MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea72298805d9968c8883702c0182e2788d9ee3e0d9e401b95e3ff998b09e11f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ea72298805d9968c8883702c0182e2788d9ee3e0d9e401b95e3ff998b09e11f1
SHA3-384 hash: 01161177f3395ca758f7c2580ee84f792b8c8e345f8c26d3921527d530642812abf7d8e6334eeb6eeb2dbb83475bba33
SHA1 hash: 01e9549c2bb5bdf47b0e42b8bf8712a943422710
MD5 hash: 92fa949579e5a1407ddd8a4afb1c6881
humanhash: zulu-foxtrot-muppet-solar
File name:c.sh
Download: download sample
Signature Mirai
File size:1'086 bytes
First seen:2025-11-26 19:13:36 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:3J3Wbdi976NI7rSKKWAaJVl7udlnylAtxuIUqyxo5:689nuMlqnnyu5
TLSH T18711E2DC29A292DB1A899E28F066841C60C0D1C423E92D17F7BFB939DFD4210761737B
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://144.31.117.111/armn/an/aelf ua-wget
http://144.31.117.111/arm5n/an/aelf ua-wget
http://144.31.117.111/arm6n/an/aelf ua-wget
http://144.31.117.111/arm7n/an/aelf ua-wget
http://144.31.117.111/m68kn/an/aelf ua-wget
http://144.31.117.111/mipsn/an/aelf ua-wget
http://144.31.117.111/mipseln/an/aelf ua-wget
http://144.31.117.111/ppcn/an/aelf ua-wget
http://144.31.117.111/ppc440n/an/aelf ua-wget
http://144.31.117.111/sh4n/an/aelf ua-wget
http://144.31.117.111/x86n/an/aelf ua-wget
http://144.31.117.111/i486n/an/aelf ua-wget
http://144.31.117.111/i686n/an/aelf ua-wget
http://144.31.117.111/x86_64n/an/aelf ua-wget
http://144.31.117.111/spcn/an/aelf ua-wget
http://144.31.117.111/arcn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=198d73fa-1600-0000-cfcd-31ca560c0000 pid=3158 /usr/bin/sudo guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164 /tmp/sample.bin guuid=198d73fa-1600-0000-cfcd-31ca560c0000 pid=3158->guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164 execve guuid=e5ac94fc-1600-0000-cfcd-31ca5d0c0000 pid=3165 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=e5ac94fc-1600-0000-cfcd-31ca5d0c0000 pid=3165 execve guuid=849ccb05-1700-0000-cfcd-31ca5e0c0000 pid=3166 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=849ccb05-1700-0000-cfcd-31ca5e0c0000 pid=3166 execve guuid=ae7db006-1700-0000-cfcd-31ca5f0c0000 pid=3167 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=ae7db006-1700-0000-cfcd-31ca5f0c0000 pid=3167 clone guuid=867dc306-1700-0000-cfcd-31ca600c0000 pid=3168 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=867dc306-1700-0000-cfcd-31ca600c0000 pid=3168 execve guuid=6dca200c-1700-0000-cfcd-31ca610c0000 pid=3169 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=6dca200c-1700-0000-cfcd-31ca610c0000 pid=3169 execve guuid=4ad7bf0c-1700-0000-cfcd-31ca620c0000 pid=3170 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=4ad7bf0c-1700-0000-cfcd-31ca620c0000 pid=3170 clone guuid=6fb1fe0c-1700-0000-cfcd-31ca640c0000 pid=3172 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=6fb1fe0c-1700-0000-cfcd-31ca640c0000 pid=3172 execve guuid=770f7c14-1700-0000-cfcd-31ca720c0000 pid=3186 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=770f7c14-1700-0000-cfcd-31ca720c0000 pid=3186 execve guuid=b5111115-1700-0000-cfcd-31ca750c0000 pid=3189 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=b5111115-1700-0000-cfcd-31ca750c0000 pid=3189 clone guuid=fc3d2f15-1700-0000-cfcd-31ca760c0000 pid=3190 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=fc3d2f15-1700-0000-cfcd-31ca760c0000 pid=3190 execve guuid=484ac219-1700-0000-cfcd-31ca810c0000 pid=3201 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=484ac219-1700-0000-cfcd-31ca810c0000 pid=3201 execve guuid=6bf6311a-1700-0000-cfcd-31ca820c0000 pid=3202 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=6bf6311a-1700-0000-cfcd-31ca820c0000 pid=3202 clone guuid=d010541a-1700-0000-cfcd-31ca830c0000 pid=3203 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=d010541a-1700-0000-cfcd-31ca830c0000 pid=3203 execve guuid=85705e1e-1700-0000-cfcd-31ca8e0c0000 pid=3214 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=85705e1e-1700-0000-cfcd-31ca8e0c0000 pid=3214 execve guuid=d67ad01e-1700-0000-cfcd-31ca8f0c0000 pid=3215 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=d67ad01e-1700-0000-cfcd-31ca8f0c0000 pid=3215 clone guuid=44a5f11e-1700-0000-cfcd-31ca900c0000 pid=3216 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=44a5f11e-1700-0000-cfcd-31ca900c0000 pid=3216 execve guuid=eadf7223-1700-0000-cfcd-31ca920c0000 pid=3218 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=eadf7223-1700-0000-cfcd-31ca920c0000 pid=3218 execve guuid=8b0fda23-1700-0000-cfcd-31ca930c0000 pid=3219 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=8b0fda23-1700-0000-cfcd-31ca930c0000 pid=3219 clone guuid=b6d9e823-1700-0000-cfcd-31ca940c0000 pid=3220 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=b6d9e823-1700-0000-cfcd-31ca940c0000 pid=3220 execve guuid=1b387b28-1700-0000-cfcd-31ca9d0c0000 pid=3229 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=1b387b28-1700-0000-cfcd-31ca9d0c0000 pid=3229 execve guuid=be37cf28-1700-0000-cfcd-31ca9e0c0000 pid=3230 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=be37cf28-1700-0000-cfcd-31ca9e0c0000 pid=3230 clone guuid=077be528-1700-0000-cfcd-31ca9f0c0000 pid=3231 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=077be528-1700-0000-cfcd-31ca9f0c0000 pid=3231 execve guuid=26e0882c-1700-0000-cfcd-31caa80c0000 pid=3240 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=26e0882c-1700-0000-cfcd-31caa80c0000 pid=3240 execve guuid=ac8bf92c-1700-0000-cfcd-31caaa0c0000 pid=3242 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=ac8bf92c-1700-0000-cfcd-31caaa0c0000 pid=3242 clone guuid=e1b0192d-1700-0000-cfcd-31caab0c0000 pid=3243 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=e1b0192d-1700-0000-cfcd-31caab0c0000 pid=3243 execve guuid=e7a7ee2f-1700-0000-cfcd-31cab40c0000 pid=3252 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=e7a7ee2f-1700-0000-cfcd-31cab40c0000 pid=3252 execve guuid=c5302430-1700-0000-cfcd-31cab60c0000 pid=3254 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=c5302430-1700-0000-cfcd-31cab60c0000 pid=3254 clone guuid=0b733430-1700-0000-cfcd-31cab70c0000 pid=3255 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=0b733430-1700-0000-cfcd-31cab70c0000 pid=3255 execve guuid=6eee2933-1700-0000-cfcd-31cac10c0000 pid=3265 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=6eee2933-1700-0000-cfcd-31cac10c0000 pid=3265 execve guuid=d1796033-1700-0000-cfcd-31cac20c0000 pid=3266 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=d1796033-1700-0000-cfcd-31cac20c0000 pid=3266 clone guuid=c45a6a33-1700-0000-cfcd-31cac30c0000 pid=3267 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=c45a6a33-1700-0000-cfcd-31cac30c0000 pid=3267 execve guuid=9e1f5f36-1700-0000-cfcd-31cacd0c0000 pid=3277 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=9e1f5f36-1700-0000-cfcd-31cacd0c0000 pid=3277 execve guuid=88199436-1700-0000-cfcd-31cacf0c0000 pid=3279 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=88199436-1700-0000-cfcd-31cacf0c0000 pid=3279 clone guuid=7a1fa136-1700-0000-cfcd-31cad00c0000 pid=3280 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=7a1fa136-1700-0000-cfcd-31cad00c0000 pid=3280 execve guuid=8ce30b39-1700-0000-cfcd-31cad90c0000 pid=3289 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=8ce30b39-1700-0000-cfcd-31cad90c0000 pid=3289 execve guuid=c5684639-1700-0000-cfcd-31cadb0c0000 pid=3291 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=c5684639-1700-0000-cfcd-31cadb0c0000 pid=3291 clone guuid=a2184f39-1700-0000-cfcd-31cadc0c0000 pid=3292 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=a2184f39-1700-0000-cfcd-31cadc0c0000 pid=3292 execve guuid=43719f3b-1700-0000-cfcd-31cae50c0000 pid=3301 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=43719f3b-1700-0000-cfcd-31cae50c0000 pid=3301 execve guuid=7003d33b-1700-0000-cfcd-31cae70c0000 pid=3303 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=7003d33b-1700-0000-cfcd-31cae70c0000 pid=3303 clone guuid=9789dd3b-1700-0000-cfcd-31cae80c0000 pid=3304 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=9789dd3b-1700-0000-cfcd-31cae80c0000 pid=3304 execve guuid=cdfc183f-1700-0000-cfcd-31caf40c0000 pid=3316 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=cdfc183f-1700-0000-cfcd-31caf40c0000 pid=3316 execve guuid=662e5b3f-1700-0000-cfcd-31caf60c0000 pid=3318 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=662e5b3f-1700-0000-cfcd-31caf60c0000 pid=3318 clone guuid=ff6d6d3f-1700-0000-cfcd-31caf70c0000 pid=3319 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=ff6d6d3f-1700-0000-cfcd-31caf70c0000 pid=3319 execve guuid=d0183743-1700-0000-cfcd-31ca030d0000 pid=3331 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=d0183743-1700-0000-cfcd-31ca030d0000 pid=3331 execve guuid=bc529a43-1700-0000-cfcd-31ca050d0000 pid=3333 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=bc529a43-1700-0000-cfcd-31ca050d0000 pid=3333 clone guuid=f9caa443-1700-0000-cfcd-31ca060d0000 pid=3334 /usr/bin/curl net send-data guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=f9caa443-1700-0000-cfcd-31ca060d0000 pid=3334 execve guuid=80b65746-1700-0000-cfcd-31ca0e0d0000 pid=3342 /usr/bin/chmod guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=80b65746-1700-0000-cfcd-31ca0e0d0000 pid=3342 execve guuid=fed99546-1700-0000-cfcd-31ca100d0000 pid=3344 /usr/bin/dash guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=fed99546-1700-0000-cfcd-31ca100d0000 pid=3344 clone guuid=f0a7b446-1700-0000-cfcd-31ca120d0000 pid=3346 /usr/bin/rm delete-file guuid=213848fc-1600-0000-cfcd-31ca5c0c0000 pid=3164->guuid=f0a7b446-1700-0000-cfcd-31ca120d0000 pid=3346 execve 4d829267-f886-5b05-996f-1dc1bb3b285e 144.31.117.111:80 guuid=e5ac94fc-1600-0000-cfcd-31ca5d0c0000 pid=3165->4d829267-f886-5b05-996f-1dc1bb3b285e send: 81B guuid=867dc306-1700-0000-cfcd-31ca600c0000 pid=3168->4d829267-f886-5b05-996f-1dc1bb3b285e send: 82B guuid=6fb1fe0c-1700-0000-cfcd-31ca640c0000 pid=3172->4d829267-f886-5b05-996f-1dc1bb3b285e send: 82B guuid=fc3d2f15-1700-0000-cfcd-31ca760c0000 pid=3190->4d829267-f886-5b05-996f-1dc1bb3b285e send: 82B guuid=d010541a-1700-0000-cfcd-31ca830c0000 pid=3203->4d829267-f886-5b05-996f-1dc1bb3b285e send: 82B guuid=44a5f11e-1700-0000-cfcd-31ca900c0000 pid=3216->4d829267-f886-5b05-996f-1dc1bb3b285e send: 82B guuid=b6d9e823-1700-0000-cfcd-31ca940c0000 pid=3220->4d829267-f886-5b05-996f-1dc1bb3b285e send: 84B guuid=077be528-1700-0000-cfcd-31ca9f0c0000 pid=3231->4d829267-f886-5b05-996f-1dc1bb3b285e send: 81B guuid=e1b0192d-1700-0000-cfcd-31caab0c0000 pid=3243->4d829267-f886-5b05-996f-1dc1bb3b285e send: 84B guuid=0b733430-1700-0000-cfcd-31cab70c0000 pid=3255->4d829267-f886-5b05-996f-1dc1bb3b285e send: 81B guuid=c45a6a33-1700-0000-cfcd-31cac30c0000 pid=3267->4d829267-f886-5b05-996f-1dc1bb3b285e send: 81B guuid=7a1fa136-1700-0000-cfcd-31cad00c0000 pid=3280->4d829267-f886-5b05-996f-1dc1bb3b285e send: 82B guuid=a2184f39-1700-0000-cfcd-31cadc0c0000 pid=3292->4d829267-f886-5b05-996f-1dc1bb3b285e send: 82B guuid=9789dd3b-1700-0000-cfcd-31cae80c0000 pid=3304->4d829267-f886-5b05-996f-1dc1bb3b285e send: 84B guuid=ff6d6d3f-1700-0000-cfcd-31caf70c0000 pid=3319->4d829267-f886-5b05-996f-1dc1bb3b285e send: 81B guuid=f9caa443-1700-0000-cfcd-31ca060d0000 pid=3334->4d829267-f886-5b05-996f-1dc1bb3b285e send: 81B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-11-26 19:14:13 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ea72298805d9968c8883702c0182e2788d9ee3e0d9e401b95e3ff998b09e11f1

(this sample)

  
Delivery method
Distributed via web download

Comments