MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dee7280b9ec3ff17e82622fd920eb9fc2aa38f20085ba5699c442dc533922e19. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: dee7280b9ec3ff17e82622fd920eb9fc2aa38f20085ba5699c442dc533922e19
SHA3-384 hash: 389fc27e281b21a4a28c783a859065f43f78adaa1ec3a23974e4bbc0cd1fc0121e33716aae52a461618e268b857e3146
SHA1 hash: 53e26b6210f5b1569838bc0b0aa9b960aac4e551
MD5 hash: 0d3398c9a828d832c72324ee97dc22ac
humanhash: pip-six-river-oranges
File name:kla.sh
Download: download sample
Signature Mirai
File size:1'667 bytes
First seen:2026-06-19 20:49:33 UTC
Last seen:2026-06-20 18:19:31 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:2RKhEcfEnsTE1hxjuDujPDtjtD3jiDajZfDZp:2RKhEcfEnsTE1PmG71VzaiZLZp
TLSH T19931B0C411D218B03DE28C27626AD998F4C57A41FEC64E40A0DEF8F9988CF49B455FB3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://62.60.159.184/bins/pmips1673174d77e84ad23d04496efa5264bd429fc3c2a38259ac22949a2156534372 Mirai62-60-159-184 elf mirai
http://62.60.159.184/bins/pmpslb05b56bf91c6024cf1cc2869e09fd1a35aff2496f0f7363c84b10e15d171fbfe Mirai62-60-159-184 elf mirai
http://62.60.159.184/bins/parm4b1975ada28b892fd1b2ea2b4527e1764c29b342070afaa49fac6d68a0dafa76 Mirai62-60-159-184 elf mirai
http://62.60.159.184/bins/parm7f940bb807d9320fb673210c1405612f4f8839074e28211792cf21cdc3ee2f609 Mirai62-60-159-184 elf mirai
http://62.60.159.184/bins/px8641c7efdbb651b767e907b30220ebe5f8b9d7a029eaca782a05d70875d69fa4d8 Mirai62-60-159-184 elf mirai

Intelligence


File Origin
# of uploads :
3
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-19T17:55:00Z UTC
Last seen:
2026-06-19T23:59:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=562c625a-1900-0000-9df6-9aa201100000 pid=4097 /usr/bin/sudo guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101 /tmp/sample.bin guuid=562c625a-1900-0000-9df6-9aa201100000 pid=4097->guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101 execve guuid=fbc6785d-1900-0000-9df6-9aa208100000 pid=4104 /usr/bin/cp guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=fbc6785d-1900-0000-9df6-9aa208100000 pid=4104 execve guuid=0e6ba963-1900-0000-9df6-9aa219100000 pid=4121 /usr/bin/bash guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=0e6ba963-1900-0000-9df6-9aa219100000 pid=4121 clone guuid=6673f66f-1900-0000-9df6-9aa247100000 pid=4167 /usr/bin/chmod guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=6673f66f-1900-0000-9df6-9aa247100000 pid=4167 execve guuid=e8eb3570-1900-0000-9df6-9aa248100000 pid=4168 /usr/bin/bash guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=e8eb3570-1900-0000-9df6-9aa248100000 pid=4168 clone guuid=673cf671-1900-0000-9df6-9aa252100000 pid=4178 /usr/bin/bash guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=673cf671-1900-0000-9df6-9aa252100000 pid=4178 clone guuid=ffb4fd7c-1900-0000-9df6-9aa286100000 pid=4230 /usr/bin/chmod guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=ffb4fd7c-1900-0000-9df6-9aa286100000 pid=4230 execve guuid=6bea777d-1900-0000-9df6-9aa287100000 pid=4231 /usr/bin/bash guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=6bea777d-1900-0000-9df6-9aa287100000 pid=4231 clone guuid=636f617f-1900-0000-9df6-9aa28f100000 pid=4239 /usr/bin/bash guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=636f617f-1900-0000-9df6-9aa28f100000 pid=4239 clone guuid=c6681889-1900-0000-9df6-9aa2ad100000 pid=4269 /usr/bin/chmod guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=c6681889-1900-0000-9df6-9aa2ad100000 pid=4269 execve guuid=999f8a89-1900-0000-9df6-9aa2ae100000 pid=4270 /usr/bin/bash guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=999f8a89-1900-0000-9df6-9aa2ae100000 pid=4270 clone guuid=9b5e698b-1900-0000-9df6-9aa2b4100000 pid=4276 /usr/bin/bash guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=9b5e698b-1900-0000-9df6-9aa2b4100000 pid=4276 clone guuid=5224bd96-1900-0000-9df6-9aa2e1100000 pid=4321 /usr/bin/chmod guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=5224bd96-1900-0000-9df6-9aa2e1100000 pid=4321 execve guuid=f3f11897-1900-0000-9df6-9aa2e5100000 pid=4325 /usr/bin/bash guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=f3f11897-1900-0000-9df6-9aa2e5100000 pid=4325 clone guuid=ca2ece97-1900-0000-9df6-9aa2ea100000 pid=4330 /usr/bin/bash guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=ca2ece97-1900-0000-9df6-9aa2ea100000 pid=4330 clone guuid=8e5b9ca1-1900-0000-9df6-9aa218110000 pid=4376 /usr/bin/chmod guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=8e5b9ca1-1900-0000-9df6-9aa218110000 pid=4376 execve guuid=1e18e3a1-1900-0000-9df6-9aa21a110000 pid=4378 /tmp/robben delete-file net guuid=f17d1f5d-1900-0000-9df6-9aa205100000 pid=4101->guuid=1e18e3a1-1900-0000-9df6-9aa21a110000 pid=4378 execve guuid=58a0b663-1900-0000-9df6-9aa21a100000 pid=4122 /usr/bin/wget net send-data write-file guuid=0e6ba963-1900-0000-9df6-9aa219100000 pid=4121->guuid=58a0b663-1900-0000-9df6-9aa21a100000 pid=4122 execve 7d2242f1-89d6-5d80-84bd-baabba4a66be 62.60.159.184:80 guuid=58a0b663-1900-0000-9df6-9aa21a100000 pid=4122->7d2242f1-89d6-5d80-84bd-baabba4a66be send: 138B guuid=48d20c72-1900-0000-9df6-9aa253100000 pid=4179 /usr/bin/wget net send-data write-file guuid=673cf671-1900-0000-9df6-9aa252100000 pid=4178->guuid=48d20c72-1900-0000-9df6-9aa253100000 pid=4179 execve guuid=48d20c72-1900-0000-9df6-9aa253100000 pid=4179->7d2242f1-89d6-5d80-84bd-baabba4a66be send: 138B guuid=767a6f7f-1900-0000-9df6-9aa290100000 pid=4240 /usr/bin/wget net send-data write-file guuid=636f617f-1900-0000-9df6-9aa28f100000 pid=4239->guuid=767a6f7f-1900-0000-9df6-9aa290100000 pid=4240 execve guuid=767a6f7f-1900-0000-9df6-9aa290100000 pid=4240->7d2242f1-89d6-5d80-84bd-baabba4a66be send: 137B guuid=c1e27b8b-1900-0000-9df6-9aa2b5100000 pid=4277 /usr/bin/wget net send-data write-file guuid=9b5e698b-1900-0000-9df6-9aa2b4100000 pid=4276->guuid=c1e27b8b-1900-0000-9df6-9aa2b5100000 pid=4277 execve guuid=c1e27b8b-1900-0000-9df6-9aa2b5100000 pid=4277->7d2242f1-89d6-5d80-84bd-baabba4a66be send: 138B guuid=852adc97-1900-0000-9df6-9aa2ed100000 pid=4333 /usr/bin/wget net send-data write-file guuid=ca2ece97-1900-0000-9df6-9aa2ea100000 pid=4330->guuid=852adc97-1900-0000-9df6-9aa2ed100000 pid=4333 execve guuid=852adc97-1900-0000-9df6-9aa2ed100000 pid=4333->7d2242f1-89d6-5d80-84bd-baabba4a66be send: 137B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=1e18e3a1-1900-0000-9df6-9aa21a110000 pid=4378->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e2cccea2-1900-0000-9df6-9aa21d110000 pid=4381 /tmp/robben net send-data zombie guuid=1e18e3a1-1900-0000-9df6-9aa21a110000 pid=4378->guuid=e2cccea2-1900-0000-9df6-9aa21d110000 pid=4381 clone guuid=b4f0d1a2-1900-0000-9df6-9aa21e110000 pid=4382 /tmp/robben guuid=1e18e3a1-1900-0000-9df6-9aa21a110000 pid=4378->guuid=b4f0d1a2-1900-0000-9df6-9aa21e110000 pid=4382 clone guuid=e2cccea2-1900-0000-9df6-9aa21d110000 pid=4381->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con cdd9a59d-ebea-5ef6-bf59-6b5cacebbc95 62.60.159.184:18129 guuid=e2cccea2-1900-0000-9df6-9aa21d110000 pid=4381->cdd9a59d-ebea-5ef6-bf59-6b5cacebbc95 send: 19B guuid=fc54e4a2-1900-0000-9df6-9aa21f110000 pid=4383 /tmp/robben guuid=e2cccea2-1900-0000-9df6-9aa21d110000 pid=4381->guuid=fc54e4a2-1900-0000-9df6-9aa21f110000 pid=4383 clone guuid=4dd6e7a2-1900-0000-9df6-9aa220110000 pid=4384 /tmp/robben guuid=e2cccea2-1900-0000-9df6-9aa21d110000 pid=4381->guuid=4dd6e7a2-1900-0000-9df6-9aa220110000 pid=4384 clone guuid=330ff6f6-1b00-0000-9df6-9aa255140000 pid=5205 /usr/bin/dash guuid=b4f0d1a2-1900-0000-9df6-9aa21e110000 pid=4382->guuid=330ff6f6-1b00-0000-9df6-9aa255140000 pid=5205 execve guuid=9386944b-1e00-0000-9df6-9aa276140000 pid=5238 /usr/bin/dash guuid=b4f0d1a2-1900-0000-9df6-9aa21e110000 pid=4382->guuid=9386944b-1e00-0000-9df6-9aa276140000 pid=5238 execve guuid=b68e24a0-2000-0000-9df6-9aa277140000 pid=5239 /usr/bin/dash guuid=b4f0d1a2-1900-0000-9df6-9aa21e110000 pid=4382->guuid=b68e24a0-2000-0000-9df6-9aa277140000 pid=5239 execve guuid=8e99c0f4-2200-0000-9df6-9aa278140000 pid=5240 /usr/bin/dash guuid=b4f0d1a2-1900-0000-9df6-9aa21e110000 pid=4382->guuid=8e99c0f4-2200-0000-9df6-9aa278140000 pid=5240 execve guuid=125f2849-2500-0000-9df6-9aa279140000 pid=5241 /usr/bin/dash guuid=b4f0d1a2-1900-0000-9df6-9aa21e110000 pid=4382->guuid=125f2849-2500-0000-9df6-9aa279140000 pid=5241 execve
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-19 20:51:05 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh dee7280b9ec3ff17e82622fd920eb9fc2aa38f20085ba5699c442dc533922e19

(this sample)

  
Delivery method
Distributed via web download

Comments