MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cae7364a3b3e6662d839843d587c232a86efb33f45db87a6f011a795f5400b42. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: cae7364a3b3e6662d839843d587c232a86efb33f45db87a6f011a795f5400b42
SHA3-384 hash: a6304c32f10cb3bfaae23d4f507a08211a5f84e1833d7b7c5f732527228e40e60676620d84175838afe415e1d94389b6
SHA1 hash: dbe909d812ee71974181d5b7d0ea1d2304fc4e35
MD5 hash: 24609271a6a085a19cd53a6927fcf19a
humanhash: friend-lake-harry-dakota
File name:sky.sh
Download: download sample
Signature Mirai
File size:677 bytes
First seen:2025-07-28 23:06:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:Vq91TyXePpWz/OC3cLjJOBUWiWbW745HbISBkTqduOBLT:491mOg60cL65E4574ABH
TLSH T18801FE8C57CFD1A928E61C78A0D7E044A34284251436917378AD2539EB8580CF2308F0
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=8377ebe1-1900-0000-3cbf-a0cb3b090000 pid=2363 /usr/bin/sudo guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371 /tmp/sample.bin guuid=8377ebe1-1900-0000-3cbf-a0cb3b090000 pid=2363->guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371 execve guuid=11a40de4-1900-0000-3cbf-a0cb45090000 pid=2373 /usr/bin/rm guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=11a40de4-1900-0000-3cbf-a0cb45090000 pid=2373 execve guuid=a78b92e4-1900-0000-3cbf-a0cb48090000 pid=2376 /usr/bin/wget net send-data write-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=a78b92e4-1900-0000-3cbf-a0cb48090000 pid=2376 execve guuid=dfcdc31c-1a00-0000-3cbf-a0cbc8090000 pid=2504 /usr/bin/chmod guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=dfcdc31c-1a00-0000-3cbf-a0cbc8090000 pid=2504 execve guuid=c6451e1d-1a00-0000-3cbf-a0cbca090000 pid=2506 /var/tmp/.ksysd delete-file net guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=c6451e1d-1a00-0000-3cbf-a0cbca090000 pid=2506 execve guuid=df04661d-1a00-0000-3cbf-a0cbcc090000 pid=2508 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=df04661d-1a00-0000-3cbf-a0cbcc090000 pid=2508 execve guuid=5421a41d-1a00-0000-3cbf-a0cbcf090000 pid=2511 /usr/bin/rm guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=5421a41d-1a00-0000-3cbf-a0cbcf090000 pid=2511 execve guuid=5cfddf1d-1a00-0000-3cbf-a0cbd0090000 pid=2512 /usr/bin/wget net guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=5cfddf1d-1a00-0000-3cbf-a0cbd0090000 pid=2512 execve guuid=843f1c21-1a00-0000-3cbf-a0cbd2090000 pid=2514 /usr/bin/chmod guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=843f1c21-1a00-0000-3cbf-a0cbd2090000 pid=2514 execve guuid=9e5d6121-1a00-0000-3cbf-a0cbd3090000 pid=2515 /var/tmp/.dbusd guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=9e5d6121-1a00-0000-3cbf-a0cbd3090000 pid=2515 execve guuid=199b2723-1a00-0000-3cbf-a0cbd7090000 pid=2519 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=199b2723-1a00-0000-3cbf-a0cbd7090000 pid=2519 execve guuid=d326b723-1a00-0000-3cbf-a0cbda090000 pid=2522 /usr/bin/rm guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=d326b723-1a00-0000-3cbf-a0cbda090000 pid=2522 execve guuid=03aa1e24-1a00-0000-3cbf-a0cbdc090000 pid=2524 /usr/bin/wget guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=03aa1e24-1a00-0000-3cbf-a0cbdc090000 pid=2524 execve guuid=c5df5125-1a00-0000-3cbf-a0cbe2090000 pid=2530 /usr/bin/chmod guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=c5df5125-1a00-0000-3cbf-a0cbe2090000 pid=2530 execve guuid=ea42cd25-1a00-0000-3cbf-a0cbe4090000 pid=2532 /var/tmp/.udevmon guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=ea42cd25-1a00-0000-3cbf-a0cbe4090000 pid=2532 execve guuid=304d6027-1a00-0000-3cbf-a0cbe9090000 pid=2537 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=304d6027-1a00-0000-3cbf-a0cbe9090000 pid=2537 execve guuid=d0b72929-1a00-0000-3cbf-a0cbf1090000 pid=2545 /usr/bin/rm guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=d0b72929-1a00-0000-3cbf-a0cbf1090000 pid=2545 execve guuid=a2c37629-1a00-0000-3cbf-a0cbf3090000 pid=2547 /usr/bin/wget net guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=a2c37629-1a00-0000-3cbf-a0cbf3090000 pid=2547 execve guuid=5c06602c-1a00-0000-3cbf-a0cbf7090000 pid=2551 /usr/bin/chmod guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=5c06602c-1a00-0000-3cbf-a0cbf7090000 pid=2551 execve guuid=d07ea82c-1a00-0000-3cbf-a0cbf9090000 pid=2553 /usr/bin/dash guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=d07ea82c-1a00-0000-3cbf-a0cbf9090000 pid=2553 clone guuid=ac1eca2f-1a00-0000-3cbf-a0cb020a0000 pid=2562 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=ac1eca2f-1a00-0000-3cbf-a0cb020a0000 pid=2562 execve guuid=66bc1130-1a00-0000-3cbf-a0cb030a0000 pid=2563 /usr/bin/rm guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=66bc1130-1a00-0000-3cbf-a0cb030a0000 pid=2563 execve guuid=d67c7c30-1a00-0000-3cbf-a0cb040a0000 pid=2564 /usr/bin/wget guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=d67c7c30-1a00-0000-3cbf-a0cb040a0000 pid=2564 execve guuid=370e4332-1a00-0000-3cbf-a0cb0a0a0000 pid=2570 /usr/bin/chmod guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=370e4332-1a00-0000-3cbf-a0cb0a0a0000 pid=2570 execve guuid=ec088732-1a00-0000-3cbf-a0cb0c0a0000 pid=2572 /var/tmp/.netd guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=ec088732-1a00-0000-3cbf-a0cb0c0a0000 pid=2572 execve guuid=0719ed33-1a00-0000-3cbf-a0cb130a0000 pid=2579 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=0719ed33-1a00-0000-3cbf-a0cb130a0000 pid=2579 execve guuid=58172834-1a00-0000-3cbf-a0cb140a0000 pid=2580 /usr/bin/rm guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=58172834-1a00-0000-3cbf-a0cb140a0000 pid=2580 execve guuid=90bfe434-1a00-0000-3cbf-a0cb180a0000 pid=2584 /usr/bin/wget guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=90bfe434-1a00-0000-3cbf-a0cb180a0000 pid=2584 execve guuid=a9fcf935-1a00-0000-3cbf-a0cb1a0a0000 pid=2586 /usr/bin/chmod guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=a9fcf935-1a00-0000-3cbf-a0cb1a0a0000 pid=2586 execve guuid=04365836-1a00-0000-3cbf-a0cb1c0a0000 pid=2588 /var/tmp/.syncd guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=04365836-1a00-0000-3cbf-a0cb1c0a0000 pid=2588 execve guuid=a6ef6d38-1a00-0000-3cbf-a0cb230a0000 pid=2595 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=a6ef6d38-1a00-0000-3cbf-a0cb230a0000 pid=2595 execve guuid=93c0b838-1a00-0000-3cbf-a0cb250a0000 pid=2597 /usr/bin/rm guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=93c0b838-1a00-0000-3cbf-a0cb250a0000 pid=2597 execve guuid=f1101739-1a00-0000-3cbf-a0cb270a0000 pid=2599 /usr/bin/wget guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=f1101739-1a00-0000-3cbf-a0cb270a0000 pid=2599 execve guuid=cd76a03a-1a00-0000-3cbf-a0cb2d0a0000 pid=2605 /usr/bin/chmod guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=cd76a03a-1a00-0000-3cbf-a0cb2d0a0000 pid=2605 execve guuid=f79a6c3b-1a00-0000-3cbf-a0cb310a0000 pid=2609 /var/tmp/.irqbal guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=f79a6c3b-1a00-0000-3cbf-a0cb310a0000 pid=2609 execve guuid=43d0ec3c-1a00-0000-3cbf-a0cb370a0000 pid=2615 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=43d0ec3c-1a00-0000-3cbf-a0cb370a0000 pid=2615 execve guuid=ba60b73d-1a00-0000-3cbf-a0cb3a0a0000 pid=2618 /usr/bin/rm guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=ba60b73d-1a00-0000-3cbf-a0cb3a0a0000 pid=2618 execve guuid=8429903e-1a00-0000-3cbf-a0cb3d0a0000 pid=2621 /usr/bin/wget net guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=8429903e-1a00-0000-3cbf-a0cb3d0a0000 pid=2621 execve guuid=77cebf40-1a00-0000-3cbf-a0cb440a0000 pid=2628 /usr/bin/chmod guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=77cebf40-1a00-0000-3cbf-a0cb440a0000 pid=2628 execve guuid=af132441-1a00-0000-3cbf-a0cb460a0000 pid=2630 /usr/bin/dash guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=af132441-1a00-0000-3cbf-a0cb460a0000 pid=2630 clone guuid=a58b5b42-1a00-0000-3cbf-a0cb4c0a0000 pid=2636 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=a58b5b42-1a00-0000-3cbf-a0cb4c0a0000 pid=2636 execve guuid=913cc442-1a00-0000-3cbf-a0cb4e0a0000 pid=2638 /usr/bin/rm guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=913cc442-1a00-0000-3cbf-a0cb4e0a0000 pid=2638 execve guuid=9e3f2343-1a00-0000-3cbf-a0cb500a0000 pid=2640 /usr/bin/wget guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=9e3f2343-1a00-0000-3cbf-a0cb500a0000 pid=2640 execve guuid=c9cbce45-1a00-0000-3cbf-a0cb5c0a0000 pid=2652 /usr/bin/chmod guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=c9cbce45-1a00-0000-3cbf-a0cb5c0a0000 pid=2652 execve guuid=4ebc0646-1a00-0000-3cbf-a0cb5e0a0000 pid=2654 /var/tmp/.modprobe guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=4ebc0646-1a00-0000-3cbf-a0cb5e0a0000 pid=2654 execve guuid=74922548-1a00-0000-3cbf-a0cb650a0000 pid=2661 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=74922548-1a00-0000-3cbf-a0cb650a0000 pid=2661 execve guuid=1bf27e48-1a00-0000-3cbf-a0cb680a0000 pid=2664 /usr/bin/rm guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=1bf27e48-1a00-0000-3cbf-a0cb680a0000 pid=2664 execve guuid=7c01d048-1a00-0000-3cbf-a0cb6a0a0000 pid=2666 /usr/bin/wget guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=7c01d048-1a00-0000-3cbf-a0cb6a0a0000 pid=2666 execve guuid=2b196d49-1a00-0000-3cbf-a0cb6d0a0000 pid=2669 /usr/bin/chmod guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=2b196d49-1a00-0000-3cbf-a0cb6d0a0000 pid=2669 execve guuid=6b1dff49-1a00-0000-3cbf-a0cb710a0000 pid=2673 /var/tmp/.kthreadd guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=6b1dff49-1a00-0000-3cbf-a0cb710a0000 pid=2673 execve guuid=6efb174b-1a00-0000-3cbf-a0cb760a0000 pid=2678 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=6efb174b-1a00-0000-3cbf-a0cb760a0000 pid=2678 execve guuid=f21a4e4b-1a00-0000-3cbf-a0cb770a0000 pid=2679 /usr/bin/rm guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=f21a4e4b-1a00-0000-3cbf-a0cb770a0000 pid=2679 execve guuid=e006bf4b-1a00-0000-3cbf-a0cb7a0a0000 pid=2682 /usr/bin/wget guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=e006bf4b-1a00-0000-3cbf-a0cb7a0a0000 pid=2682 execve guuid=9098b14d-1a00-0000-3cbf-a0cb820a0000 pid=2690 /usr/bin/chmod guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=9098b14d-1a00-0000-3cbf-a0cb820a0000 pid=2690 execve guuid=7e22e54d-1a00-0000-3cbf-a0cb840a0000 pid=2692 /var/tmp/.klogd guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=7e22e54d-1a00-0000-3cbf-a0cb840a0000 pid=2692 execve guuid=b2031450-1a00-0000-3cbf-a0cb8c0a0000 pid=2700 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=b2031450-1a00-0000-3cbf-a0cb8c0a0000 pid=2700 execve guuid=cadd5950-1a00-0000-3cbf-a0cb8e0a0000 pid=2702 /usr/bin/rm guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=cadd5950-1a00-0000-3cbf-a0cb8e0a0000 pid=2702 execve guuid=45839c50-1a00-0000-3cbf-a0cb8f0a0000 pid=2703 /usr/bin/wget net guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=45839c50-1a00-0000-3cbf-a0cb8f0a0000 pid=2703 execve guuid=34d1b952-1a00-0000-3cbf-a0cb950a0000 pid=2709 /usr/bin/chmod guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=34d1b952-1a00-0000-3cbf-a0cb950a0000 pid=2709 execve guuid=9c0afe52-1a00-0000-3cbf-a0cb970a0000 pid=2711 /var/tmp/.systemd-jd guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=9c0afe52-1a00-0000-3cbf-a0cb970a0000 pid=2711 execve guuid=36d6b453-1a00-0000-3cbf-a0cb9c0a0000 pid=2716 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=36d6b453-1a00-0000-3cbf-a0cb9c0a0000 pid=2716 execve guuid=2432fc53-1a00-0000-3cbf-a0cb9e0a0000 pid=2718 /usr/bin/rm delete-file guuid=2bcdd1e3-1900-0000-3cbf-a0cb43090000 pid=2371->guuid=2432fc53-1a00-0000-3cbf-a0cb9e0a0000 pid=2718 execve d38039d6-9633-5d71-871e-7db8066417d1 160.30.21.79:80 guuid=a78b92e4-1900-0000-3cbf-a0cb48090000 pid=2376->d38039d6-9633-5d71-871e-7db8066417d1 send: 133B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=c6451e1d-1a00-0000-3cbf-a0cbca090000 pid=2506->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=87a05d1d-1a00-0000-3cbf-a0cbcb090000 pid=2507 /var/tmp/.ksysd dns net send-data zombie guuid=c6451e1d-1a00-0000-3cbf-a0cbca090000 pid=2506->guuid=87a05d1d-1a00-0000-3cbf-a0cbcb090000 pid=2507 clone guuid=87a05d1d-1a00-0000-3cbf-a0cbcb090000 pid=2507->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 44B cc1a529b-a2ce-57e1-8332-5f23bed69004 iotmiraibotnet.duckdns.org:1995 guuid=87a05d1d-1a00-0000-3cbf-a0cbcb090000 pid=2507->cc1a529b-a2ce-57e1-8332-5f23bed69004 send: 8B guuid=f3866b1d-1a00-0000-3cbf-a0cbcd090000 pid=2509 /var/tmp/.ksysd guuid=87a05d1d-1a00-0000-3cbf-a0cbcb090000 pid=2507->guuid=f3866b1d-1a00-0000-3cbf-a0cbcd090000 pid=2509 clone guuid=56f26f1d-1a00-0000-3cbf-a0cbce090000 pid=2510 /var/tmp/.ksysd guuid=87a05d1d-1a00-0000-3cbf-a0cbcb090000 pid=2507->guuid=56f26f1d-1a00-0000-3cbf-a0cbce090000 pid=2510 clone guuid=5cfddf1d-1a00-0000-3cbf-a0cbd0090000 pid=2512->d38039d6-9633-5d71-871e-7db8066417d1 con guuid=a2c37629-1a00-0000-3cbf-a0cbf3090000 pid=2547->d38039d6-9633-5d71-871e-7db8066417d1 con guuid=8429903e-1a00-0000-3cbf-a0cb3d0a0000 pid=2621->d38039d6-9633-5d71-871e-7db8066417d1 con guuid=45839c50-1a00-0000-3cbf-a0cb8f0a0000 pid=2703->d38039d6-9633-5d71-871e-7db8066417d1 con
Threat name:
Linux.Downloader.SAgnt
Status:
Malicious
First seen:
2025-07-28 23:07:21 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
Changes its process name
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
iotmiraibotnet.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh cae7364a3b3e6662d839843d587c232a86efb33f45db87a6f011a795f5400b42

(this sample)

  
Delivery method
Distributed via web download

Comments