MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f39a63a0b0ac1991e58d9c77a0f01bcd531762120db7f79f804ee61733edc54a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f39a63a0b0ac1991e58d9c77a0f01bcd531762120db7f79f804ee61733edc54a
SHA3-384 hash: fba1635f68f6bb52715ed638c4bcc93b3f79ec097c8d05e5e99bbb81367a51c113243b66aabf1ecfb95c34556b530c92
SHA1 hash: d198fa9cc9fadb5a77a307332bc241ea8c309c5c
MD5 hash: 68718ed0d4b7e68279de80513b081797
humanhash: emma-angel-undress-jupiter
File name:w.sh
Download: download sample
Signature Mirai
File size:1'248 bytes
First seen:2025-07-18 10:16:11 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:KYC3WqYBIpqYuNNIUuiu7qYn4K6jqwmr6qEjG7qPNmB7qDq1lqS6eqbgqyV2fHA:KoqzqJ2H7qf9qwmr6qEjG7qPNmB7qDqn
TLSH T176214CCA0F6381430C3C8F25E49B47581F898EE374E46E9AA2CC5CF76189B197031E2B
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://161.97.77.188/HBTs/top1miku.armn/an/aua-wget
http://161.97.77.188/HBTs/top1miku.arm5n/an/aua-wget
http://161.97.77.188/HBTs/top1miku.arm6n/an/aua-wget
http://161.97.77.188/HBTs/top1miku.arm7n/an/aua-wget
http://161.97.77.188/HBTs/top1miku.m68kaf5ef5773b4f244557be125fa269d59bfa897f6ad5ddbbd600a224a7fe38fdb8 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.mips6dba5a43486ad2c883f236754e25806a860f5063fcf73e225f4f86c1c1741ead Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.mpsln/an/aua-wget
http://161.97.77.188/HBTs/top1miku.ppcn/an/aua-wget
http://161.97.77.188/HBTs/top1miku.sh4200f50c4e8e10d7cd12823b2ff9dcc4fd4643094ee0cb1bbd321a636af1acdc4 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.spcn/an/aua-wget
http://161.97.77.188/HBTs/top1miku.x8664aa14e4bba9920161c083819452da01e173458619866025b454e29117f427c3 Miraielf mirai opendir ua-wget x86
http://161.97.77.188/HBTs/top1miku.x86_645c03e74290ffbc6332f3d357d54853000ea53f19ee0fa3fb36d466989c48826f Miraielf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=79a20e4a-1a00-0000-f7df-aaf39e090000 pid=2462 /usr/bin/sudo guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468 /tmp/sample.bin guuid=79a20e4a-1a00-0000-f7df-aaf39e090000 pid=2462->guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468 execve guuid=8656eb4b-1a00-0000-f7df-aaf3a6090000 pid=2470 /usr/bin/busybox net send-data guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=8656eb4b-1a00-0000-f7df-aaf3a6090000 pid=2470 execve guuid=ad31064f-1a00-0000-f7df-aaf3b0090000 pid=2480 /usr/bin/chmod guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=ad31064f-1a00-0000-f7df-aaf3b0090000 pid=2480 execve guuid=b2d5464f-1a00-0000-f7df-aaf3b1090000 pid=2481 /usr/bin/dash guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=b2d5464f-1a00-0000-f7df-aaf3b1090000 pid=2481 clone guuid=c0144e4f-1a00-0000-f7df-aaf3b2090000 pid=2482 /usr/bin/busybox net send-data guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=c0144e4f-1a00-0000-f7df-aaf3b2090000 pid=2482 execve guuid=79d65252-1a00-0000-f7df-aaf3b9090000 pid=2489 /usr/bin/chmod guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=79d65252-1a00-0000-f7df-aaf3b9090000 pid=2489 execve guuid=6251cf52-1a00-0000-f7df-aaf3bb090000 pid=2491 /usr/bin/dash guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=6251cf52-1a00-0000-f7df-aaf3bb090000 pid=2491 clone guuid=8ea9d552-1a00-0000-f7df-aaf3bc090000 pid=2492 /usr/bin/busybox net send-data guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=8ea9d552-1a00-0000-f7df-aaf3bc090000 pid=2492 execve guuid=e9f72f54-1a00-0000-f7df-aaf3c1090000 pid=2497 /usr/bin/chmod guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=e9f72f54-1a00-0000-f7df-aaf3c1090000 pid=2497 execve guuid=d4429654-1a00-0000-f7df-aaf3c3090000 pid=2499 /usr/bin/dash guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=d4429654-1a00-0000-f7df-aaf3c3090000 pid=2499 clone guuid=8ccba554-1a00-0000-f7df-aaf3c4090000 pid=2500 /usr/bin/busybox net send-data guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=8ccba554-1a00-0000-f7df-aaf3c4090000 pid=2500 execve guuid=971fea55-1a00-0000-f7df-aaf3c8090000 pid=2504 /usr/bin/chmod guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=971fea55-1a00-0000-f7df-aaf3c8090000 pid=2504 execve guuid=cab42356-1a00-0000-f7df-aaf3c9090000 pid=2505 /usr/bin/dash guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=cab42356-1a00-0000-f7df-aaf3c9090000 pid=2505 clone guuid=be843056-1a00-0000-f7df-aaf3ca090000 pid=2506 /usr/bin/busybox net send-data write-file guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=be843056-1a00-0000-f7df-aaf3ca090000 pid=2506 execve guuid=384fc558-1a00-0000-f7df-aaf3cf090000 pid=2511 /usr/bin/chmod guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=384fc558-1a00-0000-f7df-aaf3cf090000 pid=2511 execve guuid=5622f858-1a00-0000-f7df-aaf3d1090000 pid=2513 /usr/bin/dash guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=5622f858-1a00-0000-f7df-aaf3d1090000 pid=2513 clone guuid=4653da5a-1a00-0000-f7df-aaf3d6090000 pid=2518 /usr/bin/busybox net send-data write-file guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=4653da5a-1a00-0000-f7df-aaf3d6090000 pid=2518 execve guuid=90a35962-1a00-0000-f7df-aaf3ea090000 pid=2538 /usr/bin/chmod guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=90a35962-1a00-0000-f7df-aaf3ea090000 pid=2538 execve guuid=899f9662-1a00-0000-f7df-aaf3ec090000 pid=2540 /usr/bin/dash guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=899f9662-1a00-0000-f7df-aaf3ec090000 pid=2540 clone guuid=42aa6f64-1a00-0000-f7df-aaf3f2090000 pid=2546 /usr/bin/busybox net send-data guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=42aa6f64-1a00-0000-f7df-aaf3f2090000 pid=2546 execve guuid=0bc39c65-1a00-0000-f7df-aaf3f4090000 pid=2548 /usr/bin/chmod guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=0bc39c65-1a00-0000-f7df-aaf3f4090000 pid=2548 execve guuid=e373ec65-1a00-0000-f7df-aaf3f5090000 pid=2549 /usr/bin/dash guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=e373ec65-1a00-0000-f7df-aaf3f5090000 pid=2549 clone guuid=1e15f965-1a00-0000-f7df-aaf3f6090000 pid=2550 /usr/bin/busybox net send-data guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=1e15f965-1a00-0000-f7df-aaf3f6090000 pid=2550 execve guuid=54245a67-1a00-0000-f7df-aaf3f7090000 pid=2551 /usr/bin/chmod guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=54245a67-1a00-0000-f7df-aaf3f7090000 pid=2551 execve guuid=853ab167-1a00-0000-f7df-aaf3f9090000 pid=2553 /usr/bin/dash guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=853ab167-1a00-0000-f7df-aaf3f9090000 pid=2553 clone guuid=bb2fbe67-1a00-0000-f7df-aaf3fa090000 pid=2554 /usr/bin/busybox net send-data write-file guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=bb2fbe67-1a00-0000-f7df-aaf3fa090000 pid=2554 execve guuid=95d75b6a-1a00-0000-f7df-aaf3010a0000 pid=2561 /usr/bin/chmod guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=95d75b6a-1a00-0000-f7df-aaf3010a0000 pid=2561 execve guuid=6e4ca36a-1a00-0000-f7df-aaf3030a0000 pid=2563 /usr/bin/dash guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=6e4ca36a-1a00-0000-f7df-aaf3030a0000 pid=2563 clone guuid=2757446b-1a00-0000-f7df-aaf3060a0000 pid=2566 /usr/bin/busybox net send-data guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=2757446b-1a00-0000-f7df-aaf3060a0000 pid=2566 execve guuid=45be9c6c-1a00-0000-f7df-aaf3090a0000 pid=2569 /usr/bin/chmod guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=45be9c6c-1a00-0000-f7df-aaf3090a0000 pid=2569 execve guuid=7440ea6c-1a00-0000-f7df-aaf30a0a0000 pid=2570 /usr/bin/dash guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=7440ea6c-1a00-0000-f7df-aaf30a0a0000 pid=2570 clone guuid=1a1bf76c-1a00-0000-f7df-aaf30b0a0000 pid=2571 /usr/bin/busybox net send-data write-file guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=1a1bf76c-1a00-0000-f7df-aaf30b0a0000 pid=2571 execve guuid=0bf1a773-1a00-0000-f7df-aaf31d0a0000 pid=2589 /usr/bin/chmod guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=0bf1a773-1a00-0000-f7df-aaf31d0a0000 pid=2589 execve guuid=6320df73-1a00-0000-f7df-aaf31e0a0000 pid=2590 /home/sandbox/top1miku.x86 net guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=6320df73-1a00-0000-f7df-aaf31e0a0000 pid=2590 execve guuid=8e193c74-1a00-0000-f7df-aaf3220a0000 pid=2594 /usr/bin/busybox net send-data write-file guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=8e193c74-1a00-0000-f7df-aaf3220a0000 pid=2594 execve guuid=e865057c-1a00-0000-f7df-aaf33a0a0000 pid=2618 /usr/bin/chmod guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=e865057c-1a00-0000-f7df-aaf33a0a0000 pid=2618 execve guuid=d6275a7c-1a00-0000-f7df-aaf33b0a0000 pid=2619 /home/sandbox/top1miku.x86_64 net guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=d6275a7c-1a00-0000-f7df-aaf33b0a0000 pid=2619 execve guuid=81bf727c-1a00-0000-f7df-aaf33e0a0000 pid=2622 /usr/bin/rm guuid=3cb9b24b-1a00-0000-f7df-aaf3a4090000 pid=2468->guuid=81bf727c-1a00-0000-f7df-aaf33e0a0000 pid=2622 execve 7a155949-225c-5534-9d46-ce85bc851092 161.97.77.188:80 guuid=8656eb4b-1a00-0000-f7df-aaf3a6090000 pid=2470->7a155949-225c-5534-9d46-ce85bc851092 send: 93B guuid=c0144e4f-1a00-0000-f7df-aaf3b2090000 pid=2482->7a155949-225c-5534-9d46-ce85bc851092 send: 94B guuid=8ea9d552-1a00-0000-f7df-aaf3bc090000 pid=2492->7a155949-225c-5534-9d46-ce85bc851092 send: 94B guuid=8ccba554-1a00-0000-f7df-aaf3c4090000 pid=2500->7a155949-225c-5534-9d46-ce85bc851092 send: 94B guuid=be843056-1a00-0000-f7df-aaf3ca090000 pid=2506->7a155949-225c-5534-9d46-ce85bc851092 send: 94B guuid=4653da5a-1a00-0000-f7df-aaf3d6090000 pid=2518->7a155949-225c-5534-9d46-ce85bc851092 send: 94B guuid=42aa6f64-1a00-0000-f7df-aaf3f2090000 pid=2546->7a155949-225c-5534-9d46-ce85bc851092 send: 94B guuid=1e15f965-1a00-0000-f7df-aaf3f6090000 pid=2550->7a155949-225c-5534-9d46-ce85bc851092 send: 93B guuid=bb2fbe67-1a00-0000-f7df-aaf3fa090000 pid=2554->7a155949-225c-5534-9d46-ce85bc851092 send: 93B guuid=2757446b-1a00-0000-f7df-aaf3060a0000 pid=2566->7a155949-225c-5534-9d46-ce85bc851092 send: 93B guuid=1a1bf76c-1a00-0000-f7df-aaf30b0a0000 pid=2571->7a155949-225c-5534-9d46-ce85bc851092 send: 93B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=6320df73-1a00-0000-f7df-aaf31e0a0000 pid=2590->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7a472574-1a00-0000-f7df-aaf3200a0000 pid=2592 /home/sandbox/top1miku.x86 guuid=6320df73-1a00-0000-f7df-aaf31e0a0000 pid=2590->guuid=7a472574-1a00-0000-f7df-aaf3200a0000 pid=2592 clone guuid=47553d74-1a00-0000-f7df-aaf3230a0000 pid=2595 /home/sandbox/top1miku.x86 write-config zombie guuid=7a472574-1a00-0000-f7df-aaf3200a0000 pid=2592->guuid=47553d74-1a00-0000-f7df-aaf3230a0000 pid=2595 clone guuid=8e193c74-1a00-0000-f7df-aaf3220a0000 pid=2594->7a155949-225c-5534-9d46-ce85bc851092 send: 96B guuid=e43f0a79-1a00-0000-f7df-aaf3310a0000 pid=2609 /usr/bin/dash guuid=47553d74-1a00-0000-f7df-aaf3230a0000 pid=2595->guuid=e43f0a79-1a00-0000-f7df-aaf3310a0000 pid=2609 execve guuid=2378a67c-1a00-0000-f7df-aaf3400a0000 pid=2624 /home/sandbox/top1miku.x86 zombie guuid=47553d74-1a00-0000-f7df-aaf3230a0000 pid=2595->guuid=2378a67c-1a00-0000-f7df-aaf3400a0000 pid=2624 clone guuid=a2ba3f79-1a00-0000-f7df-aaf3320a0000 pid=2610 /usr/bin/cp guuid=e43f0a79-1a00-0000-f7df-aaf3310a0000 pid=2609->guuid=a2ba3f79-1a00-0000-f7df-aaf3320a0000 pid=2610 execve guuid=d6275a7c-1a00-0000-f7df-aaf33b0a0000 pid=2619->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0bc9697c-1a00-0000-f7df-aaf33c0a0000 pid=2620 /home/sandbox/top1miku.x86_64 zombie guuid=d6275a7c-1a00-0000-f7df-aaf33b0a0000 pid=2619->guuid=0bc9697c-1a00-0000-f7df-aaf33c0a0000 pid=2620 clone guuid=b0f3727c-1a00-0000-f7df-aaf33f0a0000 pid=2623 /home/sandbox/top1miku.x86_64 write-config zombie guuid=0bc9697c-1a00-0000-f7df-aaf33c0a0000 pid=2620->guuid=b0f3727c-1a00-0000-f7df-aaf33f0a0000 pid=2623 clone guuid=7de9fc7d-1a00-0000-f7df-aaf3440a0000 pid=2628 /usr/bin/dash guuid=b0f3727c-1a00-0000-f7df-aaf33f0a0000 pid=2623->guuid=7de9fc7d-1a00-0000-f7df-aaf3440a0000 pid=2628 execve guuid=bc75897f-1a00-0000-f7df-aaf34a0a0000 pid=2634 /home/sandbox/top1miku.x86_64 delete-file dns net send-data zombie guuid=b0f3727c-1a00-0000-f7df-aaf33f0a0000 pid=2623->guuid=bc75897f-1a00-0000-f7df-aaf34a0a0000 pid=2634 clone guuid=03588c7e-1a00-0000-f7df-aaf3460a0000 pid=2630 /usr/bin/cp guuid=7de9fc7d-1a00-0000-f7df-aaf3440a0000 pid=2628->guuid=03588c7e-1a00-0000-f7df-aaf3460a0000 pid=2630 execve guuid=bc75897f-1a00-0000-f7df-aaf34a0a0000 pid=2634->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 4750B a1cb65f6-afd3-5a3a-9fa0-f13741392136 top1miku.duckdns.org:2004 guuid=bc75897f-1a00-0000-f7df-aaf34a0a0000 pid=2634->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 1625B
Verdict:
Malicious
Threat:
Document-HTML.Downloader.Heuristic
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-07-18 10:17:22 UTC
File Type:
Text (Shell)
AV detection:
15 of 37 (40.54%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f39a63a0b0ac1991e58d9c77a0f01bcd531762120db7f79f804ee61733edc54a

(this sample)

  
Delivery method
Distributed via web download

Comments