MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d104de180e0bd17c476d237adbb98155c78684ee0a123b356fdf8cdd62b5afde. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: d104de180e0bd17c476d237adbb98155c78684ee0a123b356fdf8cdd62b5afde
SHA3-384 hash: 6ddf8096ecc74ed4d59f1a19a4c84cff16d1f65ab66405c98330e9438a8737c30b75c53c36ebeb0e3548d04d217ff917
SHA1 hash: e3b24bc09c3f3d59c59e6fa10ba8103d9ab5f73c
MD5 hash: 858d5ab2594ec882c72dbd749c3f3423
humanhash: robin-sierra-eleven-five
File name:s.sh
Download: download sample
Signature Mirai
File size:1'400 bytes
First seen:2026-03-10 05:32:21 UTC
Last seen:2026-03-10 14:17:02 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:zbcSbKqWLCYLMKVNhhaILzFFrV+3Kqu+GLyA:v9bKqGLphnHzp+6PRT
TLSH T12021D2CA214116E1DB3E8D2D56D778C63CC400334091B78D7A4EAA8D2F61197735ABCE
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter adliwahid
Tags:mirai
URLMalware sample (SHA256 hash)SignatureTags
http://45.141.148.121/bins/n/an/an/a

Intelligence


File Origin
# of uploads :
3
# of downloads :
62
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=1034718e-1800-0000-1f4a-81cd7e0c0000 pid=3198 /usr/bin/sudo guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202 /tmp/sample.bin guuid=1034718e-1800-0000-1f4a-81cd7e0c0000 pid=3198->guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202 execve guuid=86bbd690-1800-0000-1f4a-81cd840c0000 pid=3204 /usr/bin/wget net send-data guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=86bbd690-1800-0000-1f4a-81cd840c0000 pid=3204 execve guuid=02329d97-1800-0000-1f4a-81cd8b0c0000 pid=3211 /usr/bin/curl net send-data write-file guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=02329d97-1800-0000-1f4a-81cd8b0c0000 pid=3211 execve guuid=73de3ba4-1800-0000-1f4a-81cd8c0c0000 pid=3212 /usr/bin/chmod guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=73de3ba4-1800-0000-1f4a-81cd8c0c0000 pid=3212 execve guuid=f2c9e0a4-1800-0000-1f4a-81cd8d0c0000 pid=3213 /usr/bin/bash guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=f2c9e0a4-1800-0000-1f4a-81cd8d0c0000 pid=3213 clone guuid=2cdf0fa5-1800-0000-1f4a-81cd8e0c0000 pid=3214 /usr/bin/wget net send-data write-file guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=2cdf0fa5-1800-0000-1f4a-81cd8e0c0000 pid=3214 execve guuid=911d70b0-1800-0000-1f4a-81cda10c0000 pid=3233 /usr/bin/chmod guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=911d70b0-1800-0000-1f4a-81cda10c0000 pid=3233 execve guuid=9f7bbfb0-1800-0000-1f4a-81cda30c0000 pid=3235 /usr/bin/bash guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=9f7bbfb0-1800-0000-1f4a-81cda30c0000 pid=3235 clone guuid=29f5d4b0-1800-0000-1f4a-81cda50c0000 pid=3237 /usr/bin/wget net send-data write-file guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=29f5d4b0-1800-0000-1f4a-81cda50c0000 pid=3237 execve guuid=ac1e54bd-1800-0000-1f4a-81cdb60c0000 pid=3254 /usr/bin/chmod guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=ac1e54bd-1800-0000-1f4a-81cdb60c0000 pid=3254 execve guuid=0fd8a2bd-1800-0000-1f4a-81cdb80c0000 pid=3256 /usr/bin/bash guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=0fd8a2bd-1800-0000-1f4a-81cdb80c0000 pid=3256 clone guuid=e8c1adbd-1800-0000-1f4a-81cdb90c0000 pid=3257 /usr/bin/wget net send-data write-file guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=e8c1adbd-1800-0000-1f4a-81cdb90c0000 pid=3257 execve guuid=b791c4c6-1800-0000-1f4a-81cdc60c0000 pid=3270 /usr/bin/chmod guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=b791c4c6-1800-0000-1f4a-81cdc60c0000 pid=3270 execve guuid=b50106c7-1800-0000-1f4a-81cdc80c0000 pid=3272 /usr/bin/bash guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=b50106c7-1800-0000-1f4a-81cdc80c0000 pid=3272 clone guuid=6d172cc7-1800-0000-1f4a-81cdca0c0000 pid=3274 /usr/bin/wget net send-data write-file guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=6d172cc7-1800-0000-1f4a-81cdca0c0000 pid=3274 execve guuid=a41dd4d1-1800-0000-1f4a-81cdea0c0000 pid=3306 /usr/bin/chmod guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=a41dd4d1-1800-0000-1f4a-81cdea0c0000 pid=3306 execve guuid=b7d01fd2-1800-0000-1f4a-81cdec0c0000 pid=3308 /usr/bin/bash guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=b7d01fd2-1800-0000-1f4a-81cdec0c0000 pid=3308 clone guuid=faee2bd2-1800-0000-1f4a-81cdee0c0000 pid=3310 /usr/bin/wget net send-data write-file guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=faee2bd2-1800-0000-1f4a-81cdee0c0000 pid=3310 execve guuid=6d507eda-1800-0000-1f4a-81cd040d0000 pid=3332 /usr/bin/chmod guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=6d507eda-1800-0000-1f4a-81cd040d0000 pid=3332 execve guuid=8e35d3da-1800-0000-1f4a-81cd070d0000 pid=3335 /usr/bin/bash guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=8e35d3da-1800-0000-1f4a-81cd070d0000 pid=3335 clone guuid=c3e1e3da-1800-0000-1f4a-81cd090d0000 pid=3337 /usr/bin/wget net send-data write-file guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=c3e1e3da-1800-0000-1f4a-81cd090d0000 pid=3337 execve guuid=92b134e3-1800-0000-1f4a-81cd140d0000 pid=3348 /usr/bin/chmod guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=92b134e3-1800-0000-1f4a-81cd140d0000 pid=3348 execve guuid=f2d8a3e3-1800-0000-1f4a-81cd150d0000 pid=3349 /usr/bin/bash guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=f2d8a3e3-1800-0000-1f4a-81cd150d0000 pid=3349 clone guuid=5aacb7e3-1800-0000-1f4a-81cd170d0000 pid=3351 /usr/bin/wget net send-data write-file guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=5aacb7e3-1800-0000-1f4a-81cd170d0000 pid=3351 execve guuid=c1f7acec-1800-0000-1f4a-81cd1e0d0000 pid=3358 /usr/bin/chmod guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=c1f7acec-1800-0000-1f4a-81cd1e0d0000 pid=3358 execve guuid=bf25f1ec-1800-0000-1f4a-81cd200d0000 pid=3360 /usr/bin/bash guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=bf25f1ec-1800-0000-1f4a-81cd200d0000 pid=3360 clone guuid=c8aa02ed-1800-0000-1f4a-81cd220d0000 pid=3362 /usr/bin/wget net send-data write-file guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=c8aa02ed-1800-0000-1f4a-81cd220d0000 pid=3362 execve guuid=9e4a0df8-1800-0000-1f4a-81cd3d0d0000 pid=3389 /usr/bin/chmod guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=9e4a0df8-1800-0000-1f4a-81cd3d0d0000 pid=3389 execve guuid=c1e24cf8-1800-0000-1f4a-81cd3f0d0000 pid=3391 /usr/bin/bash guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=c1e24cf8-1800-0000-1f4a-81cd3f0d0000 pid=3391 clone guuid=0dcf5df8-1800-0000-1f4a-81cd410d0000 pid=3393 /usr/bin/wget net send-data write-file guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=0dcf5df8-1800-0000-1f4a-81cd410d0000 pid=3393 execve guuid=8cc37103-1900-0000-1f4a-81cd600d0000 pid=3424 /usr/bin/chmod guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=8cc37103-1900-0000-1f4a-81cd600d0000 pid=3424 execve guuid=36bac503-1900-0000-1f4a-81cd620d0000 pid=3426 /usr/bin/bash guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=36bac503-1900-0000-1f4a-81cd620d0000 pid=3426 clone guuid=4bc6d703-1900-0000-1f4a-81cd630d0000 pid=3427 /usr/bin/wget net send-data write-file guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=4bc6d703-1900-0000-1f4a-81cd630d0000 pid=3427 execve guuid=57dc2a0c-1900-0000-1f4a-81cd790d0000 pid=3449 /usr/bin/chmod guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=57dc2a0c-1900-0000-1f4a-81cd790d0000 pid=3449 execve guuid=4d25880c-1900-0000-1f4a-81cd7b0d0000 pid=3451 /tmp/melodic.x86 delete-file net guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=4d25880c-1900-0000-1f4a-81cd7b0d0000 pid=3451 execve guuid=b8c29a0c-1900-0000-1f4a-81cd7d0d0000 pid=3453 /usr/bin/mv guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=b8c29a0c-1900-0000-1f4a-81cd7d0d0000 pid=3453 execve guuid=c14a2e0d-1900-0000-1f4a-81cd830d0000 pid=3459 /usr/bin/mv guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=c14a2e0d-1900-0000-1f4a-81cd830d0000 pid=3459 execve guuid=9c844a0e-1900-0000-1f4a-81cd8a0d0000 pid=3466 /usr/bin/mv guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=9c844a0e-1900-0000-1f4a-81cd8a0d0000 pid=3466 execve guuid=bb8db823-1900-0000-1f4a-81cdc80d0000 pid=3528 /usr/bin/mv guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=bb8db823-1900-0000-1f4a-81cdc80d0000 pid=3528 execve guuid=72545124-1900-0000-1f4a-81cdca0d0000 pid=3530 /usr/bin/mv guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=72545124-1900-0000-1f4a-81cdca0d0000 pid=3530 execve guuid=4732a328-1900-0000-1f4a-81cdd40d0000 pid=3540 /usr/bin/mv guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=4732a328-1900-0000-1f4a-81cdd40d0000 pid=3540 execve guuid=57101f2c-1900-0000-1f4a-81cdd50d0000 pid=3541 /usr/bin/mv guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=57101f2c-1900-0000-1f4a-81cdd50d0000 pid=3541 execve guuid=fc15842c-1900-0000-1f4a-81cdd60d0000 pid=3542 /usr/bin/mv guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=fc15842c-1900-0000-1f4a-81cdd60d0000 pid=3542 execve guuid=9ce47c2e-1900-0000-1f4a-81cdd70d0000 pid=3543 /usr/bin/mv guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=9ce47c2e-1900-0000-1f4a-81cdd70d0000 pid=3543 execve guuid=8aa2eb2e-1900-0000-1f4a-81cddb0d0000 pid=3547 /usr/bin/mv guuid=42257c90-1800-0000-1f4a-81cd820c0000 pid=3202->guuid=8aa2eb2e-1900-0000-1f4a-81cddb0d0000 pid=3547 execve 68d482af-04aa-5171-a538-027a48926c95 45.141.148.121:80 guuid=86bbd690-1800-0000-1f4a-81cd840c0000 pid=3204->68d482af-04aa-5171-a538-027a48926c95 send: 137B guuid=02329d97-1800-0000-1f4a-81cd8b0c0000 pid=3211->68d482af-04aa-5171-a538-027a48926c95 send: 86B guuid=2cdf0fa5-1800-0000-1f4a-81cd8e0c0000 pid=3214->68d482af-04aa-5171-a538-027a48926c95 send: 138B guuid=29f5d4b0-1800-0000-1f4a-81cda50c0000 pid=3237->68d482af-04aa-5171-a538-027a48926c95 send: 138B guuid=e8c1adbd-1800-0000-1f4a-81cdb90c0000 pid=3257->68d482af-04aa-5171-a538-027a48926c95 send: 138B guuid=6d172cc7-1800-0000-1f4a-81cdca0c0000 pid=3274->68d482af-04aa-5171-a538-027a48926c95 send: 138B guuid=faee2bd2-1800-0000-1f4a-81cdee0c0000 pid=3310->68d482af-04aa-5171-a538-027a48926c95 send: 138B guuid=c3e1e3da-1800-0000-1f4a-81cd090d0000 pid=3337->68d482af-04aa-5171-a538-027a48926c95 send: 138B guuid=5aacb7e3-1800-0000-1f4a-81cd170d0000 pid=3351->68d482af-04aa-5171-a538-027a48926c95 send: 137B guuid=c8aa02ed-1800-0000-1f4a-81cd220d0000 pid=3362->68d482af-04aa-5171-a538-027a48926c95 send: 137B guuid=0dcf5df8-1800-0000-1f4a-81cd410d0000 pid=3393->68d482af-04aa-5171-a538-027a48926c95 send: 137B guuid=4bc6d703-1900-0000-1f4a-81cd630d0000 pid=3427->68d482af-04aa-5171-a538-027a48926c95 send: 137B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=4d25880c-1900-0000-1f4a-81cd7b0d0000 pid=3451->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4ec4200d-1900-0000-1f4a-81cd7f0d0000 pid=3455 /tmp/melodic.x86 guuid=4d25880c-1900-0000-1f4a-81cd7b0d0000 pid=3451->guuid=4ec4200d-1900-0000-1f4a-81cd7f0d0000 pid=3455 clone guuid=3c7c240d-1900-0000-1f4a-81cd800d0000 pid=3456 /tmp/melodic.x86 net net-scan send-data zombie guuid=4d25880c-1900-0000-1f4a-81cd7b0d0000 pid=3451->guuid=3c7c240d-1900-0000-1f4a-81cd800d0000 pid=3456 clone guuid=1480280d-1900-0000-1f4a-81cd810d0000 pid=3457 /tmp/melodic.x86 net net-scan send-data zombie guuid=4d25880c-1900-0000-1f4a-81cd7b0d0000 pid=3451->guuid=1480280d-1900-0000-1f4a-81cd810d0000 pid=3457 clone guuid=acb32d0d-1900-0000-1f4a-81cd820d0000 pid=3458 /tmp/melodic.x86 net net-scan send-data zombie guuid=4d25880c-1900-0000-1f4a-81cd7b0d0000 pid=3451->guuid=acb32d0d-1900-0000-1f4a-81cd820d0000 pid=3458 clone guuid=caab460d-1900-0000-1f4a-81cd850d0000 pid=3461 /tmp/melodic.x86 net send-data zombie guuid=4d25880c-1900-0000-1f4a-81cd7b0d0000 pid=3451->guuid=caab460d-1900-0000-1f4a-81cd850d0000 pid=3461 clone guuid=3c7c240d-1900-0000-1f4a-81cd800d0000 pid=3456->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e50f5c51-596e-58e0-add8-30b8821d6493 95.215.84.136:80 guuid=3c7c240d-1900-0000-1f4a-81cd800d0000 pid=3456->e50f5c51-596e-58e0-add8-30b8821d6493 send: 40B f585accf-be1a-5f3e-9717-374406ddeee4 66.70.198.77:80 guuid=3c7c240d-1900-0000-1f4a-81cd800d0000 pid=3456->f585accf-be1a-5f3e-9717-374406ddeee4 send: 40B 10fc3af1-3f40-5a30-887b-ca6721802df1 13.227.165.174:80 guuid=3c7c240d-1900-0000-1f4a-81cd800d0000 pid=3456->10fc3af1-3f40-5a30-887b-ca6721802df1 send: 40B 707aa497-e1df-5d32-b618-8b5bf7e8e628 43.174.242.193:80 guuid=3c7c240d-1900-0000-1f4a-81cd800d0000 pid=3456->707aa497-e1df-5d32-b618-8b5bf7e8e628 send: 40B 8a6204d0-410f-5c2c-a02b-72088e2a5dbe 102.224.243.79:80 guuid=3c7c240d-1900-0000-1f4a-81cd800d0000 pid=3456->8a6204d0-410f-5c2c-a02b-72088e2a5dbe send: 40B guuid=3c7c240d-1900-0000-1f4a-81cd800d0000 pid=3456|send-data send-data to 4097 IP addresses review logs to see them all guuid=3c7c240d-1900-0000-1f4a-81cd800d0000 pid=3456->guuid=3c7c240d-1900-0000-1f4a-81cd800d0000 pid=3456|send-data send guuid=1480280d-1900-0000-1f4a-81cd810d0000 pid=3457->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1480280d-1900-0000-1f4a-81cd810d0000 pid=3457|send-data send-data to 4097 IP addresses review logs to see them all guuid=1480280d-1900-0000-1f4a-81cd810d0000 pid=3457->guuid=1480280d-1900-0000-1f4a-81cd810d0000 pid=3457|send-data send guuid=acb32d0d-1900-0000-1f4a-81cd820d0000 pid=3458->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=acb32d0d-1900-0000-1f4a-81cd820d0000 pid=3458|send-data send-data to 4097 IP addresses review logs to see them all guuid=acb32d0d-1900-0000-1f4a-81cd820d0000 pid=3458->guuid=acb32d0d-1900-0000-1f4a-81cd820d0000 pid=3458|send-data send guuid=caab460d-1900-0000-1f4a-81cd850d0000 pid=3461->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 337e0a31-5653-52da-a4cb-8964effb61f7 255.255.255.255:80 guuid=caab460d-1900-0000-1f4a-81cd850d0000 pid=3461->337e0a31-5653-52da-a4cb-8964effb61f7 con 5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 0.0.0.0:0 guuid=caab460d-1900-0000-1f4a-81cd850d0000 pid=3461->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 425B guuid=7a18620d-1900-0000-1f4a-81cd860d0000 pid=3462 /tmp/melodic.x86 guuid=caab460d-1900-0000-1f4a-81cd850d0000 pid=3461->guuid=7a18620d-1900-0000-1f4a-81cd860d0000 pid=3462 clone
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2026-03-08 03:07:28 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (71322) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d104de180e0bd17c476d237adbb98155c78684ee0a123b356fdf8cdd62b5afde

(this sample)

  
Delivery method
Distributed via web download

Comments