MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c48c252e93de1a98c786d08919c28ef4bf791e3bdbfef352a405bd3527467949. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: c48c252e93de1a98c786d08919c28ef4bf791e3bdbfef352a405bd3527467949
SHA3-384 hash: a563e944ef0c4b86f9050c325d21a242a080f58ab04f3809f228cd762d0f5a85c9120226728b10a196436c7e8d845601
SHA1 hash: de290fc8487e018e554b21681e1e6c2c08a28a8e
MD5 hash: 916787c5f5790108aeaf58f498ae283e
humanhash: mirror-river-island-leopard
File name:curl.sh
Download: download sample
Signature Mirai
File size:728 bytes
First seen:2025-07-06 10:54:01 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3u6DnwpuYH9auYxF2uYsQeidTCznSiVJwSk7htz0vn:3J37nisFQvdTCr7LwP91gn
TLSH T10A01DBA85061FE77022CFEA5F571575FB040E5889BAD0794AE23082ECCF9E5232A4656
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://107.150.0.18/arc4359113534cf666f893a5ce7336f975534f8af5657fca37c75bada98e6827021 Miraigafgyt mirai
http://107.150.0.18/armfd2cf8bb6373bb98a0f19a32d4c393eff037016419a22911e9e1359c9569e30c Miraigafgyt mirai
http://107.150.0.18/arm516806f28aaad7c2dc699939441f08788c60da41f368603d3366e79f1fc065f52 Miraigafgyt mirai
http://107.150.0.18/arm764af8d1f8d71f6c797d93436b6a74f2c4afd557ad0a8ea2608cd5d0397ee1434 Miraigafgyt mirai
http://107.150.0.18/mips31a91d1bddc9cd5ab38b8dcfbbba30d251bf7b6e360ac2b39f98ce8485e2d0e6 Miraigafgyt mirai
http://107.150.0.18/mpsl6d93024a640c6a3a2976c7e03c223cb15fd3d17a60b7ef03a62786826a45b7cd Miraigafgyt mirai
http://107.150.0.18/ppc3488891c6f2bba610e5b9e33f30bf8c8fa2268789d12d91a457dc147bd61c35b Miraigafgyt mirai
http://107.150.0.18/sh40851b040a2284df51949fa24ffc1bddea5a5b0ad4385e472585dcaed3322ad88 Miraigafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
26
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=da9c4baf-1900-0000-ad4a-120cad090000 pid=2477 /usr/bin/sudo guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481 /tmp/sample.bin guuid=da9c4baf-1900-0000-ad4a-120cad090000 pid=2477->guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481 execve guuid=640cdab2-1900-0000-ad4a-120cb3090000 pid=2483 /usr/bin/curl net send-data write-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=640cdab2-1900-0000-ad4a-120cb3090000 pid=2483 execve guuid=ed6c91d6-1900-0000-ad4a-120cf3090000 pid=2547 /usr/bin/chmod guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=ed6c91d6-1900-0000-ad4a-120cf3090000 pid=2547 execve guuid=2867e4d6-1900-0000-ad4a-120cf5090000 pid=2549 /usr/bin/dash guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=2867e4d6-1900-0000-ad4a-120cf5090000 pid=2549 clone guuid=e2ecced7-1900-0000-ad4a-120cf9090000 pid=2553 /usr/bin/rm delete-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=e2ecced7-1900-0000-ad4a-120cf9090000 pid=2553 execve guuid=480c3fd8-1900-0000-ad4a-120cfc090000 pid=2556 /usr/bin/curl net send-data write-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=480c3fd8-1900-0000-ad4a-120cfc090000 pid=2556 execve guuid=347a5600-1a00-0000-ad4a-120c6b0a0000 pid=2667 /usr/bin/chmod guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=347a5600-1a00-0000-ad4a-120c6b0a0000 pid=2667 execve guuid=5e529800-1a00-0000-ad4a-120c6c0a0000 pid=2668 /usr/bin/dash guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=5e529800-1a00-0000-ad4a-120c6c0a0000 pid=2668 clone guuid=fb569f01-1a00-0000-ad4a-120c700a0000 pid=2672 /usr/bin/rm delete-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=fb569f01-1a00-0000-ad4a-120c700a0000 pid=2672 execve guuid=3648e101-1a00-0000-ad4a-120c720a0000 pid=2674 /usr/bin/curl net send-data write-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=3648e101-1a00-0000-ad4a-120c720a0000 pid=2674 execve guuid=506bc921-1a00-0000-ad4a-120ccd0a0000 pid=2765 /usr/bin/chmod guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=506bc921-1a00-0000-ad4a-120ccd0a0000 pid=2765 execve guuid=97bb0a22-1a00-0000-ad4a-120cce0a0000 pid=2766 /usr/bin/dash guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=97bb0a22-1a00-0000-ad4a-120cce0a0000 pid=2766 clone guuid=9a319a22-1a00-0000-ad4a-120cd10a0000 pid=2769 /usr/bin/rm delete-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=9a319a22-1a00-0000-ad4a-120cd10a0000 pid=2769 execve guuid=5be2e222-1a00-0000-ad4a-120cd30a0000 pid=2771 /usr/bin/curl net send-data write-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=5be2e222-1a00-0000-ad4a-120cd30a0000 pid=2771 execve guuid=f876f041-1a00-0000-ad4a-120cff0a0000 pid=2815 /usr/bin/chmod guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=f876f041-1a00-0000-ad4a-120cff0a0000 pid=2815 execve guuid=f3588742-1a00-0000-ad4a-120c010b0000 pid=2817 /usr/bin/dash guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=f3588742-1a00-0000-ad4a-120c010b0000 pid=2817 clone guuid=88b46043-1a00-0000-ad4a-120c050b0000 pid=2821 /usr/bin/rm delete-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=88b46043-1a00-0000-ad4a-120c050b0000 pid=2821 execve guuid=4e91da43-1a00-0000-ad4a-120c070b0000 pid=2823 /usr/bin/curl net send-data write-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=4e91da43-1a00-0000-ad4a-120c070b0000 pid=2823 execve guuid=4654c45a-1a00-0000-ad4a-120c350b0000 pid=2869 /usr/bin/chmod guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=4654c45a-1a00-0000-ad4a-120c350b0000 pid=2869 execve guuid=6c681c5b-1a00-0000-ad4a-120c370b0000 pid=2871 /usr/bin/dash guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=6c681c5b-1a00-0000-ad4a-120c370b0000 pid=2871 clone guuid=45aea15b-1a00-0000-ad4a-120c3a0b0000 pid=2874 /usr/bin/rm delete-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=45aea15b-1a00-0000-ad4a-120c3a0b0000 pid=2874 execve guuid=0399f55b-1a00-0000-ad4a-120c3d0b0000 pid=2877 /usr/bin/curl net send-data write-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=0399f55b-1a00-0000-ad4a-120c3d0b0000 pid=2877 execve guuid=13bf996d-1a00-0000-ad4a-120c690b0000 pid=2921 /usr/bin/chmod guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=13bf996d-1a00-0000-ad4a-120c690b0000 pid=2921 execve guuid=b1f5fb6d-1a00-0000-ad4a-120c6a0b0000 pid=2922 /usr/bin/dash guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=b1f5fb6d-1a00-0000-ad4a-120c6a0b0000 pid=2922 clone guuid=5d29966e-1a00-0000-ad4a-120c6e0b0000 pid=2926 /usr/bin/rm delete-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=5d29966e-1a00-0000-ad4a-120c6e0b0000 pid=2926 execve guuid=e0ecd86e-1a00-0000-ad4a-120c710b0000 pid=2929 /usr/bin/curl net send-data write-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=e0ecd86e-1a00-0000-ad4a-120c710b0000 pid=2929 execve guuid=5ab9fd87-1a00-0000-ad4a-120c930b0000 pid=2963 /usr/bin/chmod guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=5ab9fd87-1a00-0000-ad4a-120c930b0000 pid=2963 execve guuid=f8318988-1a00-0000-ad4a-120c950b0000 pid=2965 /usr/bin/dash guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=f8318988-1a00-0000-ad4a-120c950b0000 pid=2965 clone guuid=eab0a189-1a00-0000-ad4a-120c970b0000 pid=2967 /usr/bin/rm delete-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=eab0a189-1a00-0000-ad4a-120c970b0000 pid=2967 execve guuid=57bc858a-1a00-0000-ad4a-120c980b0000 pid=2968 /usr/bin/curl net send-data write-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=57bc858a-1a00-0000-ad4a-120c980b0000 pid=2968 execve guuid=3ae6acb4-1a00-0000-ad4a-120cef0b0000 pid=3055 /usr/bin/chmod guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=3ae6acb4-1a00-0000-ad4a-120cef0b0000 pid=3055 execve guuid=46b9f0b4-1a00-0000-ad4a-120cf10b0000 pid=3057 /usr/bin/dash guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=46b9f0b4-1a00-0000-ad4a-120cf10b0000 pid=3057 clone guuid=870c98b5-1a00-0000-ad4a-120cf40b0000 pid=3060 /usr/bin/rm delete-file guuid=a7e7a0b2-1900-0000-ad4a-120cb1090000 pid=2481->guuid=870c98b5-1a00-0000-ad4a-120cf40b0000 pid=3060 execve 75f6a902-a461-5224-8170-1acd4cdf8dab 107.150.0.18:80 guuid=640cdab2-1900-0000-ad4a-120cb3090000 pid=2483->75f6a902-a461-5224-8170-1acd4cdf8dab send: 79B guuid=480c3fd8-1900-0000-ad4a-120cfc090000 pid=2556->75f6a902-a461-5224-8170-1acd4cdf8dab send: 79B guuid=3648e101-1a00-0000-ad4a-120c720a0000 pid=2674->75f6a902-a461-5224-8170-1acd4cdf8dab send: 80B guuid=5be2e222-1a00-0000-ad4a-120cd30a0000 pid=2771->75f6a902-a461-5224-8170-1acd4cdf8dab send: 80B guuid=4e91da43-1a00-0000-ad4a-120c070b0000 pid=2823->75f6a902-a461-5224-8170-1acd4cdf8dab send: 80B guuid=0399f55b-1a00-0000-ad4a-120c3d0b0000 pid=2877->75f6a902-a461-5224-8170-1acd4cdf8dab send: 80B guuid=e0ecd86e-1a00-0000-ad4a-120c710b0000 pid=2929->75f6a902-a461-5224-8170-1acd4cdf8dab send: 79B guuid=57bc858a-1a00-0000-ad4a-120c980b0000 pid=2968->75f6a902-a461-5224-8170-1acd4cdf8dab send: 79B
Verdict:
Malicious
Threat:
Document-HTML.Downloader.Heuristic
Threat name:
Document-HTML.Trojan.Heuristic
Status:
Malicious
First seen:
2025-07-06 10:54:23 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c48c252e93de1a98c786d08919c28ef4bf791e3bdbfef352a405bd3527467949

(this sample)

  
Delivery method
Distributed via web download

Comments