11:01:48 UTC
Last seen:2025-06-21 09:32:29 UTC
File type: sh
MIME type:text/plain
ssdeep 24:3J3McsVkcs5PcsZNIqKcsMKxhcsAFcsAEcsAoycsIRv/WRCcsD1xTcsXmcsBf:qdVkd5PdFKdMShdAFdAEdAoydIlWcdLw
TLSH T1F611CE9C1095724A5B2DCFCBB35D8B086A40CAE4B4FDDAB5FA344832849F110B028B1B
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.149.252.178/bot.arm93eb8e223410f702c1be6d9388205a25066cd8ee5c669e1e0954eed51b61d99c Miraielf mirai ua-wget
http://103.149.252.178/bot.arm567ba445f4d39c217eb3911c0b41ed7e4ca87c175535b1f08501e8d157c2bbd26 Miraielf mirai ua-wget
http://103.149.252.178/bot.arm661f1709d5d81bc6a521d005312751b7cfa5e5efa4a87b36c78d1df6a56166243 Miraielf mirai ua-wget
http://103.149.252.178/bot.arm799145d8a8d2bd7a401a9fac5ffc9413987eb507fd8f35b0be2d1641f285f4baa Miraielf mirai ua-wget
http://103.149.252.178/bot.m68k269ee46bd65dd8c96ad5ea5872ba50f12572714521430f410e73046afc372cee Miraielf mirai ua-wget
http://103.149.252.178/bot.mipse3b227f81a4eb81c43b5764316f3632fd41367cbb0706951b2375f43f906e8ff Miraielf mirai ua-wget
http://103.149.252.178/bot.mpsl9f1f56a03f2046fa18c79a9505f2a9fbb5272549da3eb9507b3495602246be54 Miraielf mirai ua-wget
http://103.149.252.178/bot.powerpcn/an/an/a
http://103.149.252.178/bot.sh4db65c6ad097c998d7cab2fd9bce177aa17f74a8179ac36a67c62f845285612b0 Miraielf mirai ua-wget
http://103.149.252.178/bot.x864427f663b9ef45d01d7925efe57d5670b5e27efc3e35c61abdda4786b681066d Miraielf mirai ua-wget
http://103.149.252.178/bot.x86_64dcf79d68228bb95fe49c4e3a9d0167aaef4abd8946bae55855d825b68b19cc26 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
63
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
downloader trojan agent
Status:
terminated
Behavior Graph:
%3 guuid=1c55dd04-1800-0000-2a26-d36806090000 pid=2310 /usr/bin/sudo guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313 /tmp/sample.bin guuid=1c55dd04-1800-0000-2a26-d36806090000 pid=2310->guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313 execve guuid=3857d207-1800-0000-2a26-d3680a090000 pid=2314 /usr/bin/curl net send-data guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=3857d207-1800-0000-2a26-d3680a090000 pid=2314 execve guuid=3b0b0c52-1800-0000-2a26-d368b0090000 pid=2480 /usr/bin/chmod guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=3b0b0c52-1800-0000-2a26-d368b0090000 pid=2480 execve guuid=7f4a9952-1800-0000-2a26-d368b2090000 pid=2482 /usr/bin/dash guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=7f4a9952-1800-0000-2a26-d368b2090000 pid=2482 clone guuid=b1c4a652-1800-0000-2a26-d368b3090000 pid=2483 /usr/bin/curl net send-data guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=b1c4a652-1800-0000-2a26-d368b3090000 pid=2483 execve guuid=ca09cf98-1800-0000-2a26-d368830a0000 pid=2691 /usr/bin/chmod guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=ca09cf98-1800-0000-2a26-d368830a0000 pid=2691 execve guuid=ebc50d99-1800-0000-2a26-d368850a0000 pid=2693 /usr/bin/dash guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=ebc50d99-1800-0000-2a26-d368850a0000 pid=2693 clone guuid=ce151a99-1800-0000-2a26-d368860a0000 pid=2694 /usr/bin/curl net send-data guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=ce151a99-1800-0000-2a26-d368860a0000 pid=2694 execve guuid=d5207fdf-1800-0000-2a26-d368f70a0000 pid=2807 /usr/bin/chmod guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=d5207fdf-1800-0000-2a26-d368f70a0000 pid=2807 execve guuid=f89d08e0-1800-0000-2a26-d368f80a0000 pid=2808 /usr/bin/dash guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=f89d08e0-1800-0000-2a26-d368f80a0000 pid=2808 clone guuid=a89f23e0-1800-0000-2a26-d368f90a0000 pid=2809 /usr/bin/curl net send-data guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=a89f23e0-1800-0000-2a26-d368f90a0000 pid=2809 execve guuid=63235b2c-1900-0000-2a26-d368880b0000 pid=2952 /usr/bin/chmod guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=63235b2c-1900-0000-2a26-d368880b0000 pid=2952 execve guuid=497da22c-1900-0000-2a26-d3688a0b0000 pid=2954 /usr/bin/dash guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=497da22c-1900-0000-2a26-d3688a0b0000 pid=2954 clone guuid=484ab72c-1900-0000-2a26-d3688b0b0000 pid=2955 /usr/bin/curl net send-data guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=484ab72c-1900-0000-2a26-d3688b0b0000 pid=2955 execve guuid=e8d05979-1900-0000-2a26-d368490c0000 pid=3145 /usr/bin/chmod guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=e8d05979-1900-0000-2a26-d368490c0000 pid=3145 execve guuid=e67fa679-1900-0000-2a26-d3684a0c0000 pid=3146 /usr/bin/dash guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=e67fa679-1900-0000-2a26-d3684a0c0000 pid=3146 clone guuid=14e9b279-1900-0000-2a26-d3684b0c0000 pid=3147 /usr/bin/curl net send-data guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=14e9b279-1900-0000-2a26-d3684b0c0000 pid=3147 execve guuid=5c2effbf-1900-0000-2a26-d3686b0c0000 pid=3179 /usr/bin/chmod guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=5c2effbf-1900-0000-2a26-d3686b0c0000 pid=3179 execve guuid=aba08bc0-1900-0000-2a26-d3686c0c0000 pid=3180 /usr/bin/dash guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=aba08bc0-1900-0000-2a26-d3686c0c0000 pid=3180 clone guuid=b2b79ac0-1900-0000-2a26-d3686d0c0000 pid=3181 /usr/bin/curl net send-data guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=b2b79ac0-1900-0000-2a26-d3686d0c0000 pid=3181 execve guuid=45a13108-1a00-0000-2a26-d368bf0c0000 pid=3263 /usr/bin/chmod guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=45a13108-1a00-0000-2a26-d368bf0c0000 pid=3263 execve guuid=bd0fa308-1a00-0000-2a26-d368c10c0000 pid=3265 /usr/bin/dash guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=bd0fa308-1a00-0000-2a26-d368c10c0000 pid=3265 clone guuid=5e37b708-1a00-0000-2a26-d368c20c0000 pid=3266 /usr/bin/curl net send-data guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=5e37b708-1a00-0000-2a26-d368c20c0000 pid=3266 execve guuid=6eda4329-1a00-0000-2a26-d368070d0000 pid=3335 /usr/bin/chmod guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=6eda4329-1a00-0000-2a26-d368070d0000 pid=3335 execve guuid=19738029-1a00-0000-2a26-d368090d0000 pid=3337 /usr/bin/dash guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=19738029-1a00-0000-2a26-d368090d0000 pid=3337 clone guuid=f4458629-1a00-0000-2a26-d3680a0d0000 pid=3338 /usr/bin/curl net send-data guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=f4458629-1a00-0000-2a26-d3680a0d0000 pid=3338 execve guuid=9103ef71-1a00-0000-2a26-d368d10d0000 pid=3537 /usr/bin/chmod guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=9103ef71-1a00-0000-2a26-d368d10d0000 pid=3537 execve guuid=33075f72-1a00-0000-2a26-d368d20d0000 pid=3538 /usr/bin/dash guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=33075f72-1a00-0000-2a26-d368d20d0000 pid=3538 clone guuid=968e6c72-1a00-0000-2a26-d368d30d0000 pid=3539 /usr/bin/curl net send-data guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=968e6c72-1a00-0000-2a26-d368d30d0000 pid=3539 execve guuid=a3253aad-1a00-0000-2a26-d3685a0e0000 pid=3674 /usr/bin/chmod guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=a3253aad-1a00-0000-2a26-d3685a0e0000 pid=3674 execve guuid=d28fa3ad-1a00-0000-2a26-d3685b0e0000 pid=3675 /usr/bin/dash guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=d28fa3ad-1a00-0000-2a26-d3685b0e0000 pid=3675 clone guuid=2c99b0ad-1a00-0000-2a26-d3685c0e0000 pid=3676 /usr/bin/curl net send-data guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=2c99b0ad-1a00-0000-2a26-d3685c0e0000 pid=3676 execve guuid=779cd2f6-1a00-0000-2a26-d368470f0000 pid=3911 /usr/bin/chmod guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=779cd2f6-1a00-0000-2a26-d368470f0000 pid=3911 execve guuid=fd981ef7-1a00-0000-2a26-d3684a0f0000 pid=3914 /usr/bin/dash guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=fd981ef7-1a00-0000-2a26-d3684a0f0000 pid=3914 clone guuid=a3ca25f7-1a00-0000-2a26-d3684b0f0000 pid=3915 /usr/bin/rm delete-file guuid=bff55f07-1800-0000-2a26-d36809090000 pid=2313->guuid=a3ca25f7-1a00-0000-2a26-d3684b0f0000 pid=3915 execve b95ce511-3591-5114-995b-9ce77bb440cb 103.149.252.178:80 guuid=3857d207-1800-0000-2a26-d3680a090000 pid=2314->b95ce511-3591-5114-995b-9ce77bb440cb send: 86B guuid=b1c4a652-1800-0000-2a26-d368b3090000 pid=2483->b95ce511-3591-5114-995b-9ce77bb440cb send: 87B guuid=ce151a99-1800-0000-2a26-d368860a0000 pid=2694->b95ce511-3591-5114-995b-9ce77bb440cb send: 87B guuid=a89f23e0-1800-0000-2a26-d368f90a0000 pid=2809->b95ce511-3591-5114-995b-9ce77bb440cb send: 87B guuid=484ab72c-1900-0000-2a26-d3688b0b0000 pid=2955->b95ce511-3591-5114-995b-9ce77bb440cb send: 87B guuid=14e9b279-1900-0000-2a26-d3684b0c0000 pid=3147->b95ce511-3591-5114-995b-9ce77bb440cb send: 87B guuid=b2b79ac0-1900-0000-2a26-d3686d0c0000 pid=3181->b95ce511-3591-5114-995b-9ce77bb440cb send: 87B guuid=5e37b708-1a00-0000-2a26-d368c20c0000 pid=3266->b95ce511-3591-5114-995b-9ce77bb440cb send: 90B guuid=f4458629-1a00-0000-2a26-d3680a0d0000 pid=3338->b95ce511-3591-5114-995b-9ce77bb440cb send: 86B guuid=968e6c72-1a00-0000-2a26-d368d30d0000 pid=3539->b95ce511-3591-5114-995b-9ce77bb440cb send: 86B guuid=2c99b0ad-1a00-0000-2a26-d3685c0e0000 pid=3676->b95ce511-3591-5114-995b-9ce77bb440cb send: 89B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-06-20 11:03:20 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh bb86434907dc86071af8122bb77f81ad1e3ee6934397aa43f77af62a988406b9

(this sample)

  
Delivery method
Distributed via web download

Comments