MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd1729a3b92e049c5dd5e0000881cbc244b82ab684eb985f117405595ee2ed36. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: dd1729a3b92e049c5dd5e0000881cbc244b82ab684eb985f117405595ee2ed36
SHA3-384 hash: b7f14666706656404d989b1be2826e7e5303624242ba8d0e72a0cd01ec54c6c01c84845b63b163fe397e3beec1e6fe69
SHA1 hash: 7c6b77e3038315bf3d73ec399635c765afde53ea
MD5 hash: 86b9083ce3d52daba1a0723d84905a2a
humanhash: freddie-uranus-six-hot
File name:mwah
Download: download sample
Signature Mirai
File size:763 bytes
First seen:2025-11-06 22:58:28 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:vWOZF85ZMNM2V4ZMBAZOUNHWXwYA2caKWcITUcIT2CIRlG1lcITUcITC:uOZF85EMy0MBoLVWA72pPSYM1lS4
TLSH T18901F5CF34A18920A99045A5B6938A28F288D1D65DC217CCED6A4CA9548DDDD3415EC6
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://93.157.106.238:9001/pppoebd025b87c4b51bd661b8e84abfa8c18e837c96afbc45d9ed7c6994714664853bf Miraiarm elf geofenced mirai ua-wget USA
http://93.157.106.238:9001/mwah70c7ea52d5c83fee1478d87a415b568b77b649fa45cce7b503c66df195888fe3 Miraigeofenced mirai sh ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-06T20:16:00Z UTC
Last seen:
2025-11-08T10:35:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=1a022421-1700-0000-85de-ec25e30e0000 pid=3811 /usr/bin/sudo guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817 /tmp/sample.bin write-config guuid=1a022421-1700-0000-85de-ec25e30e0000 pid=3811->guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817 execve guuid=97e2dd22-1700-0000-85de-ec25eb0e0000 pid=3819 /usr/bin/dash guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817->guuid=97e2dd22-1700-0000-85de-ec25eb0e0000 pid=3819 clone guuid=2c138723-1700-0000-85de-ec25f30e0000 pid=3827 /usr/bin/cp write-file guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817->guuid=2c138723-1700-0000-85de-ec25f30e0000 pid=3827 execve guuid=81cf042a-1700-0000-85de-ec25f80e0000 pid=3832 /usr/bin/chmod guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817->guuid=81cf042a-1700-0000-85de-ec25f80e0000 pid=3832 execve guuid=c5477d2a-1700-0000-85de-ec25f90e0000 pid=3833 /usr/bin/dash guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817->guuid=c5477d2a-1700-0000-85de-ec25f90e0000 pid=3833 clone guuid=89ac6236-1700-0000-85de-ec251c0f0000 pid=3868 /usr/bin/chmod guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817->guuid=89ac6236-1700-0000-85de-ec251c0f0000 pid=3868 execve guuid=9db4a136-1700-0000-85de-ec251d0f0000 pid=3869 /usr/bin/dash guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817->guuid=9db4a136-1700-0000-85de-ec251d0f0000 pid=3869 clone guuid=e1e02037-1700-0000-85de-ec25200f0000 pid=3872 /usr/bin/rm delete-file guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817->guuid=e1e02037-1700-0000-85de-ec25200f0000 pid=3872 execve guuid=230a6337-1700-0000-85de-ec25210f0000 pid=3873 /usr/bin/grep guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817->guuid=230a6337-1700-0000-85de-ec25210f0000 pid=3873 execve guuid=b118cb37-1700-0000-85de-ec25250f0000 pid=3877 /usr/bin/chmod guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817->guuid=b118cb37-1700-0000-85de-ec25250f0000 pid=3877 execve guuid=fcdaf737-1700-0000-85de-ec25260f0000 pid=3878 /usr/bin/grep guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817->guuid=fcdaf737-1700-0000-85de-ec25260f0000 pid=3878 execve guuid=1788ba38-1700-0000-85de-ec252b0f0000 pid=3883 /usr/bin/sed guuid=14a6ab22-1700-0000-85de-ec25e90e0000 pid=3817->guuid=1788ba38-1700-0000-85de-ec252b0f0000 pid=3883 execve guuid=4f16e622-1700-0000-85de-ec25ec0e0000 pid=3820 /usr/bin/cat guuid=97e2dd22-1700-0000-85de-ec25eb0e0000 pid=3819->guuid=4f16e622-1700-0000-85de-ec25ec0e0000 pid=3820 execve guuid=5016ec22-1700-0000-85de-ec25ed0e0000 pid=3821 /usr/bin/grep guuid=97e2dd22-1700-0000-85de-ec25eb0e0000 pid=3819->guuid=5016ec22-1700-0000-85de-ec25ed0e0000 pid=3821 execve guuid=de31ef22-1700-0000-85de-ec25ee0e0000 pid=3822 /usr/bin/grep guuid=97e2dd22-1700-0000-85de-ec25eb0e0000 pid=3819->guuid=de31ef22-1700-0000-85de-ec25ee0e0000 pid=3822 execve guuid=48a2f222-1700-0000-85de-ec25ef0e0000 pid=3823 /usr/bin/grep guuid=97e2dd22-1700-0000-85de-ec25eb0e0000 pid=3819->guuid=48a2f222-1700-0000-85de-ec25ef0e0000 pid=3823 execve guuid=5d33f622-1700-0000-85de-ec25f00e0000 pid=3824 /usr/bin/cut guuid=97e2dd22-1700-0000-85de-ec25eb0e0000 pid=3819->guuid=5d33f622-1700-0000-85de-ec25f00e0000 pid=3824 execve guuid=28de932a-1700-0000-85de-ec25fa0e0000 pid=3834 /usr/bin/wget net send-data write-file guuid=c5477d2a-1700-0000-85de-ec25f90e0000 pid=3833->guuid=28de932a-1700-0000-85de-ec25fa0e0000 pid=3834 execve e4cbdf26-f2d9-58b7-8184-7056f5df458e 93.157.106.238:9001 guuid=28de932a-1700-0000-85de-ec25fa0e0000 pid=3834->e4cbdf26-f2d9-58b7-8184-7056f5df458e send: 140B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-11-06 23:13:49 UTC
File Type:
Text (Shell)
AV detection:
8 of 23 (34.78%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh dd1729a3b92e049c5dd5e0000881cbc244b82ab684eb985f117405595ee2ed36

(this sample)

  
Delivery method
Distributed via web download

Comments