MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e524cac93a03d73520cd259dd0f4e66a6af7eb47dffcf98628d389f0507adbbd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: e524cac93a03d73520cd259dd0f4e66a6af7eb47dffcf98628d389f0507adbbd
SHA3-384 hash: ed74feb59967324a18c4f8565dc2b43229b5c4473050c4e6ba5e55818688f4d68e96fdb4ae4e4032fbf373a41475a3e2
SHA1 hash: 4f995ba5f6db800999d7e6794e635949914e03e0
MD5 hash: 21e63f86eea3b10e8fa623cd25dd9569
humanhash: bluebird-yellow-july-solar
File name:sh
Download: download sample
File size:273 bytes
First seen:2026-01-24 06:16:47 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:/VJ+pUKUF2RVYKXhHYZIUy5p3FsDKVKhOXqIKa03IKq1IEE1IKBKW:/VJ+jRpJYZWghsONI08W
TLSH T100D0C24DF84208B7B47448B966DB2445D60F929C2A0A958D5145422BB8E4C90A020517
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=9864c1db-1800-0000-83ef-ad8ab50a0000 pid=2741 /usr/bin/sudo guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748 /tmp/sample.bin guuid=9864c1db-1800-0000-83ef-ad8ab50a0000 pid=2741->guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748 execve guuid=5d7b9bdd-1800-0000-83ef-ad8abd0a0000 pid=2749 /usr/bin/wget net send-data write-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=5d7b9bdd-1800-0000-83ef-ad8abd0a0000 pid=2749 execve guuid=e4f863f2-1800-0000-83ef-ad8ae10a0000 pid=2785 /usr/bin/chmod guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=e4f863f2-1800-0000-83ef-ad8ae10a0000 pid=2785 execve guuid=e116acf2-1800-0000-83ef-ad8ae30a0000 pid=2787 /usr/bin/dash guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=e116acf2-1800-0000-83ef-ad8ae30a0000 pid=2787 clone guuid=522735f3-1800-0000-83ef-ad8ae60a0000 pid=2790 /usr/bin/rm delete-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=522735f3-1800-0000-83ef-ad8ae60a0000 pid=2790 execve guuid=2a3384f3-1800-0000-83ef-ad8ae80a0000 pid=2792 /usr/bin/wget net send-data write-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=2a3384f3-1800-0000-83ef-ad8ae80a0000 pid=2792 execve guuid=3cc02707-1900-0000-83ef-ad8a090b0000 pid=2825 /usr/bin/chmod guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=3cc02707-1900-0000-83ef-ad8a090b0000 pid=2825 execve guuid=be1f8607-1900-0000-83ef-ad8a0b0b0000 pid=2827 /usr/bin/dash guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=be1f8607-1900-0000-83ef-ad8a0b0b0000 pid=2827 clone guuid=bcc75908-1900-0000-83ef-ad8a0f0b0000 pid=2831 /usr/bin/rm delete-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=bcc75908-1900-0000-83ef-ad8a0f0b0000 pid=2831 execve guuid=0de16d09-1900-0000-83ef-ad8a120b0000 pid=2834 /usr/bin/wget net send-data write-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=0de16d09-1900-0000-83ef-ad8a120b0000 pid=2834 execve guuid=bdd5851c-1900-0000-83ef-ad8a440b0000 pid=2884 /usr/bin/chmod guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=bdd5851c-1900-0000-83ef-ad8a440b0000 pid=2884 execve guuid=2b30bf1c-1900-0000-83ef-ad8a450b0000 pid=2885 /usr/bin/dash guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=2b30bf1c-1900-0000-83ef-ad8a450b0000 pid=2885 clone guuid=040d4c1d-1900-0000-83ef-ad8a490b0000 pid=2889 /usr/bin/rm delete-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=040d4c1d-1900-0000-83ef-ad8a490b0000 pid=2889 execve guuid=64748f1d-1900-0000-83ef-ad8a4b0b0000 pid=2891 /usr/bin/wget net send-data write-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=64748f1d-1900-0000-83ef-ad8a4b0b0000 pid=2891 execve guuid=84be4930-1900-0000-83ef-ad8a750b0000 pid=2933 /usr/bin/chmod guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=84be4930-1900-0000-83ef-ad8a750b0000 pid=2933 execve guuid=e25a8730-1900-0000-83ef-ad8a770b0000 pid=2935 /usr/bin/dash guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=e25a8730-1900-0000-83ef-ad8a770b0000 pid=2935 clone guuid=3bf28831-1900-0000-83ef-ad8a7c0b0000 pid=2940 /usr/bin/rm delete-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=3bf28831-1900-0000-83ef-ad8a7c0b0000 pid=2940 execve guuid=6d4ec731-1900-0000-83ef-ad8a7e0b0000 pid=2942 /usr/bin/wget net send-data write-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=6d4ec731-1900-0000-83ef-ad8a7e0b0000 pid=2942 execve guuid=bbac7d44-1900-0000-83ef-ad8aa30b0000 pid=2979 /usr/bin/chmod guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=bbac7d44-1900-0000-83ef-ad8aa30b0000 pid=2979 execve guuid=23b6bd44-1900-0000-83ef-ad8aa40b0000 pid=2980 /usr/bin/dash guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=23b6bd44-1900-0000-83ef-ad8aa40b0000 pid=2980 clone guuid=031e4846-1900-0000-83ef-ad8aab0b0000 pid=2987 /usr/bin/rm delete-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=031e4846-1900-0000-83ef-ad8aab0b0000 pid=2987 execve guuid=f2f78246-1900-0000-83ef-ad8aad0b0000 pid=2989 /usr/bin/wget net send-data write-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=f2f78246-1900-0000-83ef-ad8aad0b0000 pid=2989 execve guuid=8ebd155f-1900-0000-83ef-ad8aee0b0000 pid=3054 /usr/bin/chmod guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=8ebd155f-1900-0000-83ef-ad8aee0b0000 pid=3054 execve guuid=8c48965f-1900-0000-83ef-ad8af10b0000 pid=3057 /usr/bin/dash guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=8c48965f-1900-0000-83ef-ad8af10b0000 pid=3057 clone guuid=c964f061-1900-0000-83ef-ad8af90b0000 pid=3065 /usr/bin/rm delete-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=c964f061-1900-0000-83ef-ad8af90b0000 pid=3065 execve guuid=d74d4c62-1900-0000-83ef-ad8afb0b0000 pid=3067 /usr/bin/wget net send-data write-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=d74d4c62-1900-0000-83ef-ad8afb0b0000 pid=3067 execve guuid=8ee0fb7a-1900-0000-83ef-ad8a340c0000 pid=3124 /usr/bin/chmod guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=8ee0fb7a-1900-0000-83ef-ad8a340c0000 pid=3124 execve guuid=0116807b-1900-0000-83ef-ad8a360c0000 pid=3126 /usr/bin/dash guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=0116807b-1900-0000-83ef-ad8a360c0000 pid=3126 clone guuid=2fa0aa7c-1900-0000-83ef-ad8a3a0c0000 pid=3130 /usr/bin/rm delete-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=2fa0aa7c-1900-0000-83ef-ad8a3a0c0000 pid=3130 execve guuid=3748247d-1900-0000-83ef-ad8a3d0c0000 pid=3133 /usr/bin/wget net send-data write-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=3748247d-1900-0000-83ef-ad8a3d0c0000 pid=3133 execve guuid=83015290-1900-0000-83ef-ad8a650c0000 pid=3173 /usr/bin/chmod guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=83015290-1900-0000-83ef-ad8a650c0000 pid=3173 execve guuid=59b0e790-1900-0000-83ef-ad8a670c0000 pid=3175 /usr/bin/dash guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=59b0e790-1900-0000-83ef-ad8a670c0000 pid=3175 clone guuid=1fd97d92-1900-0000-83ef-ad8a6d0c0000 pid=3181 /usr/bin/rm delete-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=1fd97d92-1900-0000-83ef-ad8a6d0c0000 pid=3181 execve guuid=63ec1d93-1900-0000-83ef-ad8a6e0c0000 pid=3182 /usr/bin/wget net send-data write-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=63ec1d93-1900-0000-83ef-ad8a6e0c0000 pid=3182 execve guuid=4a1765a8-1900-0000-83ef-ad8a910c0000 pid=3217 /usr/bin/chmod guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=4a1765a8-1900-0000-83ef-ad8a910c0000 pid=3217 execve guuid=423e0ba9-1900-0000-83ef-ad8a930c0000 pid=3219 /tmp/cron.kvariant net guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=423e0ba9-1900-0000-83ef-ad8a930c0000 pid=3219 execve guuid=ecf38ba9-1900-0000-83ef-ad8a960c0000 pid=3222 /usr/bin/rm delete-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=ecf38ba9-1900-0000-83ef-ad8a960c0000 pid=3222 execve guuid=3bd008aa-1900-0000-83ef-ad8a990c0000 pid=3225 /usr/bin/wget net send-data guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=3bd008aa-1900-0000-83ef-ad8a990c0000 pid=3225 execve guuid=ad4a6eb7-1900-0000-83ef-ad8aa60c0000 pid=3238 /usr/bin/chmod guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=ad4a6eb7-1900-0000-83ef-ad8aa60c0000 pid=3238 execve guuid=af2862c1-1900-0000-83ef-ad8aa80c0000 pid=3240 /tmp/cron.kvariant guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=af2862c1-1900-0000-83ef-ad8aa80c0000 pid=3240 execve guuid=d921dbc2-1900-0000-83ef-ad8aaa0c0000 pid=3242 /usr/bin/rm delete-file guuid=d1ba68dd-1800-0000-83ef-ad8abc0a0000 pid=2748->guuid=d921dbc2-1900-0000-83ef-ad8aaa0c0000 pid=3242 execve 754c9895-f526-5c23-835d-e9aa002cfebe 192.227.152.84:80 guuid=5d7b9bdd-1800-0000-83ef-ad8abd0a0000 pid=2749->754c9895-f526-5c23-835d-e9aa002cfebe send: 148B guuid=2a3384f3-1800-0000-83ef-ad8ae80a0000 pid=2792->754c9895-f526-5c23-835d-e9aa002cfebe send: 148B guuid=0de16d09-1900-0000-83ef-ad8a120b0000 pid=2834->754c9895-f526-5c23-835d-e9aa002cfebe send: 147B guuid=64748f1d-1900-0000-83ef-ad8a4b0b0000 pid=2891->754c9895-f526-5c23-835d-e9aa002cfebe send: 148B guuid=6d4ec731-1900-0000-83ef-ad8a7e0b0000 pid=2942->754c9895-f526-5c23-835d-e9aa002cfebe send: 148B guuid=f2f78246-1900-0000-83ef-ad8aad0b0000 pid=2989->754c9895-f526-5c23-835d-e9aa002cfebe send: 148B guuid=d74d4c62-1900-0000-83ef-ad8afb0b0000 pid=3067->754c9895-f526-5c23-835d-e9aa002cfebe send: 147B guuid=3748247d-1900-0000-83ef-ad8a3d0c0000 pid=3133->754c9895-f526-5c23-835d-e9aa002cfebe send: 147B guuid=63ec1d93-1900-0000-83ef-ad8a6e0c0000 pid=3182->754c9895-f526-5c23-835d-e9aa002cfebe send: 147B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=423e0ba9-1900-0000-83ef-ad8a930c0000 pid=3219->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1d9c7ba9-1900-0000-83ef-ad8a950c0000 pid=3221 /tmp/cron.kvariant net send-data zombie guuid=423e0ba9-1900-0000-83ef-ad8a930c0000 pid=3219->guuid=1d9c7ba9-1900-0000-83ef-ad8a950c0000 pid=3221 clone guuid=1d9c7ba9-1900-0000-83ef-ad8a950c0000 pid=3221->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 68b96d34-2bd8-5d1a-872f-ffb88dbcaafa 172.245.10.175:5555 guuid=1d9c7ba9-1900-0000-83ef-ad8a950c0000 pid=3221->68b96d34-2bd8-5d1a-872f-ffb88dbcaafa send: 15B guuid=65cb9ca9-1900-0000-83ef-ad8a970c0000 pid=3223 /tmp/cron.kvariant guuid=1d9c7ba9-1900-0000-83ef-ad8a950c0000 pid=3221->guuid=65cb9ca9-1900-0000-83ef-ad8a970c0000 pid=3223 clone guuid=941e50e5-1900-0000-83ef-ad8ad60c0000 pid=3286 /tmp/cron.kvariant net net-scan send-data guuid=1d9c7ba9-1900-0000-83ef-ad8a950c0000 pid=3221->guuid=941e50e5-1900-0000-83ef-ad8ad60c0000 pid=3286 clone guuid=abee59e5-1900-0000-83ef-ad8ad70c0000 pid=3287 /tmp/cron.kvariant net net-scan send-data guuid=1d9c7ba9-1900-0000-83ef-ad8a950c0000 pid=3221->guuid=abee59e5-1900-0000-83ef-ad8ad70c0000 pid=3287 clone guuid=5f8d65e5-1900-0000-83ef-ad8ad80c0000 pid=3288 /tmp/cron.kvariant net net-scan send-data guuid=1d9c7ba9-1900-0000-83ef-ad8a950c0000 pid=3221->guuid=5f8d65e5-1900-0000-83ef-ad8ad80c0000 pid=3288 clone guuid=23bc6de5-1900-0000-83ef-ad8ad90c0000 pid=3289 /tmp/cron.kvariant net net-scan send-data guuid=1d9c7ba9-1900-0000-83ef-ad8a950c0000 pid=3221->guuid=23bc6de5-1900-0000-83ef-ad8ad90c0000 pid=3289 clone guuid=594b82e5-1900-0000-83ef-ad8ada0c0000 pid=3290 /tmp/cron.kvariant net net-scan send-data guuid=1d9c7ba9-1900-0000-83ef-ad8a950c0000 pid=3221->guuid=594b82e5-1900-0000-83ef-ad8ada0c0000 pid=3290 clone guuid=da8a91e5-1900-0000-83ef-ad8adb0c0000 pid=3291 /tmp/cron.kvariant net net-scan send-data guuid=1d9c7ba9-1900-0000-83ef-ad8a950c0000 pid=3221->guuid=da8a91e5-1900-0000-83ef-ad8adb0c0000 pid=3291 clone guuid=39899fe5-1900-0000-83ef-ad8adc0c0000 pid=3292 /tmp/cron.kvariant guuid=1d9c7ba9-1900-0000-83ef-ad8a950c0000 pid=3221->guuid=39899fe5-1900-0000-83ef-ad8adc0c0000 pid=3292 clone guuid=3bd008aa-1900-0000-83ef-ad8a990c0000 pid=3225->754c9895-f526-5c23-835d-e9aa002cfebe send: 147B guuid=941e50e5-1900-0000-83ef-ad8ad60c0000 pid=3286->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 27968af5-13a1-5973-b93f-29606a011029 116.7.18.27:23 guuid=941e50e5-1900-0000-83ef-ad8ad60c0000 pid=3286->27968af5-13a1-5973-b93f-29606a011029 send: 40B c06ea98f-6878-5108-962e-9f3ac61c4afb 178.175.46.74:23 guuid=941e50e5-1900-0000-83ef-ad8ad60c0000 pid=3286->c06ea98f-6878-5108-962e-9f3ac61c4afb con guuid=941e50e5-1900-0000-83ef-ad8ad60c0000 pid=3286|send-data send-data to 4097 IP addresses review logs to see them all guuid=941e50e5-1900-0000-83ef-ad8ad60c0000 pid=3286->guuid=941e50e5-1900-0000-83ef-ad8ad60c0000 pid=3286|send-data send guuid=abee59e5-1900-0000-83ef-ad8ad70c0000 pid=3287->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=abee59e5-1900-0000-83ef-ad8ad70c0000 pid=3287->27968af5-13a1-5973-b93f-29606a011029 send: 40B guuid=abee59e5-1900-0000-83ef-ad8ad70c0000 pid=3287|send-data send-data to 4097 IP addresses review logs to see them all guuid=abee59e5-1900-0000-83ef-ad8ad70c0000 pid=3287->guuid=abee59e5-1900-0000-83ef-ad8ad70c0000 pid=3287|send-data send guuid=5f8d65e5-1900-0000-83ef-ad8ad80c0000 pid=3288->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5f8d65e5-1900-0000-83ef-ad8ad80c0000 pid=3288|send-data send-data to 4097 IP addresses review logs to see them all guuid=5f8d65e5-1900-0000-83ef-ad8ad80c0000 pid=3288->guuid=5f8d65e5-1900-0000-83ef-ad8ad80c0000 pid=3288|send-data send guuid=23bc6de5-1900-0000-83ef-ad8ad90c0000 pid=3289->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=23bc6de5-1900-0000-83ef-ad8ad90c0000 pid=3289|send-data send-data to 4097 IP addresses review logs to see them all guuid=23bc6de5-1900-0000-83ef-ad8ad90c0000 pid=3289->guuid=23bc6de5-1900-0000-83ef-ad8ad90c0000 pid=3289|send-data send guuid=594b82e5-1900-0000-83ef-ad8ada0c0000 pid=3290->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 28814fd2-9c4c-591f-9088-5077eae68dcb 191.61.162.176:37215 guuid=594b82e5-1900-0000-83ef-ad8ada0c0000 pid=3290->28814fd2-9c4c-591f-9088-5077eae68dcb send: 40B b3a2a6d3-641f-5607-9864-035bbe36a67d 192.56.56.173:37215 guuid=594b82e5-1900-0000-83ef-ad8ada0c0000 pid=3290->b3a2a6d3-641f-5607-9864-035bbe36a67d send: 40B guuid=594b82e5-1900-0000-83ef-ad8ada0c0000 pid=3290|send-data send-data to 4097 IP addresses review logs to see them all guuid=594b82e5-1900-0000-83ef-ad8ada0c0000 pid=3290->guuid=594b82e5-1900-0000-83ef-ad8ada0c0000 pid=3290|send-data send guuid=da8a91e5-1900-0000-83ef-ad8adb0c0000 pid=3291->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=da8a91e5-1900-0000-83ef-ad8adb0c0000 pid=3291|send-data send-data to 4097 IP addresses review logs to see them all guuid=da8a91e5-1900-0000-83ef-ad8adb0c0000 pid=3291->guuid=da8a91e5-1900-0000-83ef-ad8adb0c0000 pid=3291|send-data send
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.MiraiB
Status:
Malicious
First seen:
2026-01-19 18:39:00 UTC
File Type:
Text (Shell)
AV detection:
13 of 36 (36.11%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e524cac93a03d73520cd259dd0f4e66a6af7eb47dffcf98628d389f0507adbbd

(this sample)

  
Delivery method
Distributed via web download

Comments