MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c0582c6cd2a17fe2b02548249bc6929d1201ad08bac0d1bbcbe6e91215145241. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: c0582c6cd2a17fe2b02548249bc6929d1201ad08bac0d1bbcbe6e91215145241
SHA3-384 hash: 9bd280f82045a4a7061d14f6263551e9b4dbea07cd52d15f6889ee9fa518eaf39ea73bc672e4efe8ce7fef260c77aa67
SHA1 hash: 813f03e01dcf4e96a68cf2353efb77bbae47c1a3
MD5 hash: 856a2837632518946ae0a6020b4da4e3
humanhash: early-papa-oranges-shade
File name:c0582c6cd2a17fe2b02548249bc6929d1201ad08bac0d1bbcbe6e91215145241
Download: download sample
Signature Mirai
File size:1'584 bytes
First seen:2026-07-23 21:23:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:iXuXzBDedoh90/yJVhV9fLeyep7vul/l24eF7EOIFvm:iXuXFXj0/ohV9fLeyep7w/l24SEOIFvm
TLSH T18B3143AF02145E3A1742CEDE73A23548B50C86F72DEBD7989C881EEE534878C7166BC5
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter c2hunter
Tags:mirai sh wraith
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/fd2e2fn/an/aua-wget
http://5.182.210.61/46318an/an/aua-wget
http://5.182.210.61/e9a935n/an/aua-wget
http://5.182.210.61/c9c667n/an/aua-wget
http://5.182.210.61/915582n/an/aua-wget
http://5.182.210.61/86c2fen/an/aua-wget
http://5.182.210.61/00f5fan/an/aua-wget
http://5.182.210.61/5110d4n/an/aua-wget
http://5.182.210.61/657761n/an/aua-wget
http://5.182.210.61/861d9dn/an/aua-wget
http://5.182.210.61/cbff42n/an/aua-wget
http://5.182.210.61/c36308n/an/aua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-23T19:32:00Z UTC
Last seen:
2026-07-24T18:22:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a9f9287f-1800-0000-b65f-31a2c0100000 pid=4288 /usr/bin/sudo guuid=3bdbc380-1800-0000-b65f-31a2c7100000 pid=4295 /tmp/sample.bin guuid=a9f9287f-1800-0000-b65f-31a2c0100000 pid=4288->guuid=3bdbc380-1800-0000-b65f-31a2c7100000 pid=4295 execve guuid=d4012c81-1800-0000-b65f-31a2c9100000 pid=4297 /usr/bin/wget guuid=3bdbc380-1800-0000-b65f-31a2c7100000 pid=4295->guuid=d4012c81-1800-0000-b65f-31a2c9100000 pid=4297 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-23 21:24:13 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Unexpected DNS network traffic destination
Family: Mirai
Malware Config
C2 Extraction:
m4ch.ru
141.98.10.50
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments