MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e13d556c847b49ef767ded960734aa7fbbb3ec6f250c510094412afa79ac1593. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: e13d556c847b49ef767ded960734aa7fbbb3ec6f250c510094412afa79ac1593
SHA3-384 hash: 1423f3d14db0af8d7ee103ca4578591b5b0a7c8001d0586f46a6d5a2888a6b33b6d915e69868a5068017c94e2fd0c030
SHA1 hash: c0b612647ae7ea17594c2f7581dd49364fb24e88
MD5 hash: a052a91e075777272cf02ead986041e9
humanhash: romeo-music-whiskey-green
File name:123.sh
Download: download sample
Signature Mirai
File size:821 bytes
First seen:2025-08-01 13:39:35 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:yjJErl5kJP9By4qsICWJhd4qsICPv4qoCWJoe4qod/l1esQ9M9wQN/wOy0:jenqt7gqtMwqo7Mqod/l1+MvN/Ly0
TLSH T10001BDF651A009732DC9883D71DB848D55BE30836821D5687F8D743C3B2755AADB06CF
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=59d58214-1800-0000-26bc-493ece0b0000 pid=3022 /usr/bin/sudo guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029 /tmp/sample.bin guuid=59d58214-1800-0000-26bc-493ece0b0000 pid=3022->guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029 execve guuid=bad59416-1800-0000-26bc-493ed70b0000 pid=3031 /usr/bin/wget net send-data write-file guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=bad59416-1800-0000-26bc-493ed70b0000 pid=3031 execve guuid=e7bc881d-1800-0000-26bc-493eef0b0000 pid=3055 /usr/bin/chmod guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=e7bc881d-1800-0000-26bc-493eef0b0000 pid=3055 execve guuid=7f51df1d-1800-0000-26bc-493ef00b0000 pid=3056 /usr/bin/bash guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=7f51df1d-1800-0000-26bc-493ef00b0000 pid=3056 clone guuid=7397ee1d-1800-0000-26bc-493ef10b0000 pid=3057 /usr/bin/wget net send-data write-file guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=7397ee1d-1800-0000-26bc-493ef10b0000 pid=3057 execve guuid=332daf23-1800-0000-26bc-493e010c0000 pid=3073 /usr/bin/chmod guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=332daf23-1800-0000-26bc-493e010c0000 pid=3073 execve guuid=7618f023-1800-0000-26bc-493e030c0000 pid=3075 /usr/bin/bash guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=7618f023-1800-0000-26bc-493e030c0000 pid=3075 clone guuid=b21ff923-1800-0000-26bc-493e040c0000 pid=3076 /usr/bin/wget net send-data write-file guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=b21ff923-1800-0000-26bc-493e040c0000 pid=3076 execve guuid=4fd56129-1800-0000-26bc-493e180c0000 pid=3096 /usr/bin/chmod guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=4fd56129-1800-0000-26bc-493e180c0000 pid=3096 execve guuid=86429c29-1800-0000-26bc-493e1a0c0000 pid=3098 /usr/bin/bash guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=86429c29-1800-0000-26bc-493e1a0c0000 pid=3098 clone guuid=83fda429-1800-0000-26bc-493e1b0c0000 pid=3099 /usr/bin/wget net send-data write-file guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=83fda429-1800-0000-26bc-493e1b0c0000 pid=3099 execve guuid=2e9f172f-1800-0000-26bc-493e2d0c0000 pid=3117 /usr/bin/chmod guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=2e9f172f-1800-0000-26bc-493e2d0c0000 pid=3117 execve guuid=1b86602f-1800-0000-26bc-493e2f0c0000 pid=3119 /usr/bin/bash guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=1b86602f-1800-0000-26bc-493e2f0c0000 pid=3119 clone guuid=a9926d2f-1800-0000-26bc-493e300c0000 pid=3120 /usr/bin/wget net send-data write-file guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=a9926d2f-1800-0000-26bc-493e300c0000 pid=3120 execve guuid=6d69d134-1800-0000-26bc-493e420c0000 pid=3138 /usr/bin/chmod guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=6d69d134-1800-0000-26bc-493e420c0000 pid=3138 execve guuid=67416f35-1800-0000-26bc-493e450c0000 pid=3141 /usr/bin/bash guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=67416f35-1800-0000-26bc-493e450c0000 pid=3141 clone guuid=976b7a35-1800-0000-26bc-493e460c0000 pid=3142 /usr/bin/wget net send-data write-file guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=976b7a35-1800-0000-26bc-493e460c0000 pid=3142 execve guuid=28c2a93a-1800-0000-26bc-493e550c0000 pid=3157 /usr/bin/chmod guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=28c2a93a-1800-0000-26bc-493e550c0000 pid=3157 execve guuid=d223ee3a-1800-0000-26bc-493e570c0000 pid=3159 /usr/bin/bash guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=d223ee3a-1800-0000-26bc-493e570c0000 pid=3159 clone guuid=1b42f83a-1800-0000-26bc-493e580c0000 pid=3160 /usr/bin/wget net send-data write-file guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=1b42f83a-1800-0000-26bc-493e580c0000 pid=3160 execve guuid=74b8d641-1800-0000-26bc-493e6a0c0000 pid=3178 /usr/bin/chmod guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=74b8d641-1800-0000-26bc-493e6a0c0000 pid=3178 execve guuid=0a752e42-1800-0000-26bc-493e6c0c0000 pid=3180 /usr/bin/bash guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=0a752e42-1800-0000-26bc-493e6c0c0000 pid=3180 clone guuid=7d4b3842-1800-0000-26bc-493e6d0c0000 pid=3181 /usr/bin/wget net send-data write-file guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=7d4b3842-1800-0000-26bc-493e6d0c0000 pid=3181 execve guuid=efe8924e-1800-0000-26bc-493e780c0000 pid=3192 /usr/bin/chmod guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=efe8924e-1800-0000-26bc-493e780c0000 pid=3192 execve guuid=b368e54e-1800-0000-26bc-493e790c0000 pid=3193 /usr/bin/bash guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=b368e54e-1800-0000-26bc-493e790c0000 pid=3193 clone guuid=c47cef4e-1800-0000-26bc-493e7a0c0000 pid=3194 /usr/bin/wget net send-data write-file guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=c47cef4e-1800-0000-26bc-493e7a0c0000 pid=3194 execve guuid=9f454a54-1800-0000-26bc-493e7c0c0000 pid=3196 /usr/bin/chmod guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=9f454a54-1800-0000-26bc-493e7c0c0000 pid=3196 execve guuid=439cc554-1800-0000-26bc-493e7d0c0000 pid=3197 /usr/bin/bash guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=439cc554-1800-0000-26bc-493e7d0c0000 pid=3197 clone guuid=61e0d154-1800-0000-26bc-493e7e0c0000 pid=3198 /usr/bin/wget net send-data write-file guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=61e0d154-1800-0000-26bc-493e7e0c0000 pid=3198 execve guuid=f8885959-1800-0000-26bc-493e800c0000 pid=3200 /usr/bin/chmod guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=f8885959-1800-0000-26bc-493e800c0000 pid=3200 execve guuid=293cb959-1800-0000-26bc-493e810c0000 pid=3201 /usr/bin/bash guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=293cb959-1800-0000-26bc-493e810c0000 pid=3201 clone guuid=f121d259-1800-0000-26bc-493e830c0000 pid=3203 /usr/bin/wget net send-data write-file guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=f121d259-1800-0000-26bc-493e830c0000 pid=3203 execve guuid=472cb25e-1800-0000-26bc-493e860c0000 pid=3206 /usr/bin/chmod guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=472cb25e-1800-0000-26bc-493e860c0000 pid=3206 execve guuid=c888f45e-1800-0000-26bc-493e880c0000 pid=3208 /tmp/main_x86 delete-file net guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=c888f45e-1800-0000-26bc-493e880c0000 pid=3208 execve guuid=bbdcfe5e-1800-0000-26bc-493e890c0000 pid=3209 /usr/bin/wget net send-data write-file guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=bbdcfe5e-1800-0000-26bc-493e890c0000 pid=3209 execve guuid=da3a1964-1800-0000-26bc-493e9b0c0000 pid=3227 /usr/bin/chmod guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=da3a1964-1800-0000-26bc-493e9b0c0000 pid=3227 execve guuid=43d06264-1800-0000-26bc-493e9d0c0000 pid=3229 /tmp/main_x86_64 guuid=5cc12f16-1800-0000-26bc-493ed50b0000 pid=3029->guuid=43d06264-1800-0000-26bc-493e9d0c0000 pid=3229 execve 88b0cd47-b0bd-5918-aeb7-5f87fcd431ec 198.55.98.107:80 guuid=bad59416-1800-0000-26bc-493ed70b0000 pid=3031->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 136B guuid=7397ee1d-1800-0000-26bc-493ef10b0000 pid=3057->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 137B guuid=b21ff923-1800-0000-26bc-493e040c0000 pid=3076->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 137B guuid=83fda429-1800-0000-26bc-493e1b0c0000 pid=3099->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 137B guuid=a9926d2f-1800-0000-26bc-493e300c0000 pid=3120->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 137B guuid=976b7a35-1800-0000-26bc-493e460c0000 pid=3142->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 137B guuid=1b42f83a-1800-0000-26bc-493e580c0000 pid=3160->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 139B guuid=7d4b3842-1800-0000-26bc-493e6d0c0000 pid=3181->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 136B guuid=c47cef4e-1800-0000-26bc-493e7a0c0000 pid=3194->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 136B guuid=61e0d154-1800-0000-26bc-493e7e0c0000 pid=3198->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 136B guuid=f121d259-1800-0000-26bc-493e830c0000 pid=3203->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=c888f45e-1800-0000-26bc-493e880c0000 pid=3208->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=715f235f-1800-0000-26bc-493e8b0c0000 pid=3211 /tmp/main_x86 dns net send-data zombie guuid=c888f45e-1800-0000-26bc-493e880c0000 pid=3208->guuid=715f235f-1800-0000-26bc-493e8b0c0000 pid=3211 clone guuid=bbdcfe5e-1800-0000-26bc-493e890c0000 pid=3209->88b0cd47-b0bd-5918-aeb7-5f87fcd431ec send: 139B guuid=715f235f-1800-0000-26bc-493e8b0c0000 pid=3211->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 30B 1b298986-c1a2-51c3-8ea4-731b8031d0c6 botnet.eu.cc:1995 guuid=715f235f-1800-0000-26bc-493e8b0c0000 pid=3211->1b298986-c1a2-51c3-8ea4-731b8031d0c6 send: 18B guuid=914c355f-1800-0000-26bc-493e8c0c0000 pid=3212 /tmp/main_x86 guuid=715f235f-1800-0000-26bc-493e8b0c0000 pid=3211->guuid=914c355f-1800-0000-26bc-493e8c0c0000 pid=3212 clone
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2025-07-31 16:19:00 UTC
File Type:
Text (Shell)
AV detection:
3 of 23 (13.04%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads process memory
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Mirai
Mirai family
Malware Config
C2 Extraction:
botnet.eu.cc
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh e13d556c847b49ef767ded960734aa7fbbb3ec6f250c510094412afa79ac1593

(this sample)

  
Delivery method
Distributed via web download

Comments