MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e38ded5a8729c8fa35a0743e5a540a5322be9295a4a0d5318585b63c5b21dd4e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: e38ded5a8729c8fa35a0743e5a540a5322be9295a4a0d5318585b63c5b21dd4e
SHA3-384 hash: 0f369b19c4687d9cccbdc43ea51bf4a5fa8dcfe966493ba89ba94ff6226f3e572e199ecd1f57a6eb9d0ed06baf98dab2
SHA1 hash: 9494bbcb01402914e4191971424a3a8dfdf4ee7e
MD5 hash: 0af9eca8c3c87dd088ad867f19b1d5a5
humanhash: finch-mexico-lithium-india
File name:k
Download: download sample
Signature Mirai
File size:935 bytes
First seen:2025-09-26 16:30:39 UTC
Last seen:2025-09-27 13:05:33 UTC
File type: sh
MIME type:text/plain
ssdeep 12:dZoJ2egeKNWKDbnPZM5ZMoOF7+MB05+X2yTkX2ygDNkSXtvkXtMDNkSXUkX/DNkK:E22IbO5zOt+MB00kS0mkQksXS8bv
TLSH T14211E7CF11B19C325CD549DE71934D1878CBC9FC1BCACE89748A043AB48991CF176E8A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://194.31.222.17/kk/armv7lc08227c99e5c062c360c13a7e23e0eba8786615f3a68c8b4abe1305898084cc5 Miraielf mirai ua-wget
http://194.31.222.17/kk/armv5l196d4187438354ffda9b8a211b1dbb69e789036bc98c9b533584c38ee1b6ad9d Miraielf mirai ua-wget
http://194.31.222.17/kk/armv4lfa2969618c11630496f8784ca73bfb3734ceb7b7d6bc861729ab1080a3e70a55 Miraielf mirai ua-wget
http://s.cuckstudios.su/k36f94f7b717fece32e851360ea73f0fc45e2a0ab5f790c239203eae13744e121 MiraiDEU geofenced mirai opendir sh ua-wget USA

Intelligence


File Origin
# of uploads :
2
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
ps1
First seen:
2025-09-26T13:45:00Z UTC
Last seen:
2025-09-26T13:45:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=e8eab753-1900-0000-5a4a-b76f5e140000 pid=5214 /usr/bin/sudo guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223 /tmp/sample.bin guuid=e8eab753-1900-0000-5a4a-b76f5e140000 pid=5214->guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223 execve guuid=91b52256-1900-0000-5a4a-b76f68140000 pid=5224 /usr/bin/dash guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=91b52256-1900-0000-5a4a-b76f68140000 pid=5224 clone guuid=36eb1057-1900-0000-5a4a-b76f6e140000 pid=5230 /usr/bin/rm delete-file guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=36eb1057-1900-0000-5a4a-b76f6e140000 pid=5230 execve guuid=c1a36057-1900-0000-5a4a-b76f6f140000 pid=5231 /usr/bin/rm delete-file guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=c1a36057-1900-0000-5a4a-b76f6f140000 pid=5231 execve guuid=5de6bc57-1900-0000-5a4a-b76f70140000 pid=5232 /usr/bin/rm delete-file guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=5de6bc57-1900-0000-5a4a-b76f70140000 pid=5232 execve guuid=e73b0758-1900-0000-5a4a-b76f71140000 pid=5233 /usr/bin/dash guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=e73b0758-1900-0000-5a4a-b76f71140000 pid=5233 clone guuid=e1aebc58-1900-0000-5a4a-b76f73140000 pid=5235 /usr/bin/dash guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=e1aebc58-1900-0000-5a4a-b76f73140000 pid=5235 clone guuid=fe6f0259-1900-0000-5a4a-b76f75140000 pid=5237 /usr/bin/dash guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=fe6f0259-1900-0000-5a4a-b76f75140000 pid=5237 clone guuid=4a366462-1900-0000-5a4a-b76f77140000 pid=5239 /usr/bin/chmod guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=4a366462-1900-0000-5a4a-b76f77140000 pid=5239 execve guuid=e0c1ab62-1900-0000-5a4a-b76f78140000 pid=5240 /usr/bin/dash guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=e0c1ab62-1900-0000-5a4a-b76f78140000 pid=5240 clone guuid=6fee9d63-1900-0000-5a4a-b76f7a140000 pid=5242 /usr/bin/dash guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=6fee9d63-1900-0000-5a4a-b76f7a140000 pid=5242 clone guuid=8e65a96c-1900-0000-5a4a-b76f7c140000 pid=5244 /usr/bin/chmod guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=8e65a96c-1900-0000-5a4a-b76f7c140000 pid=5244 execve guuid=ccc3266d-1900-0000-5a4a-b76f7d140000 pid=5245 /usr/bin/dash guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=ccc3266d-1900-0000-5a4a-b76f7d140000 pid=5245 clone guuid=6fc54c6f-1900-0000-5a4a-b76f7f140000 pid=5247 /usr/bin/dash guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=6fc54c6f-1900-0000-5a4a-b76f7f140000 pid=5247 clone guuid=79671478-1900-0000-5a4a-b76f81140000 pid=5249 /usr/bin/chmod guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=79671478-1900-0000-5a4a-b76f81140000 pid=5249 execve guuid=15e18778-1900-0000-5a4a-b76f82140000 pid=5250 /usr/bin/dash guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=15e18778-1900-0000-5a4a-b76f82140000 pid=5250 clone guuid=b2aa527a-1900-0000-5a4a-b76f84140000 pid=5252 /usr/bin/grep guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=b2aa527a-1900-0000-5a4a-b76f84140000 pid=5252 execve guuid=5608c97a-1900-0000-5a4a-b76f85140000 pid=5253 /usr/bin/sed guuid=e95fe255-1900-0000-5a4a-b76f67140000 pid=5223->guuid=5608c97a-1900-0000-5a4a-b76f85140000 pid=5253 execve guuid=a9843156-1900-0000-5a4a-b76f69140000 pid=5225 /usr/bin/cat guuid=91b52256-1900-0000-5a4a-b76f68140000 pid=5224->guuid=a9843156-1900-0000-5a4a-b76f69140000 pid=5225 execve guuid=097a3856-1900-0000-5a4a-b76f6a140000 pid=5226 /usr/bin/grep guuid=91b52256-1900-0000-5a4a-b76f68140000 pid=5224->guuid=097a3856-1900-0000-5a4a-b76f6a140000 pid=5226 execve guuid=c6cd3f56-1900-0000-5a4a-b76f6b140000 pid=5227 /usr/bin/grep guuid=91b52256-1900-0000-5a4a-b76f68140000 pid=5224->guuid=c6cd3f56-1900-0000-5a4a-b76f6b140000 pid=5227 execve guuid=ce624656-1900-0000-5a4a-b76f6c140000 pid=5228 /usr/bin/grep guuid=91b52256-1900-0000-5a4a-b76f68140000 pid=5224->guuid=ce624656-1900-0000-5a4a-b76f6c140000 pid=5228 execve guuid=5ef54e56-1900-0000-5a4a-b76f6d140000 pid=5229 /usr/bin/cut guuid=91b52256-1900-0000-5a4a-b76f68140000 pid=5224->guuid=5ef54e56-1900-0000-5a4a-b76f6d140000 pid=5229 execve guuid=4b4c0e58-1900-0000-5a4a-b76f72140000 pid=5234 /usr/bin/cp write-file guuid=e73b0758-1900-0000-5a4a-b76f71140000 pid=5233->guuid=4b4c0e58-1900-0000-5a4a-b76f72140000 pid=5234 execve guuid=781ec558-1900-0000-5a4a-b76f74140000 pid=5236 /usr/bin/chmod guuid=e1aebc58-1900-0000-5a4a-b76f73140000 pid=5235->guuid=781ec558-1900-0000-5a4a-b76f74140000 pid=5236 execve guuid=ee441059-1900-0000-5a4a-b76f76140000 pid=5238 /usr/bin/wget net send-data write-file guuid=fe6f0259-1900-0000-5a4a-b76f75140000 pid=5237->guuid=ee441059-1900-0000-5a4a-b76f76140000 pid=5238 execve 287749b9-1937-53b1-8818-44b73ae22708 194.31.222.17:80 guuid=ee441059-1900-0000-5a4a-b76f76140000 pid=5238->287749b9-1937-53b1-8818-44b73ae22708 send: 137B guuid=1136a763-1900-0000-5a4a-b76f7b140000 pid=5243 /usr/bin/wget net send-data write-file guuid=6fee9d63-1900-0000-5a4a-b76f7a140000 pid=5242->guuid=1136a763-1900-0000-5a4a-b76f7b140000 pid=5243 execve guuid=1136a763-1900-0000-5a4a-b76f7b140000 pid=5243->287749b9-1937-53b1-8818-44b73ae22708 send: 137B guuid=ed9a576f-1900-0000-5a4a-b76f80140000 pid=5248 /usr/bin/wget net send-data write-file guuid=6fc54c6f-1900-0000-5a4a-b76f7f140000 pid=5247->guuid=ed9a576f-1900-0000-5a4a-b76f80140000 pid=5248 execve guuid=ed9a576f-1900-0000-5a4a-b76f80140000 pid=5248->287749b9-1937-53b1-8818-44b73ae22708 send: 137B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2025-09-26 16:37:47 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh e38ded5a8729c8fa35a0743e5a540a5322be9295a4a0d5318585b63c5b21dd4e

(this sample)

  
Delivery method
Distributed via web download

Comments