MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c61a01005633607b80c1d359d8d236acde9fd0cdb771b89021f1d27e9a79907d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: c61a01005633607b80c1d359d8d236acde9fd0cdb771b89021f1d27e9a79907d
SHA3-384 hash: a7a3d7eb860d666bf6c3fa1eec348aee0834f6d86f066fc51bdf9e7c6f818b277e1636192099a86ae4cf74a2fca94f9d
SHA1 hash: 3c6ef9675648d1477038c79828ac93eb63c7b354
MD5 hash: 3fc3ba26c4252487e3aa02c9e151edad
humanhash: oklahoma-hawaii-potato-king
File name:sh
Download: download sample
File size:287 bytes
First seen:2026-02-20 02:18:15 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:/VJ+pUKUF2RVYTeinYf53IUy5p3FoFGmUVKAOXqIKv3IKS1IVx1IKBK0:/VJ+jRPEYFFMgAsOVf80
TLSH T1E5D02B9CF4134C73B4708CF9BBDB34A5A60FE2086A0A58C423CC120EE4E4D50B4501A3
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=a8b731ef-1600-0000-44fd-9a96b70c0000 pid=3255 /usr/bin/sudo guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262 /tmp/sample.bin guuid=a8b731ef-1600-0000-44fd-9a96b70c0000 pid=3255->guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262 execve guuid=ad0a6cf1-1600-0000-44fd-9a96bf0c0000 pid=3263 /usr/bin/wget net send-data write-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=ad0a6cf1-1600-0000-44fd-9a96bf0c0000 pid=3263 execve guuid=6d9ec011-1700-0000-44fd-9a96050d0000 pid=3333 /usr/bin/chmod guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=6d9ec011-1700-0000-44fd-9a96050d0000 pid=3333 execve guuid=7f930c12-1700-0000-44fd-9a96070d0000 pid=3335 /usr/bin/dash guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=7f930c12-1700-0000-44fd-9a96070d0000 pid=3335 clone guuid=9b3fbf12-1700-0000-44fd-9a960a0d0000 pid=3338 /usr/bin/rm delete-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=9b3fbf12-1700-0000-44fd-9a960a0d0000 pid=3338 execve guuid=310d0313-1700-0000-44fd-9a960b0d0000 pid=3339 /usr/bin/wget net send-data write-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=310d0313-1700-0000-44fd-9a960b0d0000 pid=3339 execve guuid=c81dcf31-1700-0000-44fd-9a96530d0000 pid=3411 /usr/bin/chmod guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=c81dcf31-1700-0000-44fd-9a96530d0000 pid=3411 execve guuid=3c443e32-1700-0000-44fd-9a96550d0000 pid=3413 /usr/bin/dash guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=3c443e32-1700-0000-44fd-9a96550d0000 pid=3413 clone guuid=ffa62033-1700-0000-44fd-9a96580d0000 pid=3416 /usr/bin/rm delete-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=ffa62033-1700-0000-44fd-9a96580d0000 pid=3416 execve guuid=a5c0a133-1700-0000-44fd-9a965a0d0000 pid=3418 /usr/bin/wget net send-data write-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=a5c0a133-1700-0000-44fd-9a965a0d0000 pid=3418 execve guuid=c7396c4c-1700-0000-44fd-9a969b0d0000 pid=3483 /usr/bin/chmod guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=c7396c4c-1700-0000-44fd-9a969b0d0000 pid=3483 execve guuid=b5f6a64c-1700-0000-44fd-9a969d0d0000 pid=3485 /usr/bin/dash guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=b5f6a64c-1700-0000-44fd-9a969d0d0000 pid=3485 clone guuid=b036234d-1700-0000-44fd-9a96a40d0000 pid=3492 /usr/bin/rm delete-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=b036234d-1700-0000-44fd-9a96a40d0000 pid=3492 execve guuid=c900604d-1700-0000-44fd-9a96a50d0000 pid=3493 /usr/bin/wget net send-data write-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=c900604d-1700-0000-44fd-9a96a50d0000 pid=3493 execve guuid=8e11fe65-1700-0000-44fd-9a96c80d0000 pid=3528 /usr/bin/chmod guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=8e11fe65-1700-0000-44fd-9a96c80d0000 pid=3528 execve guuid=08a08066-1700-0000-44fd-9a96c90d0000 pid=3529 /usr/bin/dash guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=08a08066-1700-0000-44fd-9a96c90d0000 pid=3529 clone guuid=e33c9267-1700-0000-44fd-9a96cb0d0000 pid=3531 /usr/bin/rm delete-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=e33c9267-1700-0000-44fd-9a96cb0d0000 pid=3531 execve guuid=d50fc368-1700-0000-44fd-9a96cd0d0000 pid=3533 /usr/bin/wget net send-data write-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=d50fc368-1700-0000-44fd-9a96cd0d0000 pid=3533 execve guuid=ee5dcc81-1700-0000-44fd-9a96f50d0000 pid=3573 /usr/bin/chmod guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=ee5dcc81-1700-0000-44fd-9a96f50d0000 pid=3573 execve guuid=92df4882-1700-0000-44fd-9a96f70d0000 pid=3575 /usr/bin/dash guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=92df4882-1700-0000-44fd-9a96f70d0000 pid=3575 clone guuid=2a683d83-1700-0000-44fd-9a96fb0d0000 pid=3579 /usr/bin/rm delete-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=2a683d83-1700-0000-44fd-9a96fb0d0000 pid=3579 execve guuid=ffafae83-1700-0000-44fd-9a96fc0d0000 pid=3580 /usr/bin/wget net send-data write-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=ffafae83-1700-0000-44fd-9a96fc0d0000 pid=3580 execve guuid=a1ab83a2-1700-0000-44fd-9a964a0e0000 pid=3658 /usr/bin/chmod guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=a1ab83a2-1700-0000-44fd-9a964a0e0000 pid=3658 execve guuid=f542bba2-1700-0000-44fd-9a964c0e0000 pid=3660 /usr/bin/dash guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=f542bba2-1700-0000-44fd-9a964c0e0000 pid=3660 clone guuid=128c2ea3-1700-0000-44fd-9a96500e0000 pid=3664 /usr/bin/rm delete-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=128c2ea3-1700-0000-44fd-9a96500e0000 pid=3664 execve guuid=9d4263a3-1700-0000-44fd-9a96510e0000 pid=3665 /usr/bin/wget net send-data write-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=9d4263a3-1700-0000-44fd-9a96510e0000 pid=3665 execve guuid=663545bd-1700-0000-44fd-9a968c0e0000 pid=3724 /usr/bin/chmod guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=663545bd-1700-0000-44fd-9a968c0e0000 pid=3724 execve guuid=91aabcbd-1700-0000-44fd-9a968d0e0000 pid=3725 /usr/bin/dash guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=91aabcbd-1700-0000-44fd-9a968d0e0000 pid=3725 clone guuid=4287b8be-1700-0000-44fd-9a96920e0000 pid=3730 /usr/bin/rm delete-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=4287b8be-1700-0000-44fd-9a96920e0000 pid=3730 execve guuid=f99021bf-1700-0000-44fd-9a96940e0000 pid=3732 /usr/bin/wget net send-data write-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=f99021bf-1700-0000-44fd-9a96940e0000 pid=3732 execve guuid=603f37d8-1700-0000-44fd-9a96ce0e0000 pid=3790 /usr/bin/chmod guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=603f37d8-1700-0000-44fd-9a96ce0e0000 pid=3790 execve guuid=e88472d8-1700-0000-44fd-9a96cf0e0000 pid=3791 /usr/bin/dash guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=e88472d8-1700-0000-44fd-9a96cf0e0000 pid=3791 clone guuid=315ffcd8-1700-0000-44fd-9a96d60e0000 pid=3798 /usr/bin/rm delete-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=315ffcd8-1700-0000-44fd-9a96d60e0000 pid=3798 execve guuid=541a41d9-1700-0000-44fd-9a96d90e0000 pid=3801 /usr/bin/wget net send-data write-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=541a41d9-1700-0000-44fd-9a96d90e0000 pid=3801 execve guuid=e0e6cef2-1700-0000-44fd-9a963c0f0000 pid=3900 /usr/bin/chmod guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=e0e6cef2-1700-0000-44fd-9a963c0f0000 pid=3900 execve guuid=e9604ef3-1700-0000-44fd-9a96400f0000 pid=3904 /tmp/cron.kvariant guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=e9604ef3-1700-0000-44fd-9a96400f0000 pid=3904 execve guuid=239e77f3-1700-0000-44fd-9a96420f0000 pid=3906 /usr/bin/rm delete-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=239e77f3-1700-0000-44fd-9a96420f0000 pid=3906 execve guuid=06a303f4-1700-0000-44fd-9a96440f0000 pid=3908 /usr/bin/wget net send-data write-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=06a303f4-1700-0000-44fd-9a96440f0000 pid=3908 execve guuid=a378370d-1800-0000-44fd-9a967b0f0000 pid=3963 /usr/bin/chmod guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=a378370d-1800-0000-44fd-9a967b0f0000 pid=3963 execve guuid=acb2aa0d-1800-0000-44fd-9a967f0f0000 pid=3967 /usr/bin/dash guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=acb2aa0d-1800-0000-44fd-9a967f0f0000 pid=3967 clone guuid=271cf70f-1800-0000-44fd-9a96870f0000 pid=3975 /usr/bin/rm delete-file guuid=043913f1-1600-0000-44fd-9a96be0c0000 pid=3262->guuid=271cf70f-1800-0000-44fd-9a96870f0000 pid=3975 execve 9e269a19-b086-5b9b-9863-0a1f5412a545 198.144.189.70:80 guuid=ad0a6cf1-1600-0000-44fd-9a96bf0c0000 pid=3263->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 143B guuid=310d0313-1700-0000-44fd-9a960b0d0000 pid=3339->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 143B guuid=a5c0a133-1700-0000-44fd-9a965a0d0000 pid=3418->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 142B guuid=c900604d-1700-0000-44fd-9a96a50d0000 pid=3493->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 143B guuid=d50fc368-1700-0000-44fd-9a96cd0d0000 pid=3533->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 143B guuid=ffafae83-1700-0000-44fd-9a96fc0d0000 pid=3580->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 143B guuid=9d4263a3-1700-0000-44fd-9a96510e0000 pid=3665->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 142B guuid=f99021bf-1700-0000-44fd-9a96940e0000 pid=3732->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 142B guuid=541a41d9-1700-0000-44fd-9a96d90e0000 pid=3801->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 142B guuid=c0d366f3-1700-0000-44fd-9a96410f0000 pid=3905 /tmp/cron.kvariant zombie guuid=e9604ef3-1700-0000-44fd-9a96400f0000 pid=3904->guuid=c0d366f3-1700-0000-44fd-9a96410f0000 pid=3905 clone guuid=97fa7af3-1700-0000-44fd-9a96430f0000 pid=3907 /tmp/cron.kvariant net send-data zombie guuid=c0d366f3-1700-0000-44fd-9a96410f0000 pid=3905->guuid=97fa7af3-1700-0000-44fd-9a96430f0000 pid=3907 clone b176a1c4-7acf-5cab-9da1-7489b9f29878 198.144.189.70:41323 guuid=97fa7af3-1700-0000-44fd-9a96430f0000 pid=3907->b176a1c4-7acf-5cab-9da1-7489b9f29878 send: 16B guuid=bebe3741-1800-0000-44fd-9a9631100000 pid=4145 /tmp/cron.kvariant net net-scan send-data guuid=97fa7af3-1700-0000-44fd-9a96430f0000 pid=3907->guuid=bebe3741-1800-0000-44fd-9a9631100000 pid=4145 clone guuid=91a94141-1800-0000-44fd-9a9632100000 pid=4146 /tmp/cron.kvariant net net-scan send-data guuid=97fa7af3-1700-0000-44fd-9a96430f0000 pid=3907->guuid=91a94141-1800-0000-44fd-9a9632100000 pid=4146 clone guuid=06a303f4-1700-0000-44fd-9a96440f0000 pid=3908->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 142B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=bebe3741-1800-0000-44fd-9a9631100000 pid=4145->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bebe3741-1800-0000-44fd-9a9631100000 pid=4145|send-data send-data to 4097 IP addresses review logs to see them all guuid=bebe3741-1800-0000-44fd-9a9631100000 pid=4145->guuid=bebe3741-1800-0000-44fd-9a9631100000 pid=4145|send-data send guuid=91a94141-1800-0000-44fd-9a9632100000 pid=4146->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8cfb0895-3558-59af-bf4b-4d02d6007f89 134.220.115.172:37215 guuid=91a94141-1800-0000-44fd-9a9632100000 pid=4146->8cfb0895-3558-59af-bf4b-4d02d6007f89 send: 866B guuid=91a94141-1800-0000-44fd-9a9632100000 pid=4146|send-data send-data to 4092 IP addresses review logs to see them all guuid=91a94141-1800-0000-44fd-9a9632100000 pid=4146->guuid=91a94141-1800-0000-44fd-9a9632100000 pid=4146|send-data send
Threat name:
Linux.Downloader.MiraiB
Status:
Malicious
First seen:
2026-02-20 03:10:20 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh c61a01005633607b80c1d359d8d236acde9fd0cdb771b89021f1d27e9a79907d

(this sample)

  
Delivery method
Distributed via web download

Comments