MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f5f7e99c2b01bada211a396efc4921ff6b23cd19fcb0be3ba5bdc137bfd48e9a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: f5f7e99c2b01bada211a396efc4921ff6b23cd19fcb0be3ba5bdc137bfd48e9a
SHA3-384 hash: 55ef61be9423470dd96f795384d8569f6d084cb92ac525014df6e0c00ba26226fe19fecca1d20d97ad718752b94e370f
SHA1 hash: 810c8e59452b2ce5ee022218ae82850e2b22a8e2
MD5 hash: e69b37fab18b363907affbf55b65db63
humanhash: eleven-april-golf-monkey
File name:wget1.sh
Download: download sample
Signature Mirai
File size:1'139 bytes
First seen:2025-07-04 04:30:35 UTC
Last seen:2025-07-04 07:04:09 UTC
File type: sh
MIME type:text/plain
ssdeep 24:ACqUGFUKmUSNI70UqKjUS+USU03U4tmUVU4yU4kvioSUzAozUI5ogUIDoVU6KgG+:AjdHwd7HRjGV
TLSH T13221FBAD21301EB68914DD47F83343E8702EE5CDE6708F5639CF58B98C976807D50B4A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.208.158.140/arm8271f1f986b352fff15ea4a77cc5fec53c1d9dcca742d4a9c9d2ab6891eab18a Miraielf gafgyt mirai ua-wget
http://185.208.158.140/arm5575ef1a01819dd1f1c2c0fb09b0001725599230fc4ce03d197b52751ff85a341 Miraielf mirai ua-wget
http://185.208.158.140/arm66402c8ac9e7bcc47f493ed249ef2b5a0e1b0b317e0dbd8012b61d3507c67fd0e Miraielf mirai ua-wget
http://185.208.158.140/arm737d405a2afcd051f24faa7d536ac292e28148575a2ee02766b92046f413a3c57 Miraielf mirai ua-wget
http://185.208.158.140/mips7b02048872ec82be36a7a9c28d8479a1c884a2df339416c822554211e6d5b05e Miraielf gafgyt mirai ua-wget
http://185.208.158.140/mipself0c4dc9e697cc34437766c67140cc210be04bd62997bf2ace3c389e3d9e32ff7 Miraielf mirai ua-wget
http://185.208.158.140/powerpccefd6e28cd1c138a151a1721dbbe1a53b410424b259179faa792fcc8063952ba Miraielf mirai ua-wget
http://185.208.158.140/sh4dfc72b2b40890a9747c242f69db7c4941794bf89c5ff0ef75dab6e1338c6cd6f Miraielf mirai ua-wget
http://185.208.158.140/sparc36eb14fd17bd36eb37ce29bdffe3109b88ffef2387f94647593d267b3214b134 Miraielf mirai ua-wget
http://185.208.158.140/x86_641d9f46542a855257b2a801c72449db0482435d1bb05cffccc0ad56a82e4631e6 Miraielf mirai ua-wget
http://185.208.158.140/x86_327cc20c4f63b03aa33b99d2ad360b8b4697616676e3df8e6be4a8f49eb425e345 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
20
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=67c58386-1900-0000-f9f7-6b20c4080000 pid=2244 /usr/bin/sudo guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248 /tmp/sample.bin guuid=67c58386-1900-0000-f9f7-6b20c4080000 pid=2244->guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248 execve guuid=dd5b9388-1900-0000-f9f7-6b20c9080000 pid=2249 /usr/bin/rm guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=dd5b9388-1900-0000-f9f7-6b20c9080000 pid=2249 execve guuid=0a83f288-1900-0000-f9f7-6b20cb080000 pid=2251 /usr/bin/rm guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=0a83f288-1900-0000-f9f7-6b20cb080000 pid=2251 execve guuid=741b4689-1900-0000-f9f7-6b20cd080000 pid=2253 /usr/bin/wget net send-data write-file guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=741b4689-1900-0000-f9f7-6b20cd080000 pid=2253 execve guuid=af101393-1900-0000-f9f7-6b20dc080000 pid=2268 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=af101393-1900-0000-f9f7-6b20dc080000 pid=2268 execve guuid=fa1f5293-1900-0000-f9f7-6b20de080000 pid=2270 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=fa1f5293-1900-0000-f9f7-6b20de080000 pid=2270 clone guuid=dbc15b95-1900-0000-f9f7-6b20e4080000 pid=2276 /usr/bin/wget net send-data write-file guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=dbc15b95-1900-0000-f9f7-6b20e4080000 pid=2276 execve guuid=f919649c-1900-0000-f9f7-6b20f5080000 pid=2293 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=f919649c-1900-0000-f9f7-6b20f5080000 pid=2293 execve guuid=667da49c-1900-0000-f9f7-6b20f7080000 pid=2295 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=667da49c-1900-0000-f9f7-6b20f7080000 pid=2295 clone guuid=ccd0189d-1900-0000-f9f7-6b20fb080000 pid=2299 /usr/bin/wget net send-data guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=ccd0189d-1900-0000-f9f7-6b20fb080000 pid=2299 execve guuid=13cdcda0-1900-0000-f9f7-6b2000090000 pid=2304 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=13cdcda0-1900-0000-f9f7-6b2000090000 pid=2304 execve guuid=e1a524a1-1900-0000-f9f7-6b2001090000 pid=2305 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=e1a524a1-1900-0000-f9f7-6b2001090000 pid=2305 clone guuid=718733a1-1900-0000-f9f7-6b2002090000 pid=2306 /usr/bin/wget net send-data write-file guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=718733a1-1900-0000-f9f7-6b2002090000 pid=2306 execve guuid=4ecf0aa8-1900-0000-f9f7-6b2012090000 pid=2322 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=4ecf0aa8-1900-0000-f9f7-6b2012090000 pid=2322 execve guuid=d91050a8-1900-0000-f9f7-6b2014090000 pid=2324 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=d91050a8-1900-0000-f9f7-6b2014090000 pid=2324 clone guuid=0863daa8-1900-0000-f9f7-6b2018090000 pid=2328 /usr/bin/wget net send-data write-file guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=0863daa8-1900-0000-f9f7-6b2018090000 pid=2328 execve guuid=b510f6af-1900-0000-f9f7-6b2026090000 pid=2342 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=b510f6af-1900-0000-f9f7-6b2026090000 pid=2342 execve guuid=8a6262b0-1900-0000-f9f7-6b2028090000 pid=2344 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=8a6262b0-1900-0000-f9f7-6b2028090000 pid=2344 clone guuid=111b40b1-1900-0000-f9f7-6b202a090000 pid=2346 /usr/bin/wget net send-data write-file guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=111b40b1-1900-0000-f9f7-6b202a090000 pid=2346 execve guuid=ebe03fb8-1900-0000-f9f7-6b203a090000 pid=2362 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=ebe03fb8-1900-0000-f9f7-6b203a090000 pid=2362 execve guuid=aa0d88b8-1900-0000-f9f7-6b203c090000 pid=2364 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=aa0d88b8-1900-0000-f9f7-6b203c090000 pid=2364 clone guuid=3ede82ba-1900-0000-f9f7-6b2041090000 pid=2369 /usr/bin/wget net send-data write-file guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=3ede82ba-1900-0000-f9f7-6b2041090000 pid=2369 execve guuid=e4b474c1-1900-0000-f9f7-6b2053090000 pid=2387 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=e4b474c1-1900-0000-f9f7-6b2053090000 pid=2387 execve guuid=e5faa7c1-1900-0000-f9f7-6b2055090000 pid=2389 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=e5faa7c1-1900-0000-f9f7-6b2055090000 pid=2389 clone guuid=2f2321c2-1900-0000-f9f7-6b2058090000 pid=2392 /usr/bin/wget net send-data write-file guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=2f2321c2-1900-0000-f9f7-6b2058090000 pid=2392 execve guuid=2431c8c8-1900-0000-f9f7-6b2065090000 pid=2405 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=2431c8c8-1900-0000-f9f7-6b2065090000 pid=2405 execve guuid=5f8312c9-1900-0000-f9f7-6b2066090000 pid=2406 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=5f8312c9-1900-0000-f9f7-6b2066090000 pid=2406 clone guuid=fe4f9dc9-1900-0000-f9f7-6b2068090000 pid=2408 /usr/bin/wget net send-data write-file guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=fe4f9dc9-1900-0000-f9f7-6b2068090000 pid=2408 execve guuid=6e352ed0-1900-0000-f9f7-6b2075090000 pid=2421 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=6e352ed0-1900-0000-f9f7-6b2075090000 pid=2421 execve guuid=2eb16cd0-1900-0000-f9f7-6b2077090000 pid=2423 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=2eb16cd0-1900-0000-f9f7-6b2077090000 pid=2423 clone guuid=1c1d3bd1-1900-0000-f9f7-6b207b090000 pid=2427 /usr/bin/wget net send-data write-file guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=1c1d3bd1-1900-0000-f9f7-6b207b090000 pid=2427 execve guuid=5af1dad7-1900-0000-f9f7-6b2083090000 pid=2435 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=5af1dad7-1900-0000-f9f7-6b2083090000 pid=2435 execve guuid=27451dd8-1900-0000-f9f7-6b2084090000 pid=2436 /home/sandbox/x86_64 net guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=27451dd8-1900-0000-f9f7-6b2084090000 pid=2436 execve guuid=c33651d8-1900-0000-f9f7-6b2088090000 pid=2440 /usr/bin/wget net send-data write-file guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=c33651d8-1900-0000-f9f7-6b2088090000 pid=2440 execve guuid=d8b039e7-1900-0000-f9f7-6b2098090000 pid=2456 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=d8b039e7-1900-0000-f9f7-6b2098090000 pid=2456 execve guuid=a0fe7ee7-1900-0000-f9f7-6b209a090000 pid=2458 /home/sandbox/x86_32 net guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=a0fe7ee7-1900-0000-f9f7-6b209a090000 pid=2458 execve guuid=15df111d-1b00-0000-f9f7-6b20440c0000 pid=3140 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=15df111d-1b00-0000-f9f7-6b20440c0000 pid=3140 execve guuid=f3374b1d-1b00-0000-f9f7-6b20490c0000 pid=3145 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=f3374b1d-1b00-0000-f9f7-6b20490c0000 pid=3145 clone guuid=df380f1e-1b00-0000-f9f7-6b204e0c0000 pid=3150 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=df380f1e-1b00-0000-f9f7-6b204e0c0000 pid=3150 execve guuid=9056421e-1b00-0000-f9f7-6b204f0c0000 pid=3151 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=9056421e-1b00-0000-f9f7-6b204f0c0000 pid=3151 clone guuid=7e1dbb1e-1b00-0000-f9f7-6b20530c0000 pid=3155 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=7e1dbb1e-1b00-0000-f9f7-6b20530c0000 pid=3155 execve guuid=1c57041f-1b00-0000-f9f7-6b20550c0000 pid=3157 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=1c57041f-1b00-0000-f9f7-6b20550c0000 pid=3157 clone guuid=7f7b141f-1b00-0000-f9f7-6b20560c0000 pid=3158 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=7f7b141f-1b00-0000-f9f7-6b20560c0000 pid=3158 execve guuid=2b08481f-1b00-0000-f9f7-6b20580c0000 pid=3160 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=2b08481f-1b00-0000-f9f7-6b20580c0000 pid=3160 clone guuid=fcf2be1f-1b00-0000-f9f7-6b205b0c0000 pid=3163 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=fcf2be1f-1b00-0000-f9f7-6b205b0c0000 pid=3163 execve guuid=e0e2f01f-1b00-0000-f9f7-6b205d0c0000 pid=3165 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=e0e2f01f-1b00-0000-f9f7-6b205d0c0000 pid=3165 clone guuid=72196420-1b00-0000-f9f7-6b20600c0000 pid=3168 /usr/bin/chmod guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=72196420-1b00-0000-f9f7-6b20600c0000 pid=3168 execve guuid=7bd49f20-1b00-0000-f9f7-6b20610c0000 pid=3169 /usr/bin/dash guuid=59e65c88-1900-0000-f9f7-6b20c8080000 pid=2248->guuid=7bd49f20-1b00-0000-f9f7-6b20610c0000 pid=3169 clone d7a8a074-3c0d-5bba-86a5-987a33f76043 185.208.158.140:80 guuid=741b4689-1900-0000-f9f7-6b20cd080000 pid=2253->d7a8a074-3c0d-5bba-86a5-987a33f76043 send: 133B guuid=dbc15b95-1900-0000-f9f7-6b20e4080000 pid=2276->d7a8a074-3c0d-5bba-86a5-987a33f76043 send: 134B guuid=ccd0189d-1900-0000-f9f7-6b20fb080000 pid=2299->d7a8a074-3c0d-5bba-86a5-987a33f76043 send: 134B guuid=718733a1-1900-0000-f9f7-6b2002090000 pid=2306->d7a8a074-3c0d-5bba-86a5-987a33f76043 send: 134B guuid=0863daa8-1900-0000-f9f7-6b2018090000 pid=2328->d7a8a074-3c0d-5bba-86a5-987a33f76043 send: 134B guuid=111b40b1-1900-0000-f9f7-6b202a090000 pid=2346->d7a8a074-3c0d-5bba-86a5-987a33f76043 send: 136B guuid=3ede82ba-1900-0000-f9f7-6b2041090000 pid=2369->d7a8a074-3c0d-5bba-86a5-987a33f76043 send: 137B guuid=2f2321c2-1900-0000-f9f7-6b2058090000 pid=2392->d7a8a074-3c0d-5bba-86a5-987a33f76043 send: 133B guuid=fe4f9dc9-1900-0000-f9f7-6b2068090000 pid=2408->d7a8a074-3c0d-5bba-86a5-987a33f76043 send: 135B guuid=1c1d3bd1-1900-0000-f9f7-6b207b090000 pid=2427->d7a8a074-3c0d-5bba-86a5-987a33f76043 send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=27451dd8-1900-0000-f9f7-6b2084090000 pid=2436->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e2f43fd8-1900-0000-f9f7-6b2085090000 pid=2437 /home/sandbox/x86_64 dns net send-data zombie guuid=27451dd8-1900-0000-f9f7-6b2084090000 pid=2436->guuid=e2f43fd8-1900-0000-f9f7-6b2085090000 pid=2437 clone guuid=e2f43fd8-1900-0000-f9f7-6b2085090000 pid=2437->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 37B 8b9b4624-d458-58bb-98b6-f09d4c6b2dcf bot.skylablool.live:38241 guuid=e2f43fd8-1900-0000-f9f7-6b2085090000 pid=2437->8b9b4624-d458-58bb-98b6-f09d4c6b2dcf con guuid=f1ec49d8-1900-0000-f9f7-6b2086090000 pid=2438 /home/sandbox/x86_64 guuid=e2f43fd8-1900-0000-f9f7-6b2085090000 pid=2437->guuid=f1ec49d8-1900-0000-f9f7-6b2086090000 pid=2438 clone guuid=23ff50d8-1900-0000-f9f7-6b2087090000 pid=2439 /home/sandbox/x86_64 net net-scan send-data guuid=e2f43fd8-1900-0000-f9f7-6b2085090000 pid=2437->guuid=23ff50d8-1900-0000-f9f7-6b2087090000 pid=2439 clone guuid=3c2655d8-1900-0000-f9f7-6b2089090000 pid=2441 /home/sandbox/x86_64 net net-scan send-data guuid=e2f43fd8-1900-0000-f9f7-6b2085090000 pid=2437->guuid=3c2655d8-1900-0000-f9f7-6b2089090000 pid=2441 clone guuid=23ff50d8-1900-0000-f9f7-6b2087090000 pid=2439->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=23ff50d8-1900-0000-f9f7-6b2087090000 pid=2439|send-data send-data to 256 IP addresses review logs to see them all guuid=23ff50d8-1900-0000-f9f7-6b2087090000 pid=2439->guuid=23ff50d8-1900-0000-f9f7-6b2087090000 pid=2439|send-data send guuid=c33651d8-1900-0000-f9f7-6b2088090000 pid=2440->d7a8a074-3c0d-5bba-86a5-987a33f76043 send: 136B guuid=3c2655d8-1900-0000-f9f7-6b2089090000 pid=2441->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3c2655d8-1900-0000-f9f7-6b2089090000 pid=2441|send-data send-data to 512 IP addresses review logs to see them all guuid=3c2655d8-1900-0000-f9f7-6b2089090000 pid=2441->guuid=3c2655d8-1900-0000-f9f7-6b2089090000 pid=2441|send-data send guuid=a0fe7ee7-1900-0000-f9f7-6b209a090000 pid=2458->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 43a95818-0aa8-581a-825a-e5448b5aba94 0.0.0.0:34783 guuid=a0fe7ee7-1900-0000-f9f7-6b209a090000 pid=2458->43a95818-0aa8-581a-825a-e5448b5aba94 con guuid=b587091d-1b00-0000-f9f7-6b20430c0000 pid=3139 /home/sandbox/x86_32 dns net send-data zombie guuid=a0fe7ee7-1900-0000-f9f7-6b209a090000 pid=2458->guuid=b587091d-1b00-0000-f9f7-6b20430c0000 pid=3139 clone guuid=b587091d-1b00-0000-f9f7-6b20430c0000 pid=3139->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 37B guuid=b587091d-1b00-0000-f9f7-6b20430c0000 pid=3139->8b9b4624-d458-58bb-98b6-f09d4c6b2dcf send: 15B guuid=ca26171d-1b00-0000-f9f7-6b20450c0000 pid=3141 /home/sandbox/x86_32 guuid=b587091d-1b00-0000-f9f7-6b20430c0000 pid=3139->guuid=ca26171d-1b00-0000-f9f7-6b20450c0000 pid=3141 clone guuid=6c271a1d-1b00-0000-f9f7-6b20460c0000 pid=3142 /home/sandbox/x86_32 net net-scan send-data guuid=b587091d-1b00-0000-f9f7-6b20430c0000 pid=3139->guuid=6c271a1d-1b00-0000-f9f7-6b20460c0000 pid=3142 clone guuid=e71c1d1d-1b00-0000-f9f7-6b20470c0000 pid=3143 /home/sandbox/x86_32 net net-scan send-data guuid=b587091d-1b00-0000-f9f7-6b20430c0000 pid=3139->guuid=e71c1d1d-1b00-0000-f9f7-6b20470c0000 pid=3143 clone guuid=6c271a1d-1b00-0000-f9f7-6b20460c0000 pid=3142->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6c271a1d-1b00-0000-f9f7-6b20460c0000 pid=3142|send-data send-data to 4097 IP addresses review logs to see them all guuid=6c271a1d-1b00-0000-f9f7-6b20460c0000 pid=3142->guuid=6c271a1d-1b00-0000-f9f7-6b20460c0000 pid=3142|send-data send guuid=e71c1d1d-1b00-0000-f9f7-6b20470c0000 pid=3143->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 349533b2-3aaa-55b5-b7d6-e5d39be9f259 79.142.77.81:23 guuid=e71c1d1d-1b00-0000-f9f7-6b20470c0000 pid=3143->349533b2-3aaa-55b5-b7d6-e5d39be9f259 send: 40B 75f0a818-5e9b-5e61-b5b4-aaf64c4d1dc7 39.59.39.137:23 guuid=e71c1d1d-1b00-0000-f9f7-6b20470c0000 pid=3143->75f0a818-5e9b-5e61-b5b4-aaf64c4d1dc7 con guuid=e71c1d1d-1b00-0000-f9f7-6b20470c0000 pid=3143|send-data send-data to 4097 IP addresses review logs to see them all guuid=e71c1d1d-1b00-0000-f9f7-6b20470c0000 pid=3143->guuid=e71c1d1d-1b00-0000-f9f7-6b20470c0000 pid=3143|send-data send
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-07-04 04:31:21 UTC
File Type:
Text (Shell)
AV detection:
14 of 38 (36.84%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f5f7e99c2b01bada211a396efc4921ff6b23cd19fcb0be3ba5bdc137bfd48e9a

(this sample)

  
Delivery method
Distributed via web download

Comments