MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e1568cae97252fa9350ef2d2d381975c8bd29e11f126fb06bd64e92a73d7beb9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e1568cae97252fa9350ef2d2d381975c8bd29e11f126fb06bd64e92a73d7beb9
SHA3-384 hash: d0b14d69e6067eed8ff0b81cdfba8768fd0e83df6f10135be6976c30fd5b4c6993754ea00f6ce617be6c351d8bdff607
SHA1 hash: 1d5b8d5858ed9521bc305b362d2a99e24272bfa2
MD5 hash: afc7b029f3a05b97b920d0407791ee68
humanhash: october-mango-yankee-river
File name:wget.sh
Download: download sample
Signature Mirai
File size:600 bytes
First seen:2026-07-17 00:52:50 UTC
Last seen:2026-07-17 23:23:22 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:KhI5W3CtI1/TKxfvbQYpLOhPvqbiAE+8lHA:KOQyS1bkfvbZpLOSiAylg
TLSH T1E0F0AFD941016AE39F88D91F3953542D2242BBC931272FDCADCE25B9A284FD6F020E59
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://205.237.110.232/armc1bc5c236ac09f9bb74d2b2df4dac145da1afd6edaf9405cf7bce133ddd0459c Miraielf gafgyt mirai ua-wget
http://205.237.110.232/arm56690d52796a3b194421dcadef0f57c71a12983c5435cf234bd2014600e4fea28 Miraielf mirai ua-wget
http://205.237.110.232/arm7881d5a6b504c1b56324114757c4cf27cfd41c43ed49804eca0f1c5500bafedce Miraielf mirai ua-wget
http://205.237.110.232/mips0cbf6f10c9a39d628bb5c0a3810f25d2f58b37a4351045ab200c62154d03734e Gafgytelf gafgyt mirai ua-wget
http://205.237.110.232/mipsel8522dd99e4ea41eb22ebd4e2867d0a993e5c93ae2b3e55aad799808d9e01ca34 Miraimirai ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
78
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox downloader evasive mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-16T19:55:00Z UTC
Last seen:
2026-07-18T19:10:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=d2c24aac-1e00-0000-ccaa-937e5e140000 pid=5214 /usr/bin/sudo guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215 /tmp/sample.bin guuid=d2c24aac-1e00-0000-ccaa-937e5e140000 pid=5214->guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215 execve guuid=5e3cd8ae-1e00-0000-ccaa-937e60140000 pid=5216 /usr/bin/rm guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=5e3cd8ae-1e00-0000-ccaa-937e60140000 pid=5216 execve guuid=9c151caf-1e00-0000-ccaa-937e61140000 pid=5217 /usr/bin/rm guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=9c151caf-1e00-0000-ccaa-937e61140000 pid=5217 execve guuid=430e5baf-1e00-0000-ccaa-937e62140000 pid=5218 /usr/bin/rm guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=430e5baf-1e00-0000-ccaa-937e62140000 pid=5218 execve guuid=0a139baf-1e00-0000-ccaa-937e63140000 pid=5219 /usr/bin/rm guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=0a139baf-1e00-0000-ccaa-937e63140000 pid=5219 execve guuid=fc23dcaf-1e00-0000-ccaa-937e64140000 pid=5220 /usr/bin/rm guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=fc23dcaf-1e00-0000-ccaa-937e64140000 pid=5220 execve guuid=249f1eb0-1e00-0000-ccaa-937e65140000 pid=5221 /usr/bin/rm guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=249f1eb0-1e00-0000-ccaa-937e65140000 pid=5221 execve guuid=00385eb0-1e00-0000-ccaa-937e66140000 pid=5222 /usr/bin/rm guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=00385eb0-1e00-0000-ccaa-937e66140000 pid=5222 execve guuid=b16ea3b0-1e00-0000-ccaa-937e67140000 pid=5223 /usr/bin/busybox net send-data write-file guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=b16ea3b0-1e00-0000-ccaa-937e67140000 pid=5223 execve guuid=a0ca99b7-1e00-0000-ccaa-937e68140000 pid=5224 /usr/bin/chmod guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=a0ca99b7-1e00-0000-ccaa-937e68140000 pid=5224 execve guuid=7384efb7-1e00-0000-ccaa-937e69140000 pid=5225 /usr/bin/dash guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=7384efb7-1e00-0000-ccaa-937e69140000 pid=5225 clone guuid=c9d4c5b8-1e00-0000-ccaa-937e6b140000 pid=5227 /usr/bin/busybox net send-data write-file guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=c9d4c5b8-1e00-0000-ccaa-937e6b140000 pid=5227 execve guuid=6e8bc1bf-1e00-0000-ccaa-937e6c140000 pid=5228 /usr/bin/chmod guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=6e8bc1bf-1e00-0000-ccaa-937e6c140000 pid=5228 execve guuid=f0ef10c0-1e00-0000-ccaa-937e6d140000 pid=5229 /usr/bin/dash guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=f0ef10c0-1e00-0000-ccaa-937e6d140000 pid=5229 clone guuid=4fc8c4c0-1e00-0000-ccaa-937e6f140000 pid=5231 /usr/bin/busybox net send-data write-file guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=4fc8c4c0-1e00-0000-ccaa-937e6f140000 pid=5231 execve guuid=82019bc7-1e00-0000-ccaa-937e70140000 pid=5232 /usr/bin/chmod guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=82019bc7-1e00-0000-ccaa-937e70140000 pid=5232 execve guuid=179dffc7-1e00-0000-ccaa-937e71140000 pid=5233 /usr/bin/dash guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=179dffc7-1e00-0000-ccaa-937e71140000 pid=5233 clone guuid=56e68dc8-1e00-0000-ccaa-937e73140000 pid=5235 /usr/bin/busybox net send-data write-file guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=56e68dc8-1e00-0000-ccaa-937e73140000 pid=5235 execve guuid=0d417ecf-1e00-0000-ccaa-937e74140000 pid=5236 /usr/bin/chmod guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=0d417ecf-1e00-0000-ccaa-937e74140000 pid=5236 execve guuid=1711c5cf-1e00-0000-ccaa-937e75140000 pid=5237 /usr/bin/dash guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=1711c5cf-1e00-0000-ccaa-937e75140000 pid=5237 clone guuid=cbc25cd0-1e00-0000-ccaa-937e77140000 pid=5239 /usr/bin/busybox net send-data write-file guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=cbc25cd0-1e00-0000-ccaa-937e77140000 pid=5239 execve guuid=37e421d7-1e00-0000-ccaa-937e78140000 pid=5240 /usr/bin/chmod guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=37e421d7-1e00-0000-ccaa-937e78140000 pid=5240 execve guuid=9d146bd7-1e00-0000-ccaa-937e79140000 pid=5241 /usr/bin/dash guuid=f60e86ae-1e00-0000-ccaa-937e5f140000 pid=5215->guuid=9d146bd7-1e00-0000-ccaa-937e79140000 pid=5241 clone fa76a0f2-99b2-55a3-830c-43db003be0f4 205.237.110.232:80 guuid=b16ea3b0-1e00-0000-ccaa-937e67140000 pid=5223->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 81B guuid=c9d4c5b8-1e00-0000-ccaa-937e6b140000 pid=5227->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 82B guuid=4fc8c4c0-1e00-0000-ccaa-937e6f140000 pid=5231->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 82B guuid=56e68dc8-1e00-0000-ccaa-937e73140000 pid=5235->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 82B guuid=cbc25cd0-1e00-0000-ccaa-937e77140000 pid=5239->fa76a0f2-99b2-55a3-830c-43db003be0f4 send: 84B
Threat name:
Win32.Trojan.Malgent
Status:
Malicious
First seen:
2026-07-17 00:53:46 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh e1568cae97252fa9350ef2d2d381975c8bd29e11f126fb06bd64e92a73d7beb9

(this sample)

  
Delivery method
Distributed via web download

Comments