MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f79b0f4f0360ba3f509d1927c9abdff740a48a765696bed2e5a6c15b3784cf20. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: f79b0f4f0360ba3f509d1927c9abdff740a48a765696bed2e5a6c15b3784cf20
SHA3-384 hash: 63e1693d2752910d236f5bfbcb8716b04368f7bc2b0c82446b7d79b4b56d18ad042f3dced483ecc6369748169855eba8
SHA1 hash: da99c123818166273bf1b3709d3adbbe6bc95d9a
MD5 hash: e5d7648dbbd90ad3835ea700e4325de8
humanhash: skylark-river-purple-maryland
File name:sh
Download: download sample
Signature Mirai
File size:268 bytes
First seen:2026-01-18 17:57:45 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:/VJ+pUKUF2RVYTeinYf53IUy5p3FsDKVKAOXqIKa03IKq1IEE1IKBKW:/VJ+jRPEY5WgAsONI08W
TLSH T1C5D02E0CF8030CB3B4348CF9BBDB24A4DA0FA21C2B0A65C92288221FE4F0C60A020623
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
ps1
First seen:
2026-01-18T15:03:00Z UTC
Last seen:
2026-01-19T12:53:00Z UTC
Hits:
~10
Detections:
Trojan-Downloader.Shell.Agent.bi HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=a508e8e3-1800-0000-1447-82b8640b0000 pid=2916 /usr/bin/sudo guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920 /tmp/sample.bin guuid=a508e8e3-1800-0000-1447-82b8640b0000 pid=2916->guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920 execve guuid=0f9959e6-1800-0000-1447-82b86a0b0000 pid=2922 /usr/bin/wget net send-data write-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=0f9959e6-1800-0000-1447-82b86a0b0000 pid=2922 execve guuid=56195707-1900-0000-1447-82b8af0b0000 pid=2991 /usr/bin/chmod guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=56195707-1900-0000-1447-82b8af0b0000 pid=2991 execve guuid=5f669307-1900-0000-1447-82b8b10b0000 pid=2993 /usr/bin/dash guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=5f669307-1900-0000-1447-82b8b10b0000 pid=2993 clone guuid=398e2208-1900-0000-1447-82b8b50b0000 pid=2997 /usr/bin/rm delete-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=398e2208-1900-0000-1447-82b8b50b0000 pid=2997 execve guuid=8d996208-1900-0000-1447-82b8b70b0000 pid=2999 /usr/bin/wget net send-data write-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=8d996208-1900-0000-1447-82b8b70b0000 pid=2999 execve guuid=4c4e6326-1900-0000-1447-82b80c0c0000 pid=3084 /usr/bin/chmod guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=4c4e6326-1900-0000-1447-82b80c0c0000 pid=3084 execve guuid=e83ba926-1900-0000-1447-82b80d0c0000 pid=3085 /usr/bin/dash guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=e83ba926-1900-0000-1447-82b80d0c0000 pid=3085 clone guuid=600f6027-1900-0000-1447-82b8100c0000 pid=3088 /usr/bin/rm delete-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=600f6027-1900-0000-1447-82b8100c0000 pid=3088 execve guuid=ef500b28-1900-0000-1447-82b8110c0000 pid=3089 /usr/bin/wget net send-data write-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=ef500b28-1900-0000-1447-82b8110c0000 pid=3089 execve guuid=dbdacd40-1900-0000-1447-82b8530c0000 pid=3155 /usr/bin/chmod guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=dbdacd40-1900-0000-1447-82b8530c0000 pid=3155 execve guuid=7a382b41-1900-0000-1447-82b8540c0000 pid=3156 /usr/bin/dash guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=7a382b41-1900-0000-1447-82b8540c0000 pid=3156 clone guuid=6ea4c542-1900-0000-1447-82b8560c0000 pid=3158 /usr/bin/rm delete-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=6ea4c542-1900-0000-1447-82b8560c0000 pid=3158 execve guuid=85c0b345-1900-0000-1447-82b8570c0000 pid=3159 /usr/bin/wget net send-data write-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=85c0b345-1900-0000-1447-82b8570c0000 pid=3159 execve guuid=3d4bdf5f-1900-0000-1447-82b8770c0000 pid=3191 /usr/bin/chmod guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=3d4bdf5f-1900-0000-1447-82b8770c0000 pid=3191 execve guuid=ff566760-1900-0000-1447-82b8780c0000 pid=3192 /usr/bin/dash guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=ff566760-1900-0000-1447-82b8780c0000 pid=3192 clone guuid=b9931a61-1900-0000-1447-82b87a0c0000 pid=3194 /usr/bin/rm delete-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=b9931a61-1900-0000-1447-82b87a0c0000 pid=3194 execve guuid=ed91c261-1900-0000-1447-82b87b0c0000 pid=3195 /usr/bin/wget net send-data write-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=ed91c261-1900-0000-1447-82b87b0c0000 pid=3195 execve guuid=d611627d-1900-0000-1447-82b8a00c0000 pid=3232 /usr/bin/chmod guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=d611627d-1900-0000-1447-82b8a00c0000 pid=3232 execve guuid=04e2b87d-1900-0000-1447-82b8a10c0000 pid=3233 /usr/bin/dash guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=04e2b87d-1900-0000-1447-82b8a10c0000 pid=3233 clone guuid=16fd617e-1900-0000-1447-82b8a30c0000 pid=3235 /usr/bin/rm delete-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=16fd617e-1900-0000-1447-82b8a30c0000 pid=3235 execve guuid=efedaa7e-1900-0000-1447-82b8a40c0000 pid=3236 /usr/bin/wget net send-data write-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=efedaa7e-1900-0000-1447-82b8a40c0000 pid=3236 execve guuid=8667b99d-1900-0000-1447-82b8bb0c0000 pid=3259 /usr/bin/chmod guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=8667b99d-1900-0000-1447-82b8bb0c0000 pid=3259 execve guuid=634d1e9e-1900-0000-1447-82b8bc0c0000 pid=3260 /usr/bin/dash guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=634d1e9e-1900-0000-1447-82b8bc0c0000 pid=3260 clone guuid=85d6c19e-1900-0000-1447-82b8c00c0000 pid=3264 /usr/bin/rm delete-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=85d6c19e-1900-0000-1447-82b8c00c0000 pid=3264 execve guuid=75831d9f-1900-0000-1447-82b8c20c0000 pid=3266 /usr/bin/wget net send-data write-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=75831d9f-1900-0000-1447-82b8c20c0000 pid=3266 execve guuid=4927fcb7-1900-0000-1447-82b8f30c0000 pid=3315 /usr/bin/chmod guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=4927fcb7-1900-0000-1447-82b8f30c0000 pid=3315 execve guuid=d0403cb8-1900-0000-1447-82b8f50c0000 pid=3317 /usr/bin/dash guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=d0403cb8-1900-0000-1447-82b8f50c0000 pid=3317 clone guuid=814fccb8-1900-0000-1447-82b8f90c0000 pid=3321 /usr/bin/rm delete-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=814fccb8-1900-0000-1447-82b8f90c0000 pid=3321 execve guuid=b3a625b9-1900-0000-1447-82b8fb0c0000 pid=3323 /usr/bin/wget net send-data write-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=b3a625b9-1900-0000-1447-82b8fb0c0000 pid=3323 execve guuid=256d01d2-1900-0000-1447-82b82c0d0000 pid=3372 /usr/bin/chmod guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=256d01d2-1900-0000-1447-82b82c0d0000 pid=3372 execve guuid=c65a4bd2-1900-0000-1447-82b82d0d0000 pid=3373 /usr/bin/dash guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=c65a4bd2-1900-0000-1447-82b82d0d0000 pid=3373 clone guuid=c9871bd3-1900-0000-1447-82b82f0d0000 pid=3375 /usr/bin/rm delete-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=c9871bd3-1900-0000-1447-82b82f0d0000 pid=3375 execve guuid=538e64d3-1900-0000-1447-82b8300d0000 pid=3376 /usr/bin/wget net send-data write-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=538e64d3-1900-0000-1447-82b8300d0000 pid=3376 execve guuid=b72af0eb-1900-0000-1447-82b8660d0000 pid=3430 /usr/bin/chmod guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=b72af0eb-1900-0000-1447-82b8660d0000 pid=3430 execve guuid=614c2dec-1900-0000-1447-82b8670d0000 pid=3431 /tmp/cron.kvariant guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=614c2dec-1900-0000-1447-82b8670d0000 pid=3431 execve guuid=78033fec-1900-0000-1447-82b86a0d0000 pid=3434 /usr/bin/rm delete-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=78033fec-1900-0000-1447-82b86a0d0000 pid=3434 execve guuid=b31878ec-1900-0000-1447-82b86c0d0000 pid=3436 /usr/bin/wget net send-data write-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=b31878ec-1900-0000-1447-82b86c0d0000 pid=3436 execve guuid=c3028d04-1a00-0000-1447-82b8b90d0000 pid=3513 /usr/bin/chmod guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=c3028d04-1a00-0000-1447-82b8b90d0000 pid=3513 execve guuid=cf62c904-1a00-0000-1447-82b8bb0d0000 pid=3515 /usr/bin/dash guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=cf62c904-1a00-0000-1447-82b8bb0d0000 pid=3515 clone guuid=59f59605-1a00-0000-1447-82b8c00d0000 pid=3520 /usr/bin/rm delete-file guuid=8fc610e6-1800-0000-1447-82b8680b0000 pid=2920->guuid=59f59605-1a00-0000-1447-82b8c00d0000 pid=3520 execve 9e269a19-b086-5b9b-9863-0a1f5412a545 198.144.189.70:80 guuid=0f9959e6-1800-0000-1447-82b86a0b0000 pid=2922->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 143B guuid=8d996208-1900-0000-1447-82b8b70b0000 pid=2999->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 143B guuid=ef500b28-1900-0000-1447-82b8110c0000 pid=3089->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 142B guuid=85c0b345-1900-0000-1447-82b8570c0000 pid=3159->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 143B guuid=ed91c261-1900-0000-1447-82b87b0c0000 pid=3195->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 143B guuid=efedaa7e-1900-0000-1447-82b8a40c0000 pid=3236->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 143B guuid=75831d9f-1900-0000-1447-82b8c20c0000 pid=3266->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 142B guuid=b3a625b9-1900-0000-1447-82b8fb0c0000 pid=3323->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 142B guuid=538e64d3-1900-0000-1447-82b8300d0000 pid=3376->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 142B guuid=3ff139ec-1900-0000-1447-82b8690d0000 pid=3433 /tmp/cron.kvariant zombie guuid=614c2dec-1900-0000-1447-82b8670d0000 pid=3431->guuid=3ff139ec-1900-0000-1447-82b8690d0000 pid=3433 clone guuid=845e3fec-1900-0000-1447-82b86b0d0000 pid=3435 /tmp/cron.kvariant net send-data zombie guuid=3ff139ec-1900-0000-1447-82b8690d0000 pid=3433->guuid=845e3fec-1900-0000-1447-82b86b0d0000 pid=3435 clone b176a1c4-7acf-5cab-9da1-7489b9f29878 198.144.189.70:41323 guuid=845e3fec-1900-0000-1447-82b86b0d0000 pid=3435->b176a1c4-7acf-5cab-9da1-7489b9f29878 send: 11B guuid=c7f7b039-1a00-0000-1447-82b83a0e0000 pid=3642 /tmp/cron.kvariant net net-scan send-data guuid=845e3fec-1900-0000-1447-82b86b0d0000 pid=3435->guuid=c7f7b039-1a00-0000-1447-82b83a0e0000 pid=3642 clone guuid=4608b539-1a00-0000-1447-82b83b0e0000 pid=3643 /tmp/cron.kvariant net net-scan send-data guuid=845e3fec-1900-0000-1447-82b86b0d0000 pid=3435->guuid=4608b539-1a00-0000-1447-82b83b0e0000 pid=3643 clone guuid=b31878ec-1900-0000-1447-82b86c0d0000 pid=3436->9e269a19-b086-5b9b-9863-0a1f5412a545 send: 142B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=c7f7b039-1a00-0000-1447-82b83a0e0000 pid=3642->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e0297e74-1bc4-592f-8b53-71bcd207e745 186.27.179.131:23 guuid=c7f7b039-1a00-0000-1447-82b83a0e0000 pid=3642->e0297e74-1bc4-592f-8b53-71bcd207e745 con guuid=c7f7b039-1a00-0000-1447-82b83a0e0000 pid=3642|send-data send-data to 4097 IP addresses review logs to see them all guuid=c7f7b039-1a00-0000-1447-82b83a0e0000 pid=3642->guuid=c7f7b039-1a00-0000-1447-82b83a0e0000 pid=3642|send-data send guuid=4608b539-1a00-0000-1447-82b83b0e0000 pid=3643->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 1f873996-b15c-5080-a416-36d7fdf3b52f 134.220.73.95:37215 guuid=4608b539-1a00-0000-1447-82b83b0e0000 pid=3643->1f873996-b15c-5080-a416-36d7fdf3b52f con guuid=4608b539-1a00-0000-1447-82b83b0e0000 pid=3643|send-data send-data to 4096 IP addresses review logs to see them all guuid=4608b539-1a00-0000-1447-82b83b0e0000 pid=3643->guuid=4608b539-1a00-0000-1447-82b83b0e0000 pid=3643|send-data send
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.MiraiB
Status:
Malicious
First seen:
2026-01-18 17:50:39 UTC
File Type:
Text (Shell)
AV detection:
12 of 36 (33.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f79b0f4f0360ba3f509d1927c9abdff740a48a765696bed2e5a6c15b3784cf20

(this sample)

  
Delivery method
Distributed via web download

Comments