MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe6dd0178e9bf05e61106c6d1129aaf15574d6b9178f2efcd75b416780247e9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: fe6dd0178e9bf05e61106c6d1129aaf15574d6b9178f2efcd75b416780247e9b
SHA3-384 hash: 19eddc5d4b11fa5f0e351f25381a4f7ed0b6a110c4cd333701c58c24c636c5abcf60ab1d9f78a0718cc5925ac986e4e2
SHA1 hash: 3bf5ec64f9fbf9996ada78fe67af2f8fe452ec47
MD5 hash: 86602f1f4d606d4aa4aac3b9cc8a7ce5
humanhash: violet-beer-alpha-venus
File name:w.sh
Download: download sample
Signature Mirai
File size:1'278 bytes
First seen:2025-07-02 03:27:31 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:7TICI4NI6mINKVIWN+7I52IOcIZIulIZIY3gISHR:3xJm+WrN+7/dcQxl0ZQTx
TLSH T153219DFF03918027C45DCFD130698524A10886DB789C4BB82BCE8EF66E84ED8EC42E49
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.87.245/00101010101001/morte.arm0e1c862fb7b3927bbf3f71b5c83949151be2dfedd584eb482c173ce2e851dd3f Miraimirai opendir
http://196.251.87.245/00101010101001/morte.arm5a67885abc3a05d82c9083e3df77c227e91f38aa242bc9988caf35b3a447ca596 Miraimirai opendir
http://196.251.87.245/00101010101001/morte.arm661dfc5c73839259cb55254701e29c43307b89acaecf4c14b51be5d209ce80d5b Miraimirai opendir
http://196.251.87.245/00101010101001/morte.arm795d5407a92ac4b36ed3d0f10b3fb494fed6ae21491b9f5fce152b85b78fb2e12 Miraimirai opendir
http://196.251.87.245/00101010101001/morte.m68k7c5e6035418ce9f52bdb00eaff5e23d3d7a41f7a75554249c6cf6e44ce34ae3f Miraimirai opendir
http://196.251.87.245/00101010101001/morte.mipsa81cd95a99e545fa8df1f913d95d4609dcae0c7933e1b5012a728b9ea9f4e46c Miraimirai opendir
http://196.251.87.245/00101010101001/morte.mpslf4d2edf5cb22fd836842fb0c277395557f3a1329cc90c280cc12839c3e6fd72c Miraimirai opendir
http://196.251.87.245/00101010101001/morte.ppc437732d5bde3a06c54a001342f0ad3735088bc10d3aaeb69d038520c3a00a9db Miraimirai opendir
http://196.251.87.245/00101010101001/morte.sh4e0fadfca7d4f0704722720c739c817d05fa639fdbb6edbd961d0083f73342c80 Miraimirai opendir
http://196.251.87.245/00101010101001/morte.spcb98844c282ecfff203dabee396106d9726de54c4821bd35208239f7621d774b9 Miraimirai opendir
http://196.251.87.245/00101010101001/morte.x864fef063a9f02ba436aa8231ae6e68833cc7007d4acd4c911b0742fc6edb7f3e0 Miraimirai opendir
http://196.251.87.245/00101010101001/morte.x86_645f40e73a84e77e83a454da3ee487429836e3bdec4ceffc19d0d26c4901a911dd Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
14
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
downloader ransomware phishing trojan
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
obfuscated
Status:
terminated
Behavior Graph:
%3 guuid=cf663d7b-1900-0000-b4a7-abbb65140000 pid=5221 /usr/bin/sudo guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222 /tmp/sample.bin guuid=cf663d7b-1900-0000-b4a7-abbb65140000 pid=5221->guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222 execve guuid=205a0881-1900-0000-b4a7-abbb68140000 pid=5224 /usr/bin/busybox net send-data write-file guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=205a0881-1900-0000-b4a7-abbb68140000 pid=5224 execve guuid=b01e2d83-1900-0000-b4a7-abbb69140000 pid=5225 /usr/bin/chmod guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=b01e2d83-1900-0000-b4a7-abbb69140000 pid=5225 execve guuid=326c8483-1900-0000-b4a7-abbb6a140000 pid=5226 /usr/bin/dash guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=326c8483-1900-0000-b4a7-abbb6a140000 pid=5226 clone guuid=caf25084-1900-0000-b4a7-abbb6c140000 pid=5228 /usr/bin/busybox net send-data write-file guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=caf25084-1900-0000-b4a7-abbb6c140000 pid=5228 execve guuid=0450be86-1900-0000-b4a7-abbb6d140000 pid=5229 /usr/bin/chmod guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=0450be86-1900-0000-b4a7-abbb6d140000 pid=5229 execve guuid=d0e61c87-1900-0000-b4a7-abbb6e140000 pid=5230 /usr/bin/dash guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=d0e61c87-1900-0000-b4a7-abbb6e140000 pid=5230 clone guuid=25d1d387-1900-0000-b4a7-abbb70140000 pid=5232 /usr/bin/busybox net send-data write-file guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=25d1d387-1900-0000-b4a7-abbb70140000 pid=5232 execve guuid=a6e3118a-1900-0000-b4a7-abbb71140000 pid=5233 /usr/bin/chmod guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=a6e3118a-1900-0000-b4a7-abbb71140000 pid=5233 execve guuid=dd90bf8a-1900-0000-b4a7-abbb72140000 pid=5234 /usr/bin/dash guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=dd90bf8a-1900-0000-b4a7-abbb72140000 pid=5234 clone guuid=2216978c-1900-0000-b4a7-abbb74140000 pid=5236 /usr/bin/busybox net send-data write-file guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=2216978c-1900-0000-b4a7-abbb74140000 pid=5236 execve guuid=60b3db8f-1900-0000-b4a7-abbb75140000 pid=5237 /usr/bin/chmod guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=60b3db8f-1900-0000-b4a7-abbb75140000 pid=5237 execve guuid=9b982990-1900-0000-b4a7-abbb76140000 pid=5238 /usr/bin/dash guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=9b982990-1900-0000-b4a7-abbb76140000 pid=5238 clone guuid=94a4e091-1900-0000-b4a7-abbb78140000 pid=5240 /usr/bin/busybox net send-data write-file guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=94a4e091-1900-0000-b4a7-abbb78140000 pid=5240 execve guuid=9ca00f95-1900-0000-b4a7-abbb79140000 pid=5241 /usr/bin/chmod guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=9ca00f95-1900-0000-b4a7-abbb79140000 pid=5241 execve guuid=50715095-1900-0000-b4a7-abbb7a140000 pid=5242 /usr/bin/dash guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=50715095-1900-0000-b4a7-abbb7a140000 pid=5242 clone guuid=3b7bbc96-1900-0000-b4a7-abbb7c140000 pid=5244 /usr/bin/busybox net send-data write-file guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=3b7bbc96-1900-0000-b4a7-abbb7c140000 pid=5244 execve guuid=4b0b3299-1900-0000-b4a7-abbb7d140000 pid=5245 /usr/bin/chmod guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=4b0b3299-1900-0000-b4a7-abbb7d140000 pid=5245 execve guuid=1b007699-1900-0000-b4a7-abbb7e140000 pid=5246 /usr/bin/dash guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=1b007699-1900-0000-b4a7-abbb7e140000 pid=5246 clone guuid=37bc139b-1900-0000-b4a7-abbb80140000 pid=5248 /usr/bin/busybox net send-data write-file guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=37bc139b-1900-0000-b4a7-abbb80140000 pid=5248 execve guuid=7e0c309d-1900-0000-b4a7-abbb81140000 pid=5249 /usr/bin/chmod guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=7e0c309d-1900-0000-b4a7-abbb81140000 pid=5249 execve guuid=9633d29d-1900-0000-b4a7-abbb82140000 pid=5250 /usr/bin/dash guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=9633d29d-1900-0000-b4a7-abbb82140000 pid=5250 clone guuid=4187339f-1900-0000-b4a7-abbb84140000 pid=5252 /usr/bin/busybox net send-data write-file guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=4187339f-1900-0000-b4a7-abbb84140000 pid=5252 execve guuid=30ce93a1-1900-0000-b4a7-abbb85140000 pid=5253 /usr/bin/chmod guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=30ce93a1-1900-0000-b4a7-abbb85140000 pid=5253 execve guuid=208e3aa2-1900-0000-b4a7-abbb86140000 pid=5254 /usr/bin/dash guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=208e3aa2-1900-0000-b4a7-abbb86140000 pid=5254 clone guuid=adff56a2-1900-0000-b4a7-abbb87140000 pid=5255 /usr/bin/busybox net send-data write-file guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=adff56a2-1900-0000-b4a7-abbb87140000 pid=5255 execve guuid=08258ba5-1900-0000-b4a7-abbb88140000 pid=5256 /usr/bin/chmod guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=08258ba5-1900-0000-b4a7-abbb88140000 pid=5256 execve guuid=b36024a6-1900-0000-b4a7-abbb89140000 pid=5257 /usr/bin/dash guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=b36024a6-1900-0000-b4a7-abbb89140000 pid=5257 clone guuid=1e13a3a7-1900-0000-b4a7-abbb8b140000 pid=5259 /usr/bin/busybox net send-data write-file guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=1e13a3a7-1900-0000-b4a7-abbb8b140000 pid=5259 execve guuid=a3c2f0aa-1900-0000-b4a7-abbb8c140000 pid=5260 /usr/bin/chmod guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=a3c2f0aa-1900-0000-b4a7-abbb8c140000 pid=5260 execve guuid=88d78cab-1900-0000-b4a7-abbb8d140000 pid=5261 /usr/bin/dash guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=88d78cab-1900-0000-b4a7-abbb8d140000 pid=5261 clone guuid=8d8655ac-1900-0000-b4a7-abbb8f140000 pid=5263 /usr/bin/busybox net send-data write-file guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=8d8655ac-1900-0000-b4a7-abbb8f140000 pid=5263 execve guuid=870c5eae-1900-0000-b4a7-abbb90140000 pid=5264 /usr/bin/chmod guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=870c5eae-1900-0000-b4a7-abbb90140000 pid=5264 execve guuid=e408a2ae-1900-0000-b4a7-abbb91140000 pid=5265 /home/sandbox/morte.x86 net guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=e408a2ae-1900-0000-b4a7-abbb91140000 pid=5265 execve guuid=4af8ecaf-1900-0000-b4a7-abbb94140000 pid=5268 /usr/bin/busybox net send-data write-file guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=4af8ecaf-1900-0000-b4a7-abbb94140000 pid=5268 execve guuid=49e180b2-1900-0000-b4a7-abbb96140000 pid=5270 /usr/bin/chmod guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=49e180b2-1900-0000-b4a7-abbb96140000 pid=5270 execve guuid=11a3dab2-1900-0000-b4a7-abbb97140000 pid=5271 /home/sandbox/morte.x86_64 mprotect-exec net guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=11a3dab2-1900-0000-b4a7-abbb97140000 pid=5271 execve guuid=d61fbeb8-1900-0000-b4a7-abbb98140000 pid=5272 /usr/bin/rm guuid=f368807e-1900-0000-b4a7-abbb66140000 pid=5222->guuid=d61fbeb8-1900-0000-b4a7-abbb98140000 pid=5272 execve d047be9e-0261-5db6-bcf1-f98b662bc156 196.251.87.245:80 guuid=205a0881-1900-0000-b4a7-abbb68140000 pid=5224->d047be9e-0261-5db6-bcf1-f98b662bc156 send: 101B guuid=caf25084-1900-0000-b4a7-abbb6c140000 pid=5228->d047be9e-0261-5db6-bcf1-f98b662bc156 send: 102B guuid=25d1d387-1900-0000-b4a7-abbb70140000 pid=5232->d047be9e-0261-5db6-bcf1-f98b662bc156 send: 102B guuid=2216978c-1900-0000-b4a7-abbb74140000 pid=5236->d047be9e-0261-5db6-bcf1-f98b662bc156 send: 102B guuid=94a4e091-1900-0000-b4a7-abbb78140000 pid=5240->d047be9e-0261-5db6-bcf1-f98b662bc156 send: 102B guuid=3b7bbc96-1900-0000-b4a7-abbb7c140000 pid=5244->d047be9e-0261-5db6-bcf1-f98b662bc156 send: 102B guuid=37bc139b-1900-0000-b4a7-abbb80140000 pid=5248->d047be9e-0261-5db6-bcf1-f98b662bc156 send: 102B guuid=4187339f-1900-0000-b4a7-abbb84140000 pid=5252->d047be9e-0261-5db6-bcf1-f98b662bc156 send: 101B guuid=adff56a2-1900-0000-b4a7-abbb87140000 pid=5255->d047be9e-0261-5db6-bcf1-f98b662bc156 send: 101B guuid=1e13a3a7-1900-0000-b4a7-abbb8b140000 pid=5259->d047be9e-0261-5db6-bcf1-f98b662bc156 send: 101B guuid=8d8655ac-1900-0000-b4a7-abbb8f140000 pid=5263->d047be9e-0261-5db6-bcf1-f98b662bc156 send: 101B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e408a2ae-1900-0000-b4a7-abbb91140000 pid=5265->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2fbad6af-1900-0000-b4a7-abbb92140000 pid=5266 /home/sandbox/morte.x86 guuid=e408a2ae-1900-0000-b4a7-abbb91140000 pid=5265->guuid=2fbad6af-1900-0000-b4a7-abbb92140000 pid=5266 clone guuid=a2a7dfaf-1900-0000-b4a7-abbb93140000 pid=5267 /home/sandbox/morte.x86 delete-file dns net send-data zombie guuid=e408a2ae-1900-0000-b4a7-abbb91140000 pid=5265->guuid=a2a7dfaf-1900-0000-b4a7-abbb93140000 pid=5267 clone guuid=a2a7dfaf-1900-0000-b4a7-abbb93140000 pid=5267->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 37B f2314dec-3f4f-5fb5-9b72-f7ca6bdedfc6 vip.jbvipnetwork.cc:12121 guuid=a2a7dfaf-1900-0000-b4a7-abbb93140000 pid=5267->f2314dec-3f4f-5fb5-9b72-f7ca6bdedfc6 con guuid=65d4f9af-1900-0000-b4a7-abbb95140000 pid=5269 /home/sandbox/morte.x86 guuid=a2a7dfaf-1900-0000-b4a7-abbb93140000 pid=5267->guuid=65d4f9af-1900-0000-b4a7-abbb95140000 pid=5269 clone guuid=4af8ecaf-1900-0000-b4a7-abbb94140000 pid=5268->d047be9e-0261-5db6-bcf1-f98b662bc156 send: 104B guuid=11a3dab2-1900-0000-b4a7-abbb97140000 pid=5271->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=11a3dab2-1900-0000-b4a7-abbb97140000 pid=5271->f77ebf5e-2af7-5b09-86f4-388588a8b445 con
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2025-07-02 03:28:22 UTC
File Type:
Text (Shell)
AV detection:
15 of 36 (41.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fe6dd0178e9bf05e61106c6d1129aaf15574d6b9178f2efcd75b416780247e9b

(this sample)

Comments