MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fcf7ad5c421a0ab7c58a0adc7230e5607ceb214084539e0ebb4208371a496561. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: fcf7ad5c421a0ab7c58a0adc7230e5607ceb214084539e0ebb4208371a496561
SHA3-384 hash: 5525e708a0eac4476e258db8c7ec4b9acaf740f31febbed41514cf6dda53e2ceb66ab16897fc3c7c2a5ead1803492687
SHA1 hash: 2bbe5fcbb7f2ca8865fbfaa85ee60c99f0ca1b16
MD5 hash: 2460ea06924ef808adec1ef28e484301
humanhash: carbon-hot-pluto-monkey
File name:c.sh
Download: download sample
Signature Mirai
File size:708 bytes
First seen:2025-11-02 18:12:27 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3elpeS4QeKNIl51e30LKySD+OtSUJXSo+2STp2STpfippM8yS:3J3KbNI7xKbD+NUJioxwQwZiDV/
TLSH T1720175ECA4B2F787171EDF08F067C26D905190D2A3F0CE55E4990E35ACD8E01231936A
Magika batch
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://14.225.20.10/armcfaf3a934c7ca6e462a92dd30efd77e7d729c6489a89708d7d763b3c2044e87a Miraiarm elf geofenced mirai ua-wget USA
http://14.225.20.10/arm51dadc79006e0179905f7aacce2c3700236863cdfb470d57ea1c4147dc8250bb2 Miraiarm elf geofenced mirai ua-wget USA
http://14.225.20.10/arm6c114634ce88bf0e9e67e31d519352f797fc07443331e658b0b027e94e7d34896 Miraiarm elf geofenced mirai ua-wget USA
http://14.225.20.10/arm70bd072efea3edac7ceb4e7c36375286e4c3048c7bb64c830054d342db3a47682 Miraiarm elf geofenced mirai ua-wget USA
http://14.225.20.10/m68kb38d7da0820e78932e1076637f3a13b2f6159ac9a9d3f3ba5af679843a0e47b8 Miraielf geofenced m68k mirai ua-wget USA
http://14.225.20.10/mips6be7e802f862949380111de1f29bdfeb79bf29e95dae87c09075023eae08f04d Miraielf geofenced mips mirai ua-wget USA
http://14.225.20.10/mpsln/an/aelf geofenced mips mirai ua-wget USA
http://14.225.20.10/ppcfd0d38dd64ce7738b4518e0711ec7a03f2c7e01ec989eb0c7e77a13e81fc4b9d Miraielf geofenced mirai PowerPC ua-wget USA
http://14.225.20.10/spc7a76a08159df0a0ef83857daef41dc98d866c1cc939a3eecb93036a795750dab Miraielf geofenced mirai sparc ua-wget USA
http://14.225.20.10/x861e2220a4e7910b78cc5de178c301632b2e13c31697ed0a838e9ba0d460059225 Miraielf geofenced mirai ua-wget USA x86
http://14.225.20.10/x86_649b118ae3f035755a270475faa2ec351ff38ad1b3371fc83eed68089ba40fb88b Miraielf geofenced mirai ua-wget USA x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
ps1
First seen:
2025-11-02T15:27:00Z UTC
Last seen:
2025-11-03T10:18:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=03a3877b-3a00-0000-e25e-98655c040000 pid=1116 /usr/bin/sudo guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117 /tmp/sample.bin guuid=03a3877b-3a00-0000-e25e-98655c040000 pid=1116->guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117 execve guuid=758e3d7d-3a00-0000-e25e-98655e040000 pid=1118 /usr/bin/curl net send-data guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=758e3d7d-3a00-0000-e25e-98655e040000 pid=1118 execve guuid=c3bff4d2-3b00-0000-e25e-98655f040000 pid=1119 /usr/bin/chmod guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=c3bff4d2-3b00-0000-e25e-98655f040000 pid=1119 execve guuid=026436d3-3b00-0000-e25e-986560040000 pid=1120 /usr/bin/dash guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=026436d3-3b00-0000-e25e-986560040000 pid=1120 clone guuid=0a2644d3-3b00-0000-e25e-986561040000 pid=1121 /usr/bin/curl net send-data guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=0a2644d3-3b00-0000-e25e-986561040000 pid=1121 execve guuid=90d1d104-3c00-0000-e25e-986562040000 pid=1122 /usr/bin/chmod guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=90d1d104-3c00-0000-e25e-986562040000 pid=1122 execve guuid=33217805-3c00-0000-e25e-986563040000 pid=1123 /usr/bin/dash guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=33217805-3c00-0000-e25e-986563040000 pid=1123 clone guuid=bf7e9205-3c00-0000-e25e-986564040000 pid=1124 /usr/bin/curl net send-data guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=bf7e9205-3c00-0000-e25e-986564040000 pid=1124 execve guuid=9785fe55-3c00-0000-e25e-986565040000 pid=1125 /usr/bin/chmod guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=9785fe55-3c00-0000-e25e-986565040000 pid=1125 execve guuid=90117c56-3c00-0000-e25e-986566040000 pid=1126 /usr/bin/dash guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=90117c56-3c00-0000-e25e-986566040000 pid=1126 clone guuid=77fe8556-3c00-0000-e25e-986567040000 pid=1127 /usr/bin/curl net send-data guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=77fe8556-3c00-0000-e25e-986567040000 pid=1127 execve guuid=1004a8a4-3c00-0000-e25e-986568040000 pid=1128 /usr/bin/chmod guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=1004a8a4-3c00-0000-e25e-986568040000 pid=1128 execve guuid=21f213a5-3c00-0000-e25e-986569040000 pid=1129 /usr/bin/dash guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=21f213a5-3c00-0000-e25e-986569040000 pid=1129 clone guuid=9c7e25a5-3c00-0000-e25e-98656a040000 pid=1130 /usr/bin/curl net send-data guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=9c7e25a5-3c00-0000-e25e-98656a040000 pid=1130 execve guuid=02246ae5-3c00-0000-e25e-98656b040000 pid=1131 /usr/bin/chmod guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=02246ae5-3c00-0000-e25e-98656b040000 pid=1131 execve guuid=7a36d7e5-3c00-0000-e25e-98656c040000 pid=1132 /usr/bin/dash guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=7a36d7e5-3c00-0000-e25e-98656c040000 pid=1132 clone guuid=0757ebe5-3c00-0000-e25e-98656d040000 pid=1133 /usr/bin/curl net send-data guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=0757ebe5-3c00-0000-e25e-98656d040000 pid=1133 execve guuid=96172526-3d00-0000-e25e-98656e040000 pid=1134 /usr/bin/chmod guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=96172526-3d00-0000-e25e-98656e040000 pid=1134 execve guuid=4b177626-3d00-0000-e25e-98656f040000 pid=1135 /usr/bin/dash guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=4b177626-3d00-0000-e25e-98656f040000 pid=1135 clone guuid=eee4a426-3d00-0000-e25e-986570040000 pid=1136 /usr/bin/curl net send-data guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=eee4a426-3d00-0000-e25e-986570040000 pid=1136 execve guuid=f9afd17a-3d00-0000-e25e-986571040000 pid=1137 /usr/bin/chmod guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=f9afd17a-3d00-0000-e25e-986571040000 pid=1137 execve guuid=d7c9447b-3d00-0000-e25e-986572040000 pid=1138 /usr/bin/dash guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=d7c9447b-3d00-0000-e25e-986572040000 pid=1138 clone guuid=6c10557b-3d00-0000-e25e-986573040000 pid=1139 /usr/bin/curl net send-data guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=6c10557b-3d00-0000-e25e-986573040000 pid=1139 execve guuid=22b280d3-3d00-0000-e25e-986574040000 pid=1140 /usr/bin/chmod guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=22b280d3-3d00-0000-e25e-986574040000 pid=1140 execve guuid=be6355d4-3d00-0000-e25e-986575040000 pid=1141 /usr/bin/dash guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=be6355d4-3d00-0000-e25e-986575040000 pid=1141 clone guuid=79786dd4-3d00-0000-e25e-986576040000 pid=1142 /usr/bin/curl net send-data guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=79786dd4-3d00-0000-e25e-986576040000 pid=1142 execve guuid=4f79fe27-3e00-0000-e25e-986577040000 pid=1143 /usr/bin/chmod guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=4f79fe27-3e00-0000-e25e-986577040000 pid=1143 execve guuid=e5e9a528-3e00-0000-e25e-986578040000 pid=1144 /usr/bin/dash guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=e5e9a528-3e00-0000-e25e-986578040000 pid=1144 clone guuid=cbd0bf28-3e00-0000-e25e-986579040000 pid=1145 /usr/bin/curl net send-data guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=cbd0bf28-3e00-0000-e25e-986579040000 pid=1145 execve guuid=adfd7f80-3e00-0000-e25e-98657a040000 pid=1146 /usr/bin/chmod guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=adfd7f80-3e00-0000-e25e-98657a040000 pid=1146 execve guuid=f58e2f81-3e00-0000-e25e-98657b040000 pid=1147 /usr/bin/dash guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=f58e2f81-3e00-0000-e25e-98657b040000 pid=1147 clone guuid=8b295481-3e00-0000-e25e-98657c040000 pid=1148 /usr/bin/curl net send-data guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=8b295481-3e00-0000-e25e-98657c040000 pid=1148 execve guuid=4c5695c4-3e00-0000-e25e-98657d040000 pid=1149 /usr/bin/chmod guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=4c5695c4-3e00-0000-e25e-98657d040000 pid=1149 execve guuid=ed99dbc4-3e00-0000-e25e-98657e040000 pid=1150 /usr/bin/dash guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=ed99dbc4-3e00-0000-e25e-98657e040000 pid=1150 clone guuid=76b8e9c4-3e00-0000-e25e-98657f040000 pid=1151 /usr/bin/curl net send-data guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=76b8e9c4-3e00-0000-e25e-98657f040000 pid=1151 execve guuid=58ca8612-3f00-0000-e25e-986580040000 pid=1152 /usr/bin/chmod guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=58ca8612-3f00-0000-e25e-986580040000 pid=1152 execve guuid=cd71d712-3f00-0000-e25e-986581040000 pid=1153 /usr/bin/dash guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=cd71d712-3f00-0000-e25e-986581040000 pid=1153 clone guuid=aa32ed12-3f00-0000-e25e-986582040000 pid=1154 /usr/bin/rm guuid=40290b7d-3a00-0000-e25e-98655d040000 pid=1117->guuid=aa32ed12-3f00-0000-e25e-986582040000 pid=1154 execve 1620c7c4-e93d-516f-a8e7-a70e9d4dc287 14.225.20.10:80 guuid=758e3d7d-3a00-0000-e25e-98655e040000 pid=1118->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 79B guuid=0a2644d3-3b00-0000-e25e-986561040000 pid=1121->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 80B guuid=bf7e9205-3c00-0000-e25e-986564040000 pid=1124->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 80B guuid=77fe8556-3c00-0000-e25e-986567040000 pid=1127->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 80B guuid=9c7e25a5-3c00-0000-e25e-98656a040000 pid=1130->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 80B guuid=0757ebe5-3c00-0000-e25e-98656d040000 pid=1133->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 80B guuid=eee4a426-3d00-0000-e25e-986570040000 pid=1136->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 80B guuid=6c10557b-3d00-0000-e25e-986573040000 pid=1139->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 79B guuid=79786dd4-3d00-0000-e25e-986576040000 pid=1142->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 79B guuid=cbd0bf28-3e00-0000-e25e-986579040000 pid=1145->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 79B guuid=8b295481-3e00-0000-e25e-98657c040000 pid=1148->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 79B guuid=76b8e9c4-3e00-0000-e25e-98657f040000 pid=1151->1620c7c4-e93d-516f-a8e7-a70e9d4dc287 send: 82B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-11-02 18:14:32 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fcf7ad5c421a0ab7c58a0adc7230e5607ceb214084539e0ebb4208371a496561

(this sample)

  
Delivery method
Distributed via web download

Comments