MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f7ed84a0db401c71c87c6adfa25b10533238f06747073cc6b0cd7a7db4366744. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f7ed84a0db401c71c87c6adfa25b10533238f06747073cc6b0cd7a7db4366744
SHA3-384 hash: 4fa0c4e795cb3396a3d0883d0bde51c2f845d80a13a353523b8cea50076421ee94f5418ded342f285e9ef7b6fcbacbab
SHA1 hash: 644d21783ec6138cd4a9e29c314c60c605707cd1
MD5 hash: 1ebd8b70ab1ac51920ff657b60d8ab7a
humanhash: six-robin-coffee-tennessee
File name:c.sh
Download: download sample
Signature Mirai
File size:846 bytes
First seen:2025-08-15 21:30:00 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:3J3n0Ve0GYG0HNI7V0vKl02+IJ0zjw0tT40ylh07t80Uh0VG09n:SDGYpmGvDLISzLpflFUa/9
TLSH T1FE01F1ECBB716997DB09CF25E0678048902098E175744F16D9F60CF9DCEA30131B967D
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://138.201.154.194/systemcl/arma2812bf91c1836b0749615f8c92f49b055ed1152a0cfcb03cffb4473388ae1f9 Mirai32-bit elf mirai Mozi
http://138.201.154.194/systemcl/arm5467ca3ecdb388a31f9687f3f93134ae992fbfbe2936cfbd700c3d198b3b65ecb Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/arm67a4627901da5e02ceacaf688cc103b4944a3cf75b4f1f4316ee638893eaa4104 Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/arm71745a1dc09e108e719186017f4d6f10e1835aa4ba3f74b50b8394e3268c66524 Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/m68k19abfca0200531ee5ddc2dd7bc4454af84d9ffe0ef2e12cd2a54fc828ebdc659 Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/mipsad42066092b60784e1579fb3742cf3a41450dacc13b254e9c3a0c5b84aaf0db4 Mirai32-bit elf mirai Mozi
http://138.201.154.194/systemcl/mpsl7365564e3fc5bc60caa91eb8b6b87a6d8da423389be87134899fcd0caaeb3242 Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/ppcabfd19ac36a02a8d3552a65a6e023b7499af427f7ea558cbc5064b8475bd955e Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/sh4b5d5a320320766751e9a1e31bc6ff850196e0c3f0b5baee15eee600b8a3cdae2 Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/spc2b4e44a8a37c63ce0a2c007bb22d903ae9d13b643b6b556f4d15199926cdd54c Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/x862e9b4bb064c078485eab38389da45cfecd1f865d77cd5c199ae3c2fe195daf72 Mirai32-bit elf mirai Mozi
http://138.201.154.194/systemcl/x86_6447a0fa2b9aa3ebdb48324d5ad43903187a528176193716db81991191b3d3b230 Miraielf geofenced mirai opendir ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=61005589-1a00-0000-b61d-321c390a0000 pid=2617 /usr/bin/sudo guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626 /tmp/sample.bin guuid=61005589-1a00-0000-b61d-321c390a0000 pid=2617->guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626 execve guuid=5df2c68c-1a00-0000-b61d-321c440a0000 pid=2628 /usr/bin/curl net send-data guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=5df2c68c-1a00-0000-b61d-321c440a0000 pid=2628 execve guuid=1749c09e-1a00-0000-b61d-321c6f0a0000 pid=2671 /usr/bin/chmod guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=1749c09e-1a00-0000-b61d-321c6f0a0000 pid=2671 execve guuid=9687549f-1a00-0000-b61d-321c700a0000 pid=2672 /usr/bin/dash guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=9687549f-1a00-0000-b61d-321c700a0000 pid=2672 clone guuid=b238a49f-1a00-0000-b61d-321c720a0000 pid=2674 /usr/bin/curl net send-data guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=b238a49f-1a00-0000-b61d-321c720a0000 pid=2674 execve guuid=d1883ea9-1a00-0000-b61d-321c8d0a0000 pid=2701 /usr/bin/chmod guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=d1883ea9-1a00-0000-b61d-321c8d0a0000 pid=2701 execve guuid=e4909fa9-1a00-0000-b61d-321c8f0a0000 pid=2703 /usr/bin/dash guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=e4909fa9-1a00-0000-b61d-321c8f0a0000 pid=2703 clone guuid=7745b3a9-1a00-0000-b61d-321c900a0000 pid=2704 /usr/bin/curl net send-data guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=7745b3a9-1a00-0000-b61d-321c900a0000 pid=2704 execve guuid=6473deb1-1a00-0000-b61d-321ca70a0000 pid=2727 /usr/bin/chmod guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=6473deb1-1a00-0000-b61d-321ca70a0000 pid=2727 execve guuid=7eda48b2-1a00-0000-b61d-321ca90a0000 pid=2729 /usr/bin/dash guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=7eda48b2-1a00-0000-b61d-321ca90a0000 pid=2729 clone guuid=f5fb78b2-1a00-0000-b61d-321caa0a0000 pid=2730 /usr/bin/curl net send-data guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=f5fb78b2-1a00-0000-b61d-321caa0a0000 pid=2730 execve guuid=8c5422bd-1a00-0000-b61d-321cbf0a0000 pid=2751 /usr/bin/chmod guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=8c5422bd-1a00-0000-b61d-321cbf0a0000 pid=2751 execve guuid=cd7d72bd-1a00-0000-b61d-321cc10a0000 pid=2753 /usr/bin/dash guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=cd7d72bd-1a00-0000-b61d-321cc10a0000 pid=2753 clone guuid=4b3878bd-1a00-0000-b61d-321cc20a0000 pid=2754 /usr/bin/curl net send-data guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=4b3878bd-1a00-0000-b61d-321cc20a0000 pid=2754 execve guuid=1f22e8c4-1a00-0000-b61d-321cd00a0000 pid=2768 /usr/bin/chmod guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=1f22e8c4-1a00-0000-b61d-321cd00a0000 pid=2768 execve guuid=0bac6ac5-1a00-0000-b61d-321cd20a0000 pid=2770 /usr/bin/dash guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=0bac6ac5-1a00-0000-b61d-321cd20a0000 pid=2770 clone guuid=723380c5-1a00-0000-b61d-321cd30a0000 pid=2771 /usr/bin/curl net send-data guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=723380c5-1a00-0000-b61d-321cd30a0000 pid=2771 execve guuid=f4ea30cd-1a00-0000-b61d-321cdc0a0000 pid=2780 /usr/bin/chmod guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=f4ea30cd-1a00-0000-b61d-321cdc0a0000 pid=2780 execve guuid=39d371cd-1a00-0000-b61d-321cde0a0000 pid=2782 /usr/bin/dash guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=39d371cd-1a00-0000-b61d-321cde0a0000 pid=2782 clone guuid=833f81cd-1a00-0000-b61d-321cdf0a0000 pid=2783 /usr/bin/curl net send-data guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=833f81cd-1a00-0000-b61d-321cdf0a0000 pid=2783 execve guuid=35caa3d4-1a00-0000-b61d-321ce60a0000 pid=2790 /usr/bin/chmod guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=35caa3d4-1a00-0000-b61d-321ce60a0000 pid=2790 execve guuid=e3331bd5-1a00-0000-b61d-321ce80a0000 pid=2792 /usr/bin/dash guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=e3331bd5-1a00-0000-b61d-321ce80a0000 pid=2792 clone guuid=da1127d5-1a00-0000-b61d-321ce90a0000 pid=2793 /usr/bin/curl net send-data guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=da1127d5-1a00-0000-b61d-321ce90a0000 pid=2793 execve guuid=102a89dd-1a00-0000-b61d-321cfa0a0000 pid=2810 /usr/bin/chmod guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=102a89dd-1a00-0000-b61d-321cfa0a0000 pid=2810 execve guuid=255ef0dd-1a00-0000-b61d-321cfb0a0000 pid=2811 /usr/bin/dash guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=255ef0dd-1a00-0000-b61d-321cfb0a0000 pid=2811 clone guuid=d6f202de-1a00-0000-b61d-321cfc0a0000 pid=2812 /usr/bin/curl net send-data guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=d6f202de-1a00-0000-b61d-321cfc0a0000 pid=2812 execve guuid=fe59e2e5-1a00-0000-b61d-321c030b0000 pid=2819 /usr/bin/chmod guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=fe59e2e5-1a00-0000-b61d-321c030b0000 pid=2819 execve guuid=120e38e6-1a00-0000-b61d-321c050b0000 pid=2821 /usr/bin/dash guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=120e38e6-1a00-0000-b61d-321c050b0000 pid=2821 clone guuid=20c94ce6-1a00-0000-b61d-321c060b0000 pid=2822 /usr/bin/curl net send-data guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=20c94ce6-1a00-0000-b61d-321c060b0000 pid=2822 execve guuid=cad9f4f1-1a00-0000-b61d-321c1d0b0000 pid=2845 /usr/bin/chmod guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=cad9f4f1-1a00-0000-b61d-321c1d0b0000 pid=2845 execve guuid=587757f2-1a00-0000-b61d-321c1e0b0000 pid=2846 /usr/bin/dash guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=587757f2-1a00-0000-b61d-321c1e0b0000 pid=2846 clone guuid=7d7a65f2-1a00-0000-b61d-321c1f0b0000 pid=2847 /usr/bin/curl net send-data guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=7d7a65f2-1a00-0000-b61d-321c1f0b0000 pid=2847 execve guuid=fdd3fef8-1a00-0000-b61d-321c280b0000 pid=2856 /usr/bin/chmod guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=fdd3fef8-1a00-0000-b61d-321c280b0000 pid=2856 execve guuid=58f186f9-1a00-0000-b61d-321c2a0b0000 pid=2858 /usr/bin/dash guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=58f186f9-1a00-0000-b61d-321c2a0b0000 pid=2858 clone guuid=e0fd9bf9-1a00-0000-b61d-321c2b0b0000 pid=2859 /usr/bin/curl net send-data guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=e0fd9bf9-1a00-0000-b61d-321c2b0b0000 pid=2859 execve guuid=0c968702-1b00-0000-b61d-321c380b0000 pid=2872 /usr/bin/chmod guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=0c968702-1b00-0000-b61d-321c380b0000 pid=2872 execve guuid=d5ffd802-1b00-0000-b61d-321c390b0000 pid=2873 /usr/bin/dash guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=d5ffd802-1b00-0000-b61d-321c390b0000 pid=2873 clone guuid=461bed02-1b00-0000-b61d-321c3a0b0000 pid=2874 /usr/bin/rm delete-file guuid=7906628c-1a00-0000-b61d-321c420a0000 pid=2626->guuid=461bed02-1b00-0000-b61d-321c3a0b0000 pid=2874 execve 0d8bcf72-e418-554e-aa94-b31d69d8ccca 138.201.154.194:80 guuid=5df2c68c-1a00-0000-b61d-321c440a0000 pid=2628->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 91B guuid=b238a49f-1a00-0000-b61d-321c720a0000 pid=2674->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 92B guuid=7745b3a9-1a00-0000-b61d-321c900a0000 pid=2704->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 92B guuid=f5fb78b2-1a00-0000-b61d-321caa0a0000 pid=2730->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 92B guuid=4b3878bd-1a00-0000-b61d-321cc20a0000 pid=2754->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 92B guuid=723380c5-1a00-0000-b61d-321cd30a0000 pid=2771->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 92B guuid=833f81cd-1a00-0000-b61d-321cdf0a0000 pid=2783->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 92B guuid=da1127d5-1a00-0000-b61d-321ce90a0000 pid=2793->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 91B guuid=d6f202de-1a00-0000-b61d-321cfc0a0000 pid=2812->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 91B guuid=20c94ce6-1a00-0000-b61d-321c060b0000 pid=2822->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 91B guuid=7d7a65f2-1a00-0000-b61d-321c1f0b0000 pid=2847->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 91B guuid=e0fd9bf9-1a00-0000-b61d-321c2b0b0000 pid=2859->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 94B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Alevaul
Status:
Malicious
First seen:
2025-08-15 21:23:13 UTC
File Type:
Text (Shell)
AV detection:
17 of 38 (44.74%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f7ed84a0db401c71c87c6adfa25b10533238f06747073cc6b0cd7a7db4366744

(this sample)

  
Delivery method
Distributed via web download

Comments