MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fbc26ed21f0f6123fd0d98827cf63052c14b37a770ad3178245f7ee150159487. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: fbc26ed21f0f6123fd0d98827cf63052c14b37a770ad3178245f7ee150159487
SHA3-384 hash: 5309928dc8646039f257cabde2c6c9de8718ad3259490039e3025468352baeb89e1ee210fea78e1ec2df26586125b44e
SHA1 hash: edb24d8065432af1f7a36473311646f951dd3860
MD5 hash: 55116c2440648b887efa4d47f73caade
humanhash: sweet-alanine-missouri-potato
File name:curl.sh
Download: download sample
Signature Mirai
File size:772 bytes
First seen:2025-09-14 11:36:56 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3UVFwpUVBhuUVXTFpUVJkUVIoDUZ9qTC4SUZ8LhZULU5jthn:3J3IFdBhFXTUJbBWqTC42h3n
TLSH T13601C89CD1D2BCB3912C9E38F962428F1042D1CEA9BB8BD2ED31142B88E3D4021D4A66
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.94.209.216/arcee9180bd2b165795dfaaf5d6de60148d34353c66373cc322e49eaf532de435f9 Miraielf mirai
http://158.94.209.216/arm14883298489d57b2242533f561769e8f21737126e8560c4b9955dc701478c23e Mirai32-bit elf mirai Mozi
http://158.94.209.216/arm582ee72be70e8dce122910449268514083943892258ea9b9d21068e03286d03f8 Miraielf mirai
http://158.94.209.216/arm657a6ba282a2ffad3469d83844906606272225fdaeb15c2e2043a11978240de4b Miraielf mirai
http://158.94.209.216/arm75a469ba94c55f39fdf0656a0a1b98c988d699569397587d8e1141a0d928b9eea Miraielf mirai
http://158.94.209.216/mips77637c28bd5ccda2ad3c90c2d34e879fa7e10f1abe04520e5bda11cd7ed69c8e Gafgyt32-bit elf gafgyt Mozi
http://158.94.209.216/mpslafe59ccdfac00527b2983101bc1e5d91361609b4753962e0cb2cc890b8a35d2f Gafgytelf gafgyt
http://158.94.209.216/ppca8de55bad2e1d7f6821139880b74b7345a242dd8f6296f626cdceb07d5f5742e Miraielf mirai
http://158.94.209.216/sh471cf2bcec3f927abc59bb4a57e950a1685ce005380b6a2e3dad891788828dc07 Gafgytelf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-09-14T09:20:00Z UTC
Last seen:
2025-09-14T09:20:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=8857761e-1900-0000-d60a-5f4ead070000 pid=1965 /usr/bin/sudo guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966 /tmp/sample.bin guuid=8857761e-1900-0000-d60a-5f4ead070000 pid=1965->guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966 execve guuid=94608c21-1900-0000-d60a-5f4eaf070000 pid=1967 /usr/bin/curl net send-data write-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=94608c21-1900-0000-d60a-5f4eaf070000 pid=1967 execve guuid=b63f2543-1900-0000-d60a-5f4ebd070000 pid=1981 /usr/bin/chmod guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=b63f2543-1900-0000-d60a-5f4ebd070000 pid=1981 execve guuid=10637a43-1900-0000-d60a-5f4ebe070000 pid=1982 /usr/bin/dash guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=10637a43-1900-0000-d60a-5f4ebe070000 pid=1982 clone guuid=489a2846-1900-0000-d60a-5f4ec1070000 pid=1985 /usr/bin/rm delete-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=489a2846-1900-0000-d60a-5f4ec1070000 pid=1985 execve guuid=337b8146-1900-0000-d60a-5f4ec3070000 pid=1987 /usr/bin/curl net send-data write-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=337b8146-1900-0000-d60a-5f4ec3070000 pid=1987 execve guuid=6c590d56-1900-0000-d60a-5f4edf070000 pid=2015 /usr/bin/chmod guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=6c590d56-1900-0000-d60a-5f4edf070000 pid=2015 execve guuid=7fea5556-1900-0000-d60a-5f4ee0070000 pid=2016 /usr/bin/dash guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=7fea5556-1900-0000-d60a-5f4ee0070000 pid=2016 clone guuid=64341e57-1900-0000-d60a-5f4ee5070000 pid=2021 /usr/bin/rm delete-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=64341e57-1900-0000-d60a-5f4ee5070000 pid=2021 execve guuid=da2c5b57-1900-0000-d60a-5f4ee7070000 pid=2023 /usr/bin/curl net send-data write-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=da2c5b57-1900-0000-d60a-5f4ee7070000 pid=2023 execve guuid=1898f369-1900-0000-d60a-5f4e0f080000 pid=2063 /usr/bin/chmod guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=1898f369-1900-0000-d60a-5f4e0f080000 pid=2063 execve guuid=4cf13f6a-1900-0000-d60a-5f4e11080000 pid=2065 /usr/bin/dash guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=4cf13f6a-1900-0000-d60a-5f4e11080000 pid=2065 clone guuid=3198e66a-1900-0000-d60a-5f4e15080000 pid=2069 /usr/bin/rm delete-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=3198e66a-1900-0000-d60a-5f4e15080000 pid=2069 execve guuid=0e6f286b-1900-0000-d60a-5f4e17080000 pid=2071 /usr/bin/curl net send-data write-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=0e6f286b-1900-0000-d60a-5f4e17080000 pid=2071 execve guuid=862d437a-1900-0000-d60a-5f4e3d080000 pid=2109 /usr/bin/chmod guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=862d437a-1900-0000-d60a-5f4e3d080000 pid=2109 execve guuid=52b98d7a-1900-0000-d60a-5f4e3f080000 pid=2111 /usr/bin/dash guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=52b98d7a-1900-0000-d60a-5f4e3f080000 pid=2111 clone guuid=e46a987b-1900-0000-d60a-5f4e43080000 pid=2115 /usr/bin/rm delete-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=e46a987b-1900-0000-d60a-5f4e43080000 pid=2115 execve guuid=69b9e17b-1900-0000-d60a-5f4e44080000 pid=2116 /usr/bin/curl net send-data write-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=69b9e17b-1900-0000-d60a-5f4e44080000 pid=2116 execve guuid=4b89028f-1900-0000-d60a-5f4e67080000 pid=2151 /usr/bin/chmod guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=4b89028f-1900-0000-d60a-5f4e67080000 pid=2151 execve guuid=0a18618f-1900-0000-d60a-5f4e69080000 pid=2153 /usr/bin/dash guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=0a18618f-1900-0000-d60a-5f4e69080000 pid=2153 clone guuid=ee115990-1900-0000-d60a-5f4e6d080000 pid=2157 /usr/bin/rm delete-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=ee115990-1900-0000-d60a-5f4e6d080000 pid=2157 execve guuid=b80be790-1900-0000-d60a-5f4e70080000 pid=2160 /usr/bin/curl net send-data write-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=b80be790-1900-0000-d60a-5f4e70080000 pid=2160 execve guuid=430258a1-1900-0000-d60a-5f4e8e080000 pid=2190 /usr/bin/chmod guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=430258a1-1900-0000-d60a-5f4e8e080000 pid=2190 execve guuid=d9f7b9a1-1900-0000-d60a-5f4e8f080000 pid=2191 /usr/bin/dash guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=d9f7b9a1-1900-0000-d60a-5f4e8f080000 pid=2191 clone guuid=f9b061a3-1900-0000-d60a-5f4e94080000 pid=2196 /usr/bin/rm delete-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=f9b061a3-1900-0000-d60a-5f4e94080000 pid=2196 execve guuid=ad9dfaa3-1900-0000-d60a-5f4e97080000 pid=2199 /usr/bin/curl net send-data write-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=ad9dfaa3-1900-0000-d60a-5f4e97080000 pid=2199 execve guuid=745e00b3-1900-0000-d60a-5f4eca080000 pid=2250 /usr/bin/chmod guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=745e00b3-1900-0000-d60a-5f4eca080000 pid=2250 execve guuid=0b4351b3-1900-0000-d60a-5f4ecc080000 pid=2252 /usr/bin/dash guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=0b4351b3-1900-0000-d60a-5f4ecc080000 pid=2252 clone guuid=d5180cb4-1900-0000-d60a-5f4ed0080000 pid=2256 /usr/bin/rm delete-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=d5180cb4-1900-0000-d60a-5f4ed0080000 pid=2256 execve guuid=71b369b4-1900-0000-d60a-5f4ed2080000 pid=2258 /usr/bin/curl net send-data write-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=71b369b4-1900-0000-d60a-5f4ed2080000 pid=2258 execve guuid=156773c3-1900-0000-d60a-5f4eff080000 pid=2303 /usr/bin/chmod guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=156773c3-1900-0000-d60a-5f4eff080000 pid=2303 execve guuid=c7d8d0c3-1900-0000-d60a-5f4e02090000 pid=2306 /usr/bin/dash guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=c7d8d0c3-1900-0000-d60a-5f4e02090000 pid=2306 clone guuid=897898c4-1900-0000-d60a-5f4e05090000 pid=2309 /usr/bin/rm delete-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=897898c4-1900-0000-d60a-5f4e05090000 pid=2309 execve guuid=996540c9-1900-0000-d60a-5f4e06090000 pid=2310 /usr/bin/curl net send-data write-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=996540c9-1900-0000-d60a-5f4e06090000 pid=2310 execve guuid=47db1bd8-1900-0000-d60a-5f4e2d090000 pid=2349 /usr/bin/chmod guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=47db1bd8-1900-0000-d60a-5f4e2d090000 pid=2349 execve guuid=8fb959d8-1900-0000-d60a-5f4e2f090000 pid=2351 /usr/bin/dash guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=8fb959d8-1900-0000-d60a-5f4e2f090000 pid=2351 clone guuid=1d8ae7d8-1900-0000-d60a-5f4e33090000 pid=2355 /usr/bin/rm delete-file guuid=6d773621-1900-0000-d60a-5f4eae070000 pid=1966->guuid=1d8ae7d8-1900-0000-d60a-5f4e33090000 pid=2355 execve 09d65e53-632c-52c6-b821-8fe0f69e747e 158.94.209.216:80 guuid=94608c21-1900-0000-d60a-5f4eaf070000 pid=1967->09d65e53-632c-52c6-b821-8fe0f69e747e send: 81B guuid=94608c21-1900-0000-d60a-5f4eaf070000 pid=1979 /usr/bin/curl dns net send-data guuid=94608c21-1900-0000-d60a-5f4eaf070000 pid=1967->guuid=94608c21-1900-0000-d60a-5f4eaf070000 pid=1979 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=94608c21-1900-0000-d60a-5f4eaf070000 pid=1979->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 84B guuid=337b8146-1900-0000-d60a-5f4ec3070000 pid=1987->09d65e53-632c-52c6-b821-8fe0f69e747e send: 81B guuid=337b8146-1900-0000-d60a-5f4ec3070000 pid=2014 /usr/bin/curl dns net send-data guuid=337b8146-1900-0000-d60a-5f4ec3070000 pid=1987->guuid=337b8146-1900-0000-d60a-5f4ec3070000 pid=2014 clone guuid=337b8146-1900-0000-d60a-5f4ec3070000 pid=2014->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 84B guuid=da2c5b57-1900-0000-d60a-5f4ee7070000 pid=2023->09d65e53-632c-52c6-b821-8fe0f69e747e send: 82B guuid=da2c5b57-1900-0000-d60a-5f4ee7070000 pid=2061 /usr/bin/curl dns net send-data guuid=da2c5b57-1900-0000-d60a-5f4ee7070000 pid=2023->guuid=da2c5b57-1900-0000-d60a-5f4ee7070000 pid=2061 clone guuid=da2c5b57-1900-0000-d60a-5f4ee7070000 pid=2061->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 88B guuid=0e6f286b-1900-0000-d60a-5f4e17080000 pid=2071->09d65e53-632c-52c6-b821-8fe0f69e747e send: 82B guuid=0e6f286b-1900-0000-d60a-5f4e17080000 pid=2106 /usr/bin/curl dns net send-data guuid=0e6f286b-1900-0000-d60a-5f4e17080000 pid=2071->guuid=0e6f286b-1900-0000-d60a-5f4e17080000 pid=2106 clone guuid=0e6f286b-1900-0000-d60a-5f4e17080000 pid=2106->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 88B guuid=69b9e17b-1900-0000-d60a-5f4e44080000 pid=2116->09d65e53-632c-52c6-b821-8fe0f69e747e send: 82B guuid=69b9e17b-1900-0000-d60a-5f4e44080000 pid=2147 /usr/bin/curl dns net send-data guuid=69b9e17b-1900-0000-d60a-5f4e44080000 pid=2116->guuid=69b9e17b-1900-0000-d60a-5f4e44080000 pid=2147 clone guuid=69b9e17b-1900-0000-d60a-5f4e44080000 pid=2147->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 88B guuid=b80be790-1900-0000-d60a-5f4e70080000 pid=2160->09d65e53-632c-52c6-b821-8fe0f69e747e send: 82B guuid=b80be790-1900-0000-d60a-5f4e70080000 pid=2187 /usr/bin/curl dns net send-data guuid=b80be790-1900-0000-d60a-5f4e70080000 pid=2160->guuid=b80be790-1900-0000-d60a-5f4e70080000 pid=2187 clone guuid=b80be790-1900-0000-d60a-5f4e70080000 pid=2187->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 88B guuid=ad9dfaa3-1900-0000-d60a-5f4e97080000 pid=2199->09d65e53-632c-52c6-b821-8fe0f69e747e send: 82B guuid=ad9dfaa3-1900-0000-d60a-5f4e97080000 pid=2247 /usr/bin/curl dns net send-data guuid=ad9dfaa3-1900-0000-d60a-5f4e97080000 pid=2199->guuid=ad9dfaa3-1900-0000-d60a-5f4e97080000 pid=2247 clone guuid=ad9dfaa3-1900-0000-d60a-5f4e97080000 pid=2247->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 88B guuid=71b369b4-1900-0000-d60a-5f4ed2080000 pid=2258->09d65e53-632c-52c6-b821-8fe0f69e747e send: 81B guuid=71b369b4-1900-0000-d60a-5f4ed2080000 pid=2300 /usr/bin/curl dns net send-data guuid=71b369b4-1900-0000-d60a-5f4ed2080000 pid=2258->guuid=71b369b4-1900-0000-d60a-5f4ed2080000 pid=2300 clone guuid=71b369b4-1900-0000-d60a-5f4ed2080000 pid=2300->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 84B guuid=996540c9-1900-0000-d60a-5f4e06090000 pid=2310->09d65e53-632c-52c6-b821-8fe0f69e747e send: 81B guuid=996540c9-1900-0000-d60a-5f4e06090000 pid=2347 /usr/bin/curl dns net send-data guuid=996540c9-1900-0000-d60a-5f4e06090000 pid=2310->guuid=996540c9-1900-0000-d60a-5f4e06090000 pid=2347 clone guuid=996540c9-1900-0000-d60a-5f4e06090000 pid=2347->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 84B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-09-14 11:31:34 UTC
File Type:
Text (Shell)
AV detection:
12 of 38 (31.58%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fbc26ed21f0f6123fd0d98827cf63052c14b37a770ad3178245f7ee150159487

(this sample)

  
Delivery method
Distributed via web download

Comments