MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd6c602f90687a7215402aa880024ace9e2df920733c39b16d02caef7488097f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: bd6c602f90687a7215402aa880024ace9e2df920733c39b16d02caef7488097f
SHA3-384 hash: fec28b1756fdf2ad87d90e6a5f235ba55dc0149700e71a57e5478c0d33984a5cd4ada7f0819e9bb860c1e74b2c7646b3
SHA1 hash: 2861aca301bc8ca05bd0a51358d0332e6a17f2ef
MD5 hash: 98ac42751623f32f8b1b800329e2ca16
humanhash: jupiter-speaker-pasta-saturn
File name:8pr95K9.sh
Download: download sample
Signature Mirai
File size:3'586 bytes
First seen:2026-03-17 19:21:11 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:IXDurDKDWHbVLIf7wZDNwt5wFkt5wsePj4JxUrHG/tq4rcQ2cDUTWIduz4sGs:IXGW+LiUZDCOsIDYoypDUTHe9
TLSH T15171E7CDE0E063746CDDDE6332BB9944B540A48614C27F689ECC34F2598FE85648EB82
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://178.16.54.73/1MstuFfwhCXulrIe663a4312de309f96b41c5fc13cbc672e3fc901231549354d529410a46c5953b Miraielf mirai ua-wget
http://178.16.54.73/aPG03YviN7x462f2fbb527f9a086e9cf23bd80c3ce7f74f673de58b4258b14d2ccac6134c0196 Miraielf mirai ua-wget
http://178.16.54.73/nN5oWS8MHN04Ygtb6a05e2244a46eca59671bad97f27846eaaca8beb3d915dae39140969612650c Miraielf mirai ua-wget
http://178.16.54.73/rHSgIuc6bWCRNhnI3444490e3044cb9f9c8eebade13d23de7530dc848e8cbeec2ed98c8210af12d4 Miraielf mirai ua-wget
http://178.16.54.73/D6B8YmcOcvmdInZ77cebd4c3451c365ecd8ae3cec19d34dd32b27a0fa50bd03e7347f0bc4b053fd8 Miraielf mirai ua-wget
http://178.16.54.73/O2KseZ2Rs2kK4F3920d8143477ec76be6bb791c96d88e7d65cd928a9a96907990eff0cb56c5aaf Miraielf mirai ua-wget
http://178.16.54.73/FZXSOupfc3xz7c576c16ba57b38bb0b51613059f6ee9afad77ec7b4c1d15f8a1203da6989d48 Miraielf mirai ua-wget
http://178.16.54.73/cwpj9HGq8KjAUVTUaa01d67acbcbddda7acd553b700e9aa5172d716266e68fc245bcf28f66eb56d1 Miraielf mirai ua-wget
http://178.16.54.73/zGA6GUqtaiYtKVd1ca90b03cc79e7b4627518021a2d3b304e8a0a157494b797964a4dfc3eb2e23 Miraielf mirai ua-wget
http://178.16.54.73/mOv9lSkDu5BYI30ad659a251eb5ddbbd0d7892425386d4ebc70b7bd1ada8cb2fe7a83f9206f44e Miraielf mirai ua-wget
http://178.16.54.73/F3yJCc1PmcByE3DUNEqZ5n8c2f0301b28eaab1e35d1620fd6c5179f51956641e6791b5e5f877fd7ed184fc Miraielf mirai ua-wget
http://178.16.54.73/N9OXfQc1EvrvIymQ8c87f8e1095c827cc036fe352fe22e285ac8e6d3602bf7cd12db3311b67d319f Miraielf mirai ua-wget
http://178.16.54.73/7lmqyBAjov9oMU29f20243292cc7287ac1e24a4bd2c7976ac94fbcd1669be8a39502c6c329a3d6 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 busybox evasive expand lolbin medusa mirai
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=629d44ca-1800-0000-c97e-3a3d32060000 pid=1586 /usr/bin/sudo guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592 /tmp/sample.bin guuid=629d44ca-1800-0000-c97e-3a3d32060000 pid=1586->guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592 execve guuid=b19ab8de-1800-0000-c97e-3a3d69060000 pid=1641 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=b19ab8de-1800-0000-c97e-3a3d69060000 pid=1641 execve guuid=5d5209df-1800-0000-c97e-3a3d6b060000 pid=1643 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=5d5209df-1800-0000-c97e-3a3d6b060000 pid=1643 execve guuid=55e621e8-1800-0000-c97e-3a3d84060000 pid=1668 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=55e621e8-1800-0000-c97e-3a3d84060000 pid=1668 execve guuid=62db6ce8-1800-0000-c97e-3a3d86060000 pid=1670 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=62db6ce8-1800-0000-c97e-3a3d86060000 pid=1670 clone guuid=3d4a92e8-1800-0000-c97e-3a3d87060000 pid=1671 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=3d4a92e8-1800-0000-c97e-3a3d87060000 pid=1671 execve guuid=d99d08e9-1800-0000-c97e-3a3d89060000 pid=1673 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=d99d08e9-1800-0000-c97e-3a3d89060000 pid=1673 execve guuid=6f6537ef-1800-0000-c97e-3a3d9c060000 pid=1692 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=6f6537ef-1800-0000-c97e-3a3d9c060000 pid=1692 execve guuid=7b159def-1800-0000-c97e-3a3d9e060000 pid=1694 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=7b159def-1800-0000-c97e-3a3d9e060000 pid=1694 clone guuid=a903d2ef-1800-0000-c97e-3a3da0060000 pid=1696 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=a903d2ef-1800-0000-c97e-3a3da0060000 pid=1696 execve guuid=b4bd59f0-1800-0000-c97e-3a3da2060000 pid=1698 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=b4bd59f0-1800-0000-c97e-3a3da2060000 pid=1698 execve guuid=a993caf6-1800-0000-c97e-3a3db3060000 pid=1715 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=a993caf6-1800-0000-c97e-3a3db3060000 pid=1715 execve guuid=8abb19f7-1800-0000-c97e-3a3db5060000 pid=1717 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=8abb19f7-1800-0000-c97e-3a3db5060000 pid=1717 clone guuid=8aa92cf7-1800-0000-c97e-3a3db6060000 pid=1718 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=8aa92cf7-1800-0000-c97e-3a3db6060000 pid=1718 execve guuid=ab1cc2f7-1800-0000-c97e-3a3db8060000 pid=1720 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=ab1cc2f7-1800-0000-c97e-3a3db8060000 pid=1720 execve guuid=2b330bfe-1800-0000-c97e-3a3dc7060000 pid=1735 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=2b330bfe-1800-0000-c97e-3a3dc7060000 pid=1735 execve guuid=201754fe-1800-0000-c97e-3a3dc9060000 pid=1737 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=201754fe-1800-0000-c97e-3a3dc9060000 pid=1737 clone guuid=e0e16efe-1800-0000-c97e-3a3dca060000 pid=1738 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=e0e16efe-1800-0000-c97e-3a3dca060000 pid=1738 execve guuid=68b4bbfe-1800-0000-c97e-3a3dcc060000 pid=1740 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=68b4bbfe-1800-0000-c97e-3a3dcc060000 pid=1740 execve guuid=fbf87c04-1900-0000-c97e-3a3ddd060000 pid=1757 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=fbf87c04-1900-0000-c97e-3a3ddd060000 pid=1757 execve guuid=90fcd504-1900-0000-c97e-3a3dde060000 pid=1758 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=90fcd504-1900-0000-c97e-3a3dde060000 pid=1758 clone guuid=dd23fa04-1900-0000-c97e-3a3ddf060000 pid=1759 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=dd23fa04-1900-0000-c97e-3a3ddf060000 pid=1759 execve guuid=61414005-1900-0000-c97e-3a3de1060000 pid=1761 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=61414005-1900-0000-c97e-3a3de1060000 pid=1761 execve guuid=ca50610b-1900-0000-c97e-3a3df1060000 pid=1777 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=ca50610b-1900-0000-c97e-3a3df1060000 pid=1777 execve guuid=12a8aa0b-1900-0000-c97e-3a3df3060000 pid=1779 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=12a8aa0b-1900-0000-c97e-3a3df3060000 pid=1779 clone guuid=3cf2c10b-1900-0000-c97e-3a3df5060000 pid=1781 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=3cf2c10b-1900-0000-c97e-3a3df5060000 pid=1781 execve guuid=5290100c-1900-0000-c97e-3a3df7060000 pid=1783 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=5290100c-1900-0000-c97e-3a3df7060000 pid=1783 execve guuid=aaa20412-1900-0000-c97e-3a3d06070000 pid=1798 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=aaa20412-1900-0000-c97e-3a3d06070000 pid=1798 execve guuid=9e697612-1900-0000-c97e-3a3d07070000 pid=1799 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=9e697612-1900-0000-c97e-3a3d07070000 pid=1799 clone guuid=107a9f12-1900-0000-c97e-3a3d08070000 pid=1800 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=107a9f12-1900-0000-c97e-3a3d08070000 pid=1800 execve guuid=e18d2813-1900-0000-c97e-3a3d09070000 pid=1801 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=e18d2813-1900-0000-c97e-3a3d09070000 pid=1801 execve guuid=e5bbab1a-1900-0000-c97e-3a3d16070000 pid=1814 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=e5bbab1a-1900-0000-c97e-3a3d16070000 pid=1814 execve guuid=2fbdea1a-1900-0000-c97e-3a3d17070000 pid=1815 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=2fbdea1a-1900-0000-c97e-3a3d17070000 pid=1815 clone guuid=7af8121b-1900-0000-c97e-3a3d18070000 pid=1816 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=7af8121b-1900-0000-c97e-3a3d18070000 pid=1816 execve guuid=33ff5a1b-1900-0000-c97e-3a3d1a070000 pid=1818 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=33ff5a1b-1900-0000-c97e-3a3d1a070000 pid=1818 execve guuid=a0c54e21-1900-0000-c97e-3a3d29070000 pid=1833 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=a0c54e21-1900-0000-c97e-3a3d29070000 pid=1833 execve guuid=e9639821-1900-0000-c97e-3a3d2b070000 pid=1835 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=e9639821-1900-0000-c97e-3a3d2b070000 pid=1835 clone guuid=4827ac21-1900-0000-c97e-3a3d2c070000 pid=1836 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=4827ac21-1900-0000-c97e-3a3d2c070000 pid=1836 execve guuid=696d0622-1900-0000-c97e-3a3d2e070000 pid=1838 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=696d0622-1900-0000-c97e-3a3d2e070000 pid=1838 execve guuid=e520b727-1900-0000-c97e-3a3d3c070000 pid=1852 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=e520b727-1900-0000-c97e-3a3d3c070000 pid=1852 execve guuid=88131128-1900-0000-c97e-3a3d3e070000 pid=1854 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=88131128-1900-0000-c97e-3a3d3e070000 pid=1854 clone guuid=e3cc3228-1900-0000-c97e-3a3d3f070000 pid=1855 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=e3cc3228-1900-0000-c97e-3a3d3f070000 pid=1855 execve guuid=7ac17a28-1900-0000-c97e-3a3d41070000 pid=1857 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=7ac17a28-1900-0000-c97e-3a3d41070000 pid=1857 execve guuid=92cb3d2e-1900-0000-c97e-3a3d50070000 pid=1872 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=92cb3d2e-1900-0000-c97e-3a3d50070000 pid=1872 execve guuid=bd2c922e-1900-0000-c97e-3a3d51070000 pid=1873 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=bd2c922e-1900-0000-c97e-3a3d51070000 pid=1873 clone guuid=deeca92e-1900-0000-c97e-3a3d52070000 pid=1874 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=deeca92e-1900-0000-c97e-3a3d52070000 pid=1874 execve guuid=1efa062f-1900-0000-c97e-3a3d54070000 pid=1876 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=1efa062f-1900-0000-c97e-3a3d54070000 pid=1876 execve guuid=7f915d35-1900-0000-c97e-3a3d64070000 pid=1892 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=7f915d35-1900-0000-c97e-3a3d64070000 pid=1892 execve guuid=0d8dad35-1900-0000-c97e-3a3d65070000 pid=1893 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=0d8dad35-1900-0000-c97e-3a3d65070000 pid=1893 clone guuid=ecf6cc35-1900-0000-c97e-3a3d67070000 pid=1895 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=ecf6cc35-1900-0000-c97e-3a3d67070000 pid=1895 execve guuid=9d371e36-1900-0000-c97e-3a3d68070000 pid=1896 /usr/bin/wget net send-data guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=9d371e36-1900-0000-c97e-3a3d68070000 pid=1896 execve guuid=6622bb3c-1900-0000-c97e-3a3d77070000 pid=1911 /usr/bin/chmod guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=6622bb3c-1900-0000-c97e-3a3d77070000 pid=1911 execve guuid=3aa4133d-1900-0000-c97e-3a3d78070000 pid=1912 /usr/bin/bash guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=3aa4133d-1900-0000-c97e-3a3d78070000 pid=1912 clone guuid=d483363d-1900-0000-c97e-3a3d79070000 pid=1913 /usr/bin/rm guuid=72fa6bcc-1800-0000-c97e-3a3d38060000 pid=1592->guuid=d483363d-1900-0000-c97e-3a3d79070000 pid=1913 execve f5f94e0b-aab7-5a34-a212-b0a801bf3658 178.16.54.73:80 guuid=5d5209df-1800-0000-c97e-3a3d6b060000 pid=1643->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 142B guuid=d99d08e9-1800-0000-c97e-3a3d89060000 pid=1673->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 140B guuid=b4bd59f0-1800-0000-c97e-3a3da2060000 pid=1698->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 142B guuid=ab1cc2f7-1800-0000-c97e-3a3db8060000 pid=1720->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 143B guuid=68b4bbfe-1800-0000-c97e-3a3dcc060000 pid=1740->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 143B guuid=61414005-1900-0000-c97e-3a3de1060000 pid=1761->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 141B guuid=5290100c-1900-0000-c97e-3a3df7060000 pid=1783->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 139B guuid=e18d2813-1900-0000-c97e-3a3d09070000 pid=1801->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 143B guuid=33ff5a1b-1900-0000-c97e-3a3d1a070000 pid=1818->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 141B guuid=696d0622-1900-0000-c97e-3a3d2e070000 pid=1838->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 141B guuid=7ac17a28-1900-0000-c97e-3a3d41070000 pid=1857->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 149B guuid=1efa062f-1900-0000-c97e-3a3d54070000 pid=1876->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 143B guuid=9d371e36-1900-0000-c97e-3a3d68070000 pid=1896->f5f94e0b-aab7-5a34-a212-b0a801bf3658 send: 141B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-17 19:22:21 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Creates/modifies Cron job
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Renames itself
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:UNK_install_script
Author:evilcel3ri
Description:Detects a suspicious behaviour in an bash installation script

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh bd6c602f90687a7215402aa880024ace9e2df920733c39b16d02caef7488097f

(this sample)

  
Delivery method
Distributed via web download

Comments