MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c792b032fb1f71205f9f3caf58437f8525d99ffca1530511c86ffd92fd22413b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c792b032fb1f71205f9f3caf58437f8525d99ffca1530511c86ffd92fd22413b
SHA3-384 hash: 3c14c91e49df1663edc6cc1f9d29e93d74c7e5d4a6bbb0b1e3b8d5915415331e492ef694f175f171eafc561cafd922af
SHA1 hash: 7960f2227633a66a1ba197e8074e1949bbc9065b
MD5 hash: 915bfc96306d854889017eda91ce1343
humanhash: illinois-potato-lima-july
File name:o
Download: download sample
Signature Mirai
File size:94 bytes
First seen:2026-07-17 23:09:25 UTC
Last seen:2026-07-18 19:04:53 UTC
File type: sh
MIME type:text/plain
ssdeep 3:KYyM+KDQNUCq+DKT7GBzSEyLTUWOvn:JyMI5WeII
TLSH T1D2B0129B606120C0DE48BC00146B0F1D224347C234694E0C5CE02671CC985047870D09
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://205.237.110.232/tvt/mips06c4ddabac5e976f152f482a47581313fdb95e2cbee564d56279648bbaf5694a Miraielf gafgyt mirai ua-wget

Intelligence


File Origin
# of uploads :
443
# of downloads :
17
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=78b33559-1b00-0000-59a2-0fc5a90a0000 pid=2729 /usr/bin/sudo guuid=1131f75b-1b00-0000-59a2-0fc5b00a0000 pid=2736 /tmp/sample.bin guuid=78b33559-1b00-0000-59a2-0fc5a90a0000 pid=2729->guuid=1131f75b-1b00-0000-59a2-0fc5b00a0000 pid=2736 execve guuid=72a75a5c-1b00-0000-59a2-0fc5b20a0000 pid=2738 /usr/bin/rm guuid=1131f75b-1b00-0000-59a2-0fc5b00a0000 pid=2736->guuid=72a75a5c-1b00-0000-59a2-0fc5b20a0000 pid=2738 execve guuid=fb4af85c-1b00-0000-59a2-0fc5b40a0000 pid=2740 /usr/bin/dash guuid=1131f75b-1b00-0000-59a2-0fc5b00a0000 pid=2736->guuid=fb4af85c-1b00-0000-59a2-0fc5b40a0000 pid=2740 clone guuid=c032025d-1b00-0000-59a2-0fc5b50a0000 pid=2741 /usr/bin/chmod guuid=1131f75b-1b00-0000-59a2-0fc5b00a0000 pid=2736->guuid=c032025d-1b00-0000-59a2-0fc5b50a0000 pid=2741 execve guuid=a6b4395d-1b00-0000-59a2-0fc5b70a0000 pid=2743 /usr/bin/dash guuid=1131f75b-1b00-0000-59a2-0fc5b00a0000 pid=2736->guuid=a6b4395d-1b00-0000-59a2-0fc5b70a0000 pid=2743 clone
Gathering data
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2026-07-18 04:03:28 UTC
AV detection:
8 of 38 (21.05%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c792b032fb1f71205f9f3caf58437f8525d99ffca1530511c86ffd92fd22413b

(this sample)

  
Delivery method
Distributed via web download

Comments