MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bbc2e14c07d5ee19ca4886d63c92ea610ae277ee7be26fc650bee5b801c13584. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bbc2e14c07d5ee19ca4886d63c92ea610ae277ee7be26fc650bee5b801c13584
SHA3-384 hash: e97fa31bf366a958d2b1d1f24601c51c089f21bc05fe9c4377c80600021f2f2926b56251d6139ba5ba0df4e032d83247
SHA1 hash: 07271940327df085e023085ebb71f6d9e9ba7cb3
MD5 hash: 85f6ad31941c2aabba9fbac8b1e7c423
humanhash: washington-winter-failed-seven
File name:w.sh
Download: download sample
Signature Mirai
File size:931 bytes
First seen:2025-11-23 10:10:31 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:oXYEJNIl5E0LKmv+Ob9jMZT5tSOXtTRebR:YYEJNI7HKe+YjSTDlXtTR2R
TLSH T1A71160CEF2B162A205804DE5B0698838A534E7D432508F5EDCDD08FA91E5A687277E6D
Magika txt
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
26
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive mirai
Status:
terminated
Behavior Graph:
%3 guuid=d95ddcf2-1900-0000-d35d-547f7a0b0000 pid=2938 /usr/bin/sudo guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946 /tmp/sample.bin guuid=d95ddcf2-1900-0000-d35d-547f7a0b0000 pid=2938->guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946 execve guuid=90aa86f5-1900-0000-d35d-547f830b0000 pid=2947 /usr/bin/busybox net send-data write-file guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=90aa86f5-1900-0000-d35d-547f830b0000 pid=2947 execve guuid=18f7470b-1a00-0000-d35d-547fb30b0000 pid=2995 /usr/bin/chmod guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=18f7470b-1a00-0000-d35d-547fb30b0000 pid=2995 execve guuid=fe59c80b-1a00-0000-d35d-547fb40b0000 pid=2996 /usr/bin/dash guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=fe59c80b-1a00-0000-d35d-547fb40b0000 pid=2996 clone guuid=bb74200e-1a00-0000-d35d-547fb90b0000 pid=3001 /usr/bin/busybox net send-data write-file guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=bb74200e-1a00-0000-d35d-547fb90b0000 pid=3001 execve guuid=9504e923-1a00-0000-d35d-547ff00b0000 pid=3056 /usr/bin/chmod guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=9504e923-1a00-0000-d35d-547ff00b0000 pid=3056 execve guuid=b5185024-1a00-0000-d35d-547ff20b0000 pid=3058 /usr/bin/dash guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=b5185024-1a00-0000-d35d-547ff20b0000 pid=3058 clone guuid=c6345b26-1a00-0000-d35d-547ff80b0000 pid=3064 /usr/bin/busybox net send-data write-file guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=c6345b26-1a00-0000-d35d-547ff80b0000 pid=3064 execve guuid=c9615f44-1a00-0000-d35d-547f440c0000 pid=3140 /usr/bin/chmod guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=c9615f44-1a00-0000-d35d-547f440c0000 pid=3140 execve guuid=b3799544-1a00-0000-d35d-547f460c0000 pid=3142 /usr/bin/dash guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=b3799544-1a00-0000-d35d-547f460c0000 pid=3142 clone guuid=f0bde645-1a00-0000-d35d-547f4c0c0000 pid=3148 /usr/bin/busybox net send-data write-file guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=f0bde645-1a00-0000-d35d-547f4c0c0000 pid=3148 execve guuid=76893664-1a00-0000-d35d-547f730c0000 pid=3187 /usr/bin/chmod guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=76893664-1a00-0000-d35d-547f730c0000 pid=3187 execve guuid=35b5b864-1a00-0000-d35d-547f740c0000 pid=3188 /usr/bin/dash guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=35b5b864-1a00-0000-d35d-547f740c0000 pid=3188 clone guuid=233d5865-1a00-0000-d35d-547f760c0000 pid=3190 /usr/bin/busybox net send-data write-file guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=233d5865-1a00-0000-d35d-547f760c0000 pid=3190 execve guuid=741ae086-1a00-0000-d35d-547f9b0c0000 pid=3227 /usr/bin/chmod guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=741ae086-1a00-0000-d35d-547f9b0c0000 pid=3227 execve guuid=08de5487-1a00-0000-d35d-547f9c0c0000 pid=3228 /usr/bin/dash guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=08de5487-1a00-0000-d35d-547f9c0c0000 pid=3228 clone guuid=bebd3989-1a00-0000-d35d-547f9e0c0000 pid=3230 /usr/bin/busybox net send-data write-file guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=bebd3989-1a00-0000-d35d-547f9e0c0000 pid=3230 execve guuid=d22d01a7-1a00-0000-d35d-547fbe0c0000 pid=3262 /usr/bin/chmod guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=d22d01a7-1a00-0000-d35d-547fbe0c0000 pid=3262 execve guuid=896963a7-1a00-0000-d35d-547fc00c0000 pid=3264 /usr/bin/dash guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=896963a7-1a00-0000-d35d-547fc00c0000 pid=3264 clone guuid=90da54a9-1a00-0000-d35d-547fc50c0000 pid=3269 /usr/bin/busybox net send-data write-file guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=90da54a9-1a00-0000-d35d-547fc50c0000 pid=3269 execve guuid=9cc7f3c6-1a00-0000-d35d-547ffa0c0000 pid=3322 /usr/bin/chmod guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=9cc7f3c6-1a00-0000-d35d-547ffa0c0000 pid=3322 execve guuid=e9ed33c7-1a00-0000-d35d-547ffb0c0000 pid=3323 /usr/bin/dash guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=e9ed33c7-1a00-0000-d35d-547ffb0c0000 pid=3323 clone guuid=cf4b92c8-1a00-0000-d35d-547f000d0000 pid=3328 /usr/bin/busybox net send-data write-file guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=cf4b92c8-1a00-0000-d35d-547f000d0000 pid=3328 execve guuid=cd0311df-1a00-0000-d35d-547f240d0000 pid=3364 /usr/bin/chmod guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=cd0311df-1a00-0000-d35d-547f240d0000 pid=3364 execve guuid=b0315bdf-1a00-0000-d35d-547f250d0000 pid=3365 /usr/bin/dash guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=b0315bdf-1a00-0000-d35d-547f250d0000 pid=3365 clone guuid=9d0001e0-1a00-0000-d35d-547f270d0000 pid=3367 /usr/bin/busybox net send-data guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=9d0001e0-1a00-0000-d35d-547f270d0000 pid=3367 execve guuid=825696ee-1a00-0000-d35d-547f4b0d0000 pid=3403 /usr/bin/chmod guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=825696ee-1a00-0000-d35d-547f4b0d0000 pid=3403 execve guuid=38abedee-1a00-0000-d35d-547f4d0d0000 pid=3405 /usr/bin/dash guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=38abedee-1a00-0000-d35d-547f4d0d0000 pid=3405 clone guuid=762dfbee-1a00-0000-d35d-547f4e0d0000 pid=3406 /usr/bin/busybox net send-data guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=762dfbee-1a00-0000-d35d-547f4e0d0000 pid=3406 execve guuid=917613fe-1a00-0000-d35d-547f760d0000 pid=3446 /usr/bin/chmod guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=917613fe-1a00-0000-d35d-547f760d0000 pid=3446 execve guuid=94bbb5fe-1a00-0000-d35d-547f780d0000 pid=3448 /usr/bin/dash guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=94bbb5fe-1a00-0000-d35d-547f780d0000 pid=3448 clone guuid=6822cbfe-1a00-0000-d35d-547f790d0000 pid=3449 /usr/bin/busybox net send-data write-file guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=6822cbfe-1a00-0000-d35d-547f790d0000 pid=3449 execve guuid=55eb7c15-1b00-0000-d35d-547fbc0d0000 pid=3516 /usr/bin/chmod guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=55eb7c15-1b00-0000-d35d-547fbc0d0000 pid=3516 execve guuid=fdfeeb15-1b00-0000-d35d-547fbd0d0000 pid=3517 /home/sandbox/x86 net guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=fdfeeb15-1b00-0000-d35d-547fbd0d0000 pid=3517 execve guuid=eebb642f-1b00-0000-d35d-547fee0d0000 pid=3566 /usr/bin/busybox net send-data write-file guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=eebb642f-1b00-0000-d35d-547fee0d0000 pid=3566 execve guuid=82df1d4f-1b00-0000-d35d-547f160e0000 pid=3606 /usr/bin/chmod guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=82df1d4f-1b00-0000-d35d-547f160e0000 pid=3606 execve guuid=c8ee8e4f-1b00-0000-d35d-547f180e0000 pid=3608 /home/sandbox/x86_64 net guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=c8ee8e4f-1b00-0000-d35d-547f180e0000 pid=3608 execve guuid=c162186b-1b00-0000-d35d-547f500e0000 pid=3664 /usr/bin/rm delete-file guuid=87d74cf5-1900-0000-d35d-547f820b0000 pid=2946->guuid=c162186b-1b00-0000-d35d-547f500e0000 pid=3664 execve 9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 38.107.233.38:80 guuid=90aa86f5-1900-0000-d35d-547f830b0000 pid=2947->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 88B guuid=bb74200e-1a00-0000-d35d-547fb90b0000 pid=3001->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 89B guuid=c6345b26-1a00-0000-d35d-547ff80b0000 pid=3064->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 89B guuid=f0bde645-1a00-0000-d35d-547f4c0c0000 pid=3148->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 89B guuid=233d5865-1a00-0000-d35d-547f760c0000 pid=3190->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 89B guuid=bebd3989-1a00-0000-d35d-547f9e0c0000 pid=3230->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 89B guuid=90da54a9-1a00-0000-d35d-547fc50c0000 pid=3269->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 89B guuid=cf4b92c8-1a00-0000-d35d-547f000d0000 pid=3328->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 88B guuid=9d0001e0-1a00-0000-d35d-547f270d0000 pid=3367->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 88B guuid=762dfbee-1a00-0000-d35d-547f4e0d0000 pid=3406->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 88B guuid=6822cbfe-1a00-0000-d35d-547f790d0000 pid=3449->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=fdfeeb15-1b00-0000-d35d-547fbd0d0000 pid=3517->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=776a562f-1b00-0000-d35d-547fec0d0000 pid=3564 /home/sandbox/x86 guuid=fdfeeb15-1b00-0000-d35d-547fbd0d0000 pid=3517->guuid=776a562f-1b00-0000-d35d-547fec0d0000 pid=3564 clone guuid=829c5c2f-1b00-0000-d35d-547fed0d0000 pid=3565 /home/sandbox/x86 dns net send-data zombie guuid=fdfeeb15-1b00-0000-d35d-547fbd0d0000 pid=3517->guuid=829c5c2f-1b00-0000-d35d-547fed0d0000 pid=3565 clone guuid=829c5c2f-1b00-0000-d35d-547fed0d0000 pid=3565->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 42B 92baddd7-8a81-534e-9407-4c1f931774f6 ahahahahahajs.unproxy.st:9772 guuid=829c5c2f-1b00-0000-d35d-547fed0d0000 pid=3565->92baddd7-8a81-534e-9407-4c1f931774f6 send: 42B guuid=eebb642f-1b00-0000-d35d-547fee0d0000 pid=3566->9aec39e1-7b9f-53b3-9ac2-65f3c52fc566 send: 91B guuid=c8ee8e4f-1b00-0000-d35d-547f180e0000 pid=3608->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4c0e086b-1b00-0000-d35d-547f4e0e0000 pid=3662 /home/sandbox/x86_64 zombie guuid=c8ee8e4f-1b00-0000-d35d-547f180e0000 pid=3608->guuid=4c0e086b-1b00-0000-d35d-547f4e0e0000 pid=3662 clone guuid=6fa80e6b-1b00-0000-d35d-547f4f0e0000 pid=3663 /home/sandbox/x86_64 dns net send-data zombie guuid=c8ee8e4f-1b00-0000-d35d-547f180e0000 pid=3608->guuid=6fa80e6b-1b00-0000-d35d-547f4f0e0000 pid=3663 clone guuid=6fa80e6b-1b00-0000-d35d-547f4f0e0000 pid=3663->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 42B guuid=6fa80e6b-1b00-0000-d35d-547f4f0e0000 pid=3663->92baddd7-8a81-534e-9407-4c1f931774f6 send: 47B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-11-23 05:16:19 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh bbc2e14c07d5ee19ca4886d63c92ea610ae277ee7be26fc650bee5b801c13584

(this sample)

  
Delivery method
Distributed via web download

Comments