MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c4880ba6c4d19629349f8d7621e6211f858cbfc57d0832807e11a4e68b3216dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: c4880ba6c4d19629349f8d7621e6211f858cbfc57d0832807e11a4e68b3216dd
SHA3-384 hash: 4f00584f82f12df1bbf48cf6b39e830f483787df2bc21718cf901dd2692fa7a4a0c010d14ced6144c98142e8c72cf3eb
SHA1 hash: a53fca2a3f64f7d0065220ae1b2a30a251510174
MD5 hash: 51eb958850d26d794b11b51e17eb8224
humanhash: football-oven-purple-hotel
File name:router.zyxel.sh
Download: download sample
Signature Mirai
File size:1'337 bytes
First seen:2025-08-19 19:13:15 UTC
Last seen:2025-08-20 12:30:44 UTC
File type: sh
MIME type:text/plain
ssdeep 12:Ktv60EtaLld6zEt16CEtXWzUf6KMtXTmz6KYEtqaOEd61tR6ZtX6nt5Vd6ttCt/N:30gzPCxRzjHbQ2CKt/e3J/zgIiJea
TLSH T1E721F59EA85C7105F1F9CB91B813D7809F4DC5A79DD02F01A78C7836C78ED04F925A89
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.121.84.24/kitty.armv7ld2e3797d560655d10343c8749c8b5764fad4e198922fb2eeb926d0d118336086 Miraimirai
http://87.121.84.24/kitty.armv6lb972934f1394eae72964b3f04c46274261545ae8228eb486cde8c3e412e08cc3 Miraimirai
http://87.121.84.24/kitty.armv5l97b4d91cdf8381fd41328dfe32f3a251b534dd9f113ac9ec9f846d3addf04101 Miraimirai
http://87.121.84.24/kitty.mipsc812b4f50d1288e9b517b6537de95de6aac192cf046be6b724f2d281a03c8868 Miraimirai
http://87.121.84.24/kitty.mipsel939235c603e1ed8b025723acd727bb1172ead9c1b2732c65118430e8df89f42f Miraimirai
http://87.121.84.24/kitty.aarch648ce935a8bb49a62aa1820e6b9fe9ed7a5443ff7b52dc9b3cd61a51312268786d Miraimirai
http://87.121.84.24/kitty.i68622e0da690218ce29ecd3a2e009b4b4132213a78e9ac55df412449fdc974730c4 Miraimirai
http://87.121.84.24/kitty.i486ed431df063607e4eb0d0727ed1be114f86ca0e1e7f8ccf3cc342257e7ffd8c20 Miraimirai
http://87.121.84.24/kitty.x86_6456ec330679baad3e92d2ee3a4a7e8b4eb2264dc580f5c5d96cab80381a00fe9c Miraimirai
http://87.121.84.24/kitty.powerpc621cd88f72054e15eebba7a81a790b92eb31909e3162d0e9ab39075dc713056a Miraimirai
http://87.121.84.24/kitty.powerpc644205d66932386177580f0c3ef524a89c6716c56ee27248ca38b5f1945270a8be Miraimirai
http://87.121.84.24/kitty.m68k9badc17fbdb06c26c0c1681674fe8f28fa9e60be812a8a99b73177296184e1ff Miraimirai

Intelligence


File Origin
# of uploads :
3
# of downloads :
26
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=98952dd7-1800-0000-fb24-e5bc060a0000 pid=2566 /usr/bin/sudo guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572 /tmp/sample.bin guuid=98952dd7-1800-0000-fb24-e5bc060a0000 pid=2566->guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572 execve guuid=20a451d9-1800-0000-fb24-e5bc0e0a0000 pid=2574 /usr/bin/wget net send-data write-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=20a451d9-1800-0000-fb24-e5bc0e0a0000 pid=2574 execve guuid=303f25e3-1800-0000-fb24-e5bc2e0a0000 pid=2606 /usr/bin/chmod guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=303f25e3-1800-0000-fb24-e5bc2e0a0000 pid=2606 execve guuid=9f9167e3-1800-0000-fb24-e5bc300a0000 pid=2608 /usr/bin/dash guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=9f9167e3-1800-0000-fb24-e5bc300a0000 pid=2608 clone guuid=980dfde3-1800-0000-fb24-e5bc340a0000 pid=2612 /usr/bin/rm delete-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=980dfde3-1800-0000-fb24-e5bc340a0000 pid=2612 execve guuid=895633e4-1800-0000-fb24-e5bc350a0000 pid=2613 /usr/bin/wget net send-data write-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=895633e4-1800-0000-fb24-e5bc350a0000 pid=2613 execve guuid=587138ea-1800-0000-fb24-e5bc480a0000 pid=2632 /usr/bin/chmod guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=587138ea-1800-0000-fb24-e5bc480a0000 pid=2632 execve guuid=aa717fea-1800-0000-fb24-e5bc4a0a0000 pid=2634 /usr/bin/dash guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=aa717fea-1800-0000-fb24-e5bc4a0a0000 pid=2634 clone guuid=b358f1ea-1800-0000-fb24-e5bc4e0a0000 pid=2638 /usr/bin/rm delete-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=b358f1ea-1800-0000-fb24-e5bc4e0a0000 pid=2638 execve guuid=62f62ceb-1800-0000-fb24-e5bc500a0000 pid=2640 /usr/bin/wget net send-data write-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=62f62ceb-1800-0000-fb24-e5bc500a0000 pid=2640 execve guuid=55f70af6-1800-0000-fb24-e5bc730a0000 pid=2675 /usr/bin/chmod guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=55f70af6-1800-0000-fb24-e5bc730a0000 pid=2675 execve guuid=20214cf6-1800-0000-fb24-e5bc750a0000 pid=2677 /usr/bin/dash guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=20214cf6-1800-0000-fb24-e5bc750a0000 pid=2677 clone guuid=35e6daf7-1800-0000-fb24-e5bc7a0a0000 pid=2682 /usr/bin/rm delete-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=35e6daf7-1800-0000-fb24-e5bc7a0a0000 pid=2682 execve guuid=7f2117f8-1800-0000-fb24-e5bc7c0a0000 pid=2684 /usr/bin/wget net send-data write-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=7f2117f8-1800-0000-fb24-e5bc7c0a0000 pid=2684 execve guuid=38e5a2fe-1800-0000-fb24-e5bc910a0000 pid=2705 /usr/bin/chmod guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=38e5a2fe-1800-0000-fb24-e5bc910a0000 pid=2705 execve guuid=082fdefe-1800-0000-fb24-e5bc920a0000 pid=2706 /usr/bin/dash guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=082fdefe-1800-0000-fb24-e5bc920a0000 pid=2706 clone guuid=773258ff-1800-0000-fb24-e5bc960a0000 pid=2710 /usr/bin/rm delete-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=773258ff-1800-0000-fb24-e5bc960a0000 pid=2710 execve guuid=7b0794ff-1800-0000-fb24-e5bc980a0000 pid=2712 /usr/bin/wget net send-data write-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=7b0794ff-1800-0000-fb24-e5bc980a0000 pid=2712 execve guuid=b8a3f20a-1900-0000-fb24-e5bcbb0a0000 pid=2747 /usr/bin/chmod guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=b8a3f20a-1900-0000-fb24-e5bcbb0a0000 pid=2747 execve guuid=d9e62d0b-1900-0000-fb24-e5bcbc0a0000 pid=2748 /usr/bin/dash guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=d9e62d0b-1900-0000-fb24-e5bcbc0a0000 pid=2748 clone guuid=c324ee0c-1900-0000-fb24-e5bcc10a0000 pid=2753 /usr/bin/rm delete-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=c324ee0c-1900-0000-fb24-e5bcc10a0000 pid=2753 execve guuid=49cb270d-1900-0000-fb24-e5bcc30a0000 pid=2755 /usr/bin/wget net send-data write-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=49cb270d-1900-0000-fb24-e5bcc30a0000 pid=2755 execve guuid=b1039d12-1900-0000-fb24-e5bcce0a0000 pid=2766 /usr/bin/chmod guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=b1039d12-1900-0000-fb24-e5bcce0a0000 pid=2766 execve guuid=95dfd512-1900-0000-fb24-e5bcd00a0000 pid=2768 /usr/bin/dash guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=95dfd512-1900-0000-fb24-e5bcd00a0000 pid=2768 clone guuid=8ff25e13-1900-0000-fb24-e5bcd30a0000 pid=2771 /usr/bin/rm delete-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=8ff25e13-1900-0000-fb24-e5bcd30a0000 pid=2771 execve guuid=94d89913-1900-0000-fb24-e5bcd50a0000 pid=2773 /usr/bin/wget net send-data write-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=94d89913-1900-0000-fb24-e5bcd50a0000 pid=2773 execve guuid=8bae5318-1900-0000-fb24-e5bcde0a0000 pid=2782 /usr/bin/chmod guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=8bae5318-1900-0000-fb24-e5bcde0a0000 pid=2782 execve guuid=d847ad18-1900-0000-fb24-e5bce00a0000 pid=2784 /tmp/kitty.i686 guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=d847ad18-1900-0000-fb24-e5bce00a0000 pid=2784 execve guuid=b0b7ca18-1900-0000-fb24-e5bce30a0000 pid=2787 /usr/bin/rm guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=b0b7ca18-1900-0000-fb24-e5bce30a0000 pid=2787 execve guuid=1a101e19-1900-0000-fb24-e5bce60a0000 pid=2790 /usr/bin/wget guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=1a101e19-1900-0000-fb24-e5bce60a0000 pid=2790 execve guuid=f2065819-1900-0000-fb24-e5bce80a0000 pid=2792 /usr/bin/chmod guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=f2065819-1900-0000-fb24-e5bce80a0000 pid=2792 execve guuid=2a14a619-1900-0000-fb24-e5bcea0a0000 pid=2794 /usr/bin/dash guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=2a14a619-1900-0000-fb24-e5bcea0a0000 pid=2794 clone guuid=5759b019-1900-0000-fb24-e5bceb0a0000 pid=2795 /usr/bin/rm guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=5759b019-1900-0000-fb24-e5bceb0a0000 pid=2795 execve guuid=270af219-1900-0000-fb24-e5bcec0a0000 pid=2796 /usr/bin/wget net send-data write-file guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=270af219-1900-0000-fb24-e5bcec0a0000 pid=2796 execve guuid=dc6a7620-1900-0000-fb24-e5bcf50a0000 pid=2805 /usr/bin/chmod guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=dc6a7620-1900-0000-fb24-e5bcf50a0000 pid=2805 execve guuid=18089d20-1900-0000-fb24-e5bcf60a0000 pid=2806 /usr/bin/dash guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=18089d20-1900-0000-fb24-e5bcf60a0000 pid=2806 clone guuid=b2eda620-1900-0000-fb24-e5bcf70a0000 pid=2807 /usr/bin/rm guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=b2eda620-1900-0000-fb24-e5bcf70a0000 pid=2807 execve guuid=a6d6b820-1900-0000-fb24-e5bcf90a0000 pid=2809 /usr/bin/wget guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=a6d6b820-1900-0000-fb24-e5bcf90a0000 pid=2809 execve guuid=75afdd20-1900-0000-fb24-e5bcfa0a0000 pid=2810 /usr/bin/chmod guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=75afdd20-1900-0000-fb24-e5bcfa0a0000 pid=2810 execve guuid=fb592021-1900-0000-fb24-e5bcfc0a0000 pid=2812 /usr/bin/dash guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=fb592021-1900-0000-fb24-e5bcfc0a0000 pid=2812 clone guuid=22b42c21-1900-0000-fb24-e5bcfd0a0000 pid=2813 /usr/bin/rm guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=22b42c21-1900-0000-fb24-e5bcfd0a0000 pid=2813 execve guuid=db066721-1900-0000-fb24-e5bcff0a0000 pid=2815 /usr/bin/wget guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=db066721-1900-0000-fb24-e5bcff0a0000 pid=2815 execve guuid=c7937c21-1900-0000-fb24-e5bc000b0000 pid=2816 /usr/bin/chmod guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=c7937c21-1900-0000-fb24-e5bc000b0000 pid=2816 execve guuid=b95eb721-1900-0000-fb24-e5bc020b0000 pid=2818 /usr/bin/dash guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=b95eb721-1900-0000-fb24-e5bc020b0000 pid=2818 clone guuid=41e8c221-1900-0000-fb24-e5bc030b0000 pid=2819 /usr/bin/rm guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=41e8c221-1900-0000-fb24-e5bc030b0000 pid=2819 execve guuid=dbedfa21-1900-0000-fb24-e5bc040b0000 pid=2820 /usr/bin/wget guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=dbedfa21-1900-0000-fb24-e5bc040b0000 pid=2820 execve guuid=2f6d1022-1900-0000-fb24-e5bc050b0000 pid=2821 /usr/bin/chmod guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=2f6d1022-1900-0000-fb24-e5bc050b0000 pid=2821 execve guuid=ee885222-1900-0000-fb24-e5bc060b0000 pid=2822 /usr/bin/dash guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=ee885222-1900-0000-fb24-e5bc060b0000 pid=2822 clone guuid=f3205e22-1900-0000-fb24-e5bc070b0000 pid=2823 /usr/bin/rm guuid=421619d9-1800-0000-fb24-e5bc0c0a0000 pid=2572->guuid=f3205e22-1900-0000-fb24-e5bc070b0000 pid=2823 execve 24e69ce0-a918-556e-bb6f-805920d5782b 87.121.84.24:80 guuid=20a451d9-1800-0000-fb24-e5bc0e0a0000 pid=2574->24e69ce0-a918-556e-bb6f-805920d5782b send: 139B guuid=895633e4-1800-0000-fb24-e5bc350a0000 pid=2613->24e69ce0-a918-556e-bb6f-805920d5782b send: 139B guuid=62f62ceb-1800-0000-fb24-e5bc500a0000 pid=2640->24e69ce0-a918-556e-bb6f-805920d5782b send: 139B guuid=7f2117f8-1800-0000-fb24-e5bc7c0a0000 pid=2684->24e69ce0-a918-556e-bb6f-805920d5782b send: 137B guuid=7b0794ff-1800-0000-fb24-e5bc980a0000 pid=2712->24e69ce0-a918-556e-bb6f-805920d5782b send: 139B guuid=49cb270d-1900-0000-fb24-e5bcc30a0000 pid=2755->24e69ce0-a918-556e-bb6f-805920d5782b send: 140B guuid=94d89913-1900-0000-fb24-e5bcd50a0000 pid=2773->24e69ce0-a918-556e-bb6f-805920d5782b send: 137B guuid=32c8c118-1900-0000-fb24-e5bce10a0000 pid=2785 /tmp/kitty.i686 guuid=d847ad18-1900-0000-fb24-e5bce00a0000 pid=2784->guuid=32c8c118-1900-0000-fb24-e5bce10a0000 pid=2785 clone guuid=09bacb18-1900-0000-fb24-e5bce40a0000 pid=2788 /tmp/kitty.i686 delete-file net send-data zombie guuid=32c8c118-1900-0000-fb24-e5bce10a0000 pid=2785->guuid=09bacb18-1900-0000-fb24-e5bce40a0000 pid=2788 clone eb9dca7b-d301-522e-83c7-8d6f291efc38 66.78.40.221:9080 guuid=09bacb18-1900-0000-fb24-e5bce40a0000 pid=2788->eb9dca7b-d301-522e-83c7-8d6f291efc38 send: 70B b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=09bacb18-1900-0000-fb24-e5bce40a0000 pid=2788->b4bf20d4-f7c8-5c24-8830-c23364537aa4 send: 40B 6a6ce952-23cd-5c51-b461-6ca6a8c64225 1.0.0.1:53 guuid=09bacb18-1900-0000-fb24-e5bce40a0000 pid=2788->6a6ce952-23cd-5c51-b461-6ca6a8c64225 send: 40B guuid=09bacb18-1900-0000-fb24-e5bce40a0000 pid=2789 /tmp/kitty.i686 zombie guuid=09bacb18-1900-0000-fb24-e5bce40a0000 pid=2788->guuid=09bacb18-1900-0000-fb24-e5bce40a0000 pid=2789 clone guuid=270af219-1900-0000-fb24-e5bcec0a0000 pid=2796->24e69ce0-a918-556e-bb6f-805920d5782b send: 139B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-08-17 23:38:21 UTC
File Type:
Text (Shell)
AV detection:
18 of 38 (47.37%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c4880ba6c4d19629349f8d7621e6211f858cbfc57d0832807e11a4e68b3216dd

(this sample)

  
Delivery method
Distributed via web download

Comments