MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cdd6936d8df252eebe2b249f6fe3dea581055d1bf22330043fb22f40065d7883. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: cdd6936d8df252eebe2b249f6fe3dea581055d1bf22330043fb22f40065d7883
SHA3-384 hash: a86e5617c1c319c76fa122d2f955330b146021770977e05e7b25c40893d8d9d8075b34e9e37cf4823c51946af4ec1d7d
SHA1 hash: 35b6caf62b87da0898110b6f038c2361a1428834
MD5 hash: 36af85a77609189f49c67844a8b32271
humanhash: chicken-tango-coffee-fanta
File name:w.sh
Download: download sample
Signature Mirai
File size:802 bytes
First seen:2025-08-21 05:38:25 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:F9kSCKNIl5WD30LKjD+OQ2Wo3A0S1tMxyk:PH3NI7RKjD+J2Wow0ctMX
TLSH T1AB019BCF29F16AA2048CCE587077881996258EC061910F9EFADC0CB75BD4D18B217E9A
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://141.98.10.30/armd27aabafaa1beb49bf4e7f8c78418fc9bbc9c175b333bc4357e515102b854350 Miraielf mirai ua-wget
http://141.98.10.30/arm5e3155750e28e3b1f55f0d94edc1add56227af71d2b989693b2aef43df81b9450 Miraielf mirai ua-wget
http://141.98.10.30/arm6b8d674cec7c48ec354fea58d29189c1675779e6f2d4a329945f4ed1adf1ea425 Miraielf mirai ua-wget
http://141.98.10.30/arm734ddd03e4a01a087f7a7a9921e371a3df3b14adc96357c32efea888f2e385cea Miraielf mirai ua-wget
http://141.98.10.30/m68kn/an/aelf ua-wget
http://141.98.10.30/mipsb9af1689b7651a2114cf98f5b3aba25b818cc38382d72afb10cdcbaf7e1a0e0a Miraielf mirai ua-wget
http://141.98.10.30/mpsl2004b84cd216c52dc6b407a4d85092564a545b8358f87720ce7bf260343a597b Miraielf mirai ua-wget
http://141.98.10.30/ppcee14e4dfb3d49efd81f9459061ab49aa1f7f537cb2bc5f6c4ab81ca8f77fd6cb Hailbotelf HailBot ua-wget
http://141.98.10.30/sh4a2287ee119c76b2b77f49e8af1dde094519ec73a3bd68b146ea66ae9b4d9d325 Gafgytelf gafgyt ua-wget
http://141.98.10.30/spcn/an/aelf ua-wget
http://141.98.10.30/x8672854a8a556bcc78833b414e1e1311e289feeaa70e3189db0cf6dafdf69ceee7 Miraielf mirai ua-wget
http://141.98.10.30/x86_64n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox expand lolbin
Status:
terminated
Behavior Graph:
%3 guuid=eec2d36f-1a00-0000-5d66-34d11a0d0000 pid=3354 /usr/bin/sudo guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359 /tmp/sample.bin guuid=eec2d36f-1a00-0000-5d66-34d11a0d0000 pid=3354->guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359 execve guuid=d7e9fe72-1a00-0000-5d66-34d1210d0000 pid=3361 /usr/bin/busybox net send-data write-file guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=d7e9fe72-1a00-0000-5d66-34d1210d0000 pid=3361 execve guuid=f0d9387e-1a00-0000-5d66-34d1290d0000 pid=3369 /usr/bin/chmod guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=f0d9387e-1a00-0000-5d66-34d1290d0000 pid=3369 execve guuid=840ce47e-1a00-0000-5d66-34d12a0d0000 pid=3370 /usr/bin/dash guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=840ce47e-1a00-0000-5d66-34d12a0d0000 pid=3370 clone guuid=8ddb1780-1a00-0000-5d66-34d12c0d0000 pid=3372 /usr/bin/busybox net send-data write-file guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=8ddb1780-1a00-0000-5d66-34d12c0d0000 pid=3372 execve guuid=c0fe79d2-1a00-0000-5d66-34d12d0d0000 pid=3373 /usr/bin/chmod guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=c0fe79d2-1a00-0000-5d66-34d12d0d0000 pid=3373 execve guuid=2a79c7d2-1a00-0000-5d66-34d12f0d0000 pid=3375 /usr/bin/dash guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=2a79c7d2-1a00-0000-5d66-34d12f0d0000 pid=3375 clone guuid=49e211d5-1a00-0000-5d66-34d1310d0000 pid=3377 /usr/bin/busybox net send-data write-file guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=49e211d5-1a00-0000-5d66-34d1310d0000 pid=3377 execve guuid=06c53ce0-1a00-0000-5d66-34d1460d0000 pid=3398 /usr/bin/chmod guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=06c53ce0-1a00-0000-5d66-34d1460d0000 pid=3398 execve guuid=670dabe0-1a00-0000-5d66-34d1480d0000 pid=3400 /usr/bin/dash guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=670dabe0-1a00-0000-5d66-34d1480d0000 pid=3400 clone guuid=f2558de2-1a00-0000-5d66-34d14d0d0000 pid=3405 /usr/bin/busybox net send-data write-file guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=f2558de2-1a00-0000-5d66-34d14d0d0000 pid=3405 execve guuid=7602d6ec-1a00-0000-5d66-34d16a0d0000 pid=3434 /usr/bin/chmod guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=7602d6ec-1a00-0000-5d66-34d16a0d0000 pid=3434 execve guuid=6d3a19ed-1a00-0000-5d66-34d16c0d0000 pid=3436 /usr/bin/dash guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=6d3a19ed-1a00-0000-5d66-34d16c0d0000 pid=3436 clone guuid=63ca5eee-1a00-0000-5d66-34d1710d0000 pid=3441 /usr/bin/busybox net send-data guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=63ca5eee-1a00-0000-5d66-34d1710d0000 pid=3441 execve guuid=8ccfaaf2-1a00-0000-5d66-34d17e0d0000 pid=3454 /usr/bin/chmod guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=8ccfaaf2-1a00-0000-5d66-34d17e0d0000 pid=3454 execve guuid=4377f7f2-1a00-0000-5d66-34d1800d0000 pid=3456 /usr/bin/dash guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=4377f7f2-1a00-0000-5d66-34d1800d0000 pid=3456 clone guuid=ba3605f3-1a00-0000-5d66-34d1810d0000 pid=3457 /usr/bin/busybox net send-data write-file guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=ba3605f3-1a00-0000-5d66-34d1810d0000 pid=3457 execve guuid=befb79fd-1a00-0000-5d66-34d1a00d0000 pid=3488 /usr/bin/chmod guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=befb79fd-1a00-0000-5d66-34d1a00d0000 pid=3488 execve guuid=0bc1c3fd-1a00-0000-5d66-34d1a20d0000 pid=3490 /usr/bin/dash guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=0bc1c3fd-1a00-0000-5d66-34d1a20d0000 pid=3490 clone guuid=eaa49eff-1a00-0000-5d66-34d1a90d0000 pid=3497 /usr/bin/busybox net send-data write-file guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=eaa49eff-1a00-0000-5d66-34d1a90d0000 pid=3497 execve guuid=3192080a-1b00-0000-5d66-34d1bf0d0000 pid=3519 /usr/bin/chmod guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=3192080a-1b00-0000-5d66-34d1bf0d0000 pid=3519 execve guuid=51ec570a-1b00-0000-5d66-34d1c10d0000 pid=3521 /usr/bin/dash guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=51ec570a-1b00-0000-5d66-34d1c10d0000 pid=3521 clone guuid=2a37de0a-1b00-0000-5d66-34d1c50d0000 pid=3525 /usr/bin/busybox net send-data write-file guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=2a37de0a-1b00-0000-5d66-34d1c50d0000 pid=3525 execve guuid=cf6a2a15-1b00-0000-5d66-34d1d60d0000 pid=3542 /usr/bin/chmod guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=cf6a2a15-1b00-0000-5d66-34d1d60d0000 pid=3542 execve guuid=47c08515-1b00-0000-5d66-34d1d80d0000 pid=3544 /usr/bin/dash guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=47c08515-1b00-0000-5d66-34d1d80d0000 pid=3544 clone guuid=b33e3817-1b00-0000-5d66-34d1de0d0000 pid=3550 /usr/bin/busybox net send-data write-file guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=b33e3817-1b00-0000-5d66-34d1de0d0000 pid=3550 execve guuid=bc8fad21-1b00-0000-5d66-34d1ec0d0000 pid=3564 /usr/bin/chmod guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=bc8fad21-1b00-0000-5d66-34d1ec0d0000 pid=3564 execve guuid=88b6ea21-1b00-0000-5d66-34d1ed0d0000 pid=3565 /usr/bin/dash guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=88b6ea21-1b00-0000-5d66-34d1ed0d0000 pid=3565 clone guuid=c577a422-1b00-0000-5d66-34d1f10d0000 pid=3569 /usr/bin/busybox net send-data guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=c577a422-1b00-0000-5d66-34d1f10d0000 pid=3569 execve guuid=4f490227-1b00-0000-5d66-34d1000e0000 pid=3584 /usr/bin/chmod guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=4f490227-1b00-0000-5d66-34d1000e0000 pid=3584 execve guuid=46344627-1b00-0000-5d66-34d1020e0000 pid=3586 /usr/bin/dash guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=46344627-1b00-0000-5d66-34d1020e0000 pid=3586 clone guuid=49485127-1b00-0000-5d66-34d1030e0000 pid=3587 /usr/bin/busybox net send-data write-file guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=49485127-1b00-0000-5d66-34d1030e0000 pid=3587 execve guuid=0b2eb531-1b00-0000-5d66-34d11a0e0000 pid=3610 /usr/bin/chmod guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=0b2eb531-1b00-0000-5d66-34d11a0e0000 pid=3610 execve guuid=6250ff31-1b00-0000-5d66-34d11c0e0000 pid=3612 /home/sandbox/x86 guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=6250ff31-1b00-0000-5d66-34d11c0e0000 pid=3612 execve guuid=1aa67a33-1b00-0000-5d66-34d1220e0000 pid=3618 /usr/bin/busybox net send-data guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=1aa67a33-1b00-0000-5d66-34d1220e0000 pid=3618 execve guuid=2cfdf037-1b00-0000-5d66-34d1300e0000 pid=3632 /usr/bin/chmod guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=2cfdf037-1b00-0000-5d66-34d1300e0000 pid=3632 execve guuid=1a284638-1b00-0000-5d66-34d1320e0000 pid=3634 /usr/bin/dash guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=1a284638-1b00-0000-5d66-34d1320e0000 pid=3634 clone guuid=0b255138-1b00-0000-5d66-34d1330e0000 pid=3635 /usr/bin/rm delete-file guuid=84797272-1a00-0000-5d66-34d11f0d0000 pid=3359->guuid=0b255138-1b00-0000-5d66-34d1330e0000 pid=3635 execve 1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd 141.98.10.30:80 guuid=d7e9fe72-1a00-0000-5d66-34d1210d0000 pid=3361->1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd send: 78B guuid=8ddb1780-1a00-0000-5d66-34d12c0d0000 pid=3372->1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd send: 79B guuid=49e211d5-1a00-0000-5d66-34d1310d0000 pid=3377->1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd send: 79B guuid=f2558de2-1a00-0000-5d66-34d14d0d0000 pid=3405->1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd send: 79B guuid=63ca5eee-1a00-0000-5d66-34d1710d0000 pid=3441->1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd send: 79B guuid=ba3605f3-1a00-0000-5d66-34d1810d0000 pid=3457->1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd send: 79B guuid=eaa49eff-1a00-0000-5d66-34d1a90d0000 pid=3497->1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd send: 79B guuid=2a37de0a-1b00-0000-5d66-34d1c50d0000 pid=3525->1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd send: 78B guuid=b33e3817-1b00-0000-5d66-34d1de0d0000 pid=3550->1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd send: 78B guuid=c577a422-1b00-0000-5d66-34d1f10d0000 pid=3569->1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd send: 78B guuid=49485127-1b00-0000-5d66-34d1030e0000 pid=3587->1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd send: 78B guuid=c2d86233-1b00-0000-5d66-34d11e0e0000 pid=3614 /home/sandbox/ guuid=6250ff31-1b00-0000-5d66-34d11c0e0000 pid=3612->guuid=c2d86233-1b00-0000-5d66-34d11e0e0000 pid=3614 clone guuid=60876733-1b00-0000-5d66-34d11f0e0000 pid=3615 /home/sandbox/ zombie guuid=6250ff31-1b00-0000-5d66-34d11c0e0000 pid=3612->guuid=60876733-1b00-0000-5d66-34d11f0e0000 pid=3615 clone guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617 /home/sandbox/ dns net send-data zombie guuid=6250ff31-1b00-0000-5d66-34d11c0e0000 pid=3612->guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617 clone 1953617f-bd2b-56a9-9ede-0bea1c944f64 178.254.22.166:53 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->1953617f-bd2b-56a9-9ede-0bea1c944f64 send: 26B 84a380bc-aa57-5600-87c1-ca531ceab881 80.152.203.134:53 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->84a380bc-aa57-5600-87c1-ca531ceab881 send: 26B c006e0d4-15dc-58d0-b637-5f3998ed7693 mdw7.xyz:23021 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->c006e0d4-15dc-58d0-b637-5f3998ed7693 send: 13B 997a677b-e2e3-587d-b712-9bb3900e9b02 51.158.108.203:53 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->997a677b-e2e3-587d-b712-9bb3900e9b02 send: 52B dd220067-2456-5bea-8a97-717b3bf49707 mdw7.xyz:15453 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->dd220067-2456-5bea-8a97-717b3bf49707 send: 13B a7cd0bd1-5b44-573f-8ca4-bf2acb8b2248 217.160.70.42:53 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->a7cd0bd1-5b44-573f-8ca4-bf2acb8b2248 send: 52B c52bcfce-6084-5923-a3c9-4743bfff906c mdw7.xyz:25376 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->c52bcfce-6084-5923-a3c9-4743bfff906c send: 13B c0b60401-2787-5e57-85f9-7652823a4a8e 70.34.254.19:53 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->c0b60401-2787-5e57-85f9-7652823a4a8e send: 26B afe192fb-736d-5df2-ad22-9276ad1588e5 202.61.197.122:53 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->afe192fb-736d-5df2-ad22-9276ad1588e5 send: 52B ac0b4284-2aa4-5c89-80a0-995c690355af 81.169.136.222:53 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->ac0b4284-2aa4-5c89-80a0-995c690355af send: 26B b9c0fcda-ccfc-54e8-a56a-1c29e2527ab9 mdw7.xyz:3882 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->b9c0fcda-ccfc-54e8-a56a-1c29e2527ab9 send: 13B 8bd6ab2d-3d81-5b50-b8b7-b90478aa381c mdw7.xyz:10735 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->8bd6ab2d-3d81-5b50-b8b7-b90478aa381c send: 13B e7e3f3be-4c6e-5491-b4cf-189f3e7a0301 65.21.1.106:53 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->e7e3f3be-4c6e-5491-b4cf-189f3e7a0301 send: 26B 631adf9f-df1e-5135-8420-2d45a8006db1 mdw7.xyz:8112 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->631adf9f-df1e-5135-8420-2d45a8006db1 send: 13B 28064cf3-1023-5341-8222-1d2ca68f2c33 152.53.15.127:53 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->28064cf3-1023-5341-8222-1d2ca68f2c33 send: 26B f6f762bc-77b3-5e8f-a326-a7266bb02688 mdw7.xyz:6355 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->f6f762bc-77b3-5e8f-a326-a7266bb02688 send: 13B ebbab8e9-96d9-5e03-983f-484bde16a3ab mdw7.xyz:24452 guuid=5dd06e33-1b00-0000-5d66-34d1210e0000 pid=3617->ebbab8e9-96d9-5e03-983f-484bde16a3ab send: 13B guuid=1aa67a33-1b00-0000-5d66-34d1220e0000 pid=3618->1594cce3-e2b3-575f-b6ee-b2ba9ccbc1cd send: 81B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-08-21 05:39:34 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh cdd6936d8df252eebe2b249f6fe3dea581055d1bf22330043fb22f40065d7883

(this sample)

  
Delivery method
Distributed via web download

Comments