MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ff86b365045d30bad56d386f863d9aaf133f19b6653b9f5a16a3a41c323653ac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: ff86b365045d30bad56d386f863d9aaf133f19b6653b9f5a16a3a41c323653ac
SHA3-384 hash: 645196d796ec56c59710a3b4476463857488c8c38b3c9834e898eb0bbe3102419a7e68df30f03492e40b987be0dcde91
SHA1 hash: 237aecd0e986d5b645aa42c6f43679ba75810349
MD5 hash: 824615a653b714292cc441b4f3944646
humanhash: london-idaho-blue-winner
File name:w.sh
Download: download sample
Signature Mirai
File size:1'140 bytes
First seen:2025-12-21 02:23:22 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:TObLzjIXOzxNI5nXz1rKDgzUp5zd+4zfsp5zBCq5ztuklzcxxzyvYgzTMuHA:TeLzoOzAXzxygzk5zM4zfM5zIq5zQklA
TLSH T1F82178CE22509226C90CDF883F5D653CA558ABE4E5A08F289CDD487DAB9CA187167F09
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://143.20.185.78/bins/frost.arm8a6ddd16ceeec5a114f3e8319a225ce5f75cba9225d79855231de0b113472d1f Miraiarm elf geofenced mirai ua-wget USA
http://143.20.185.78/bins/frost.arm598e2d7934b42ebce6ecbdbf56fb8bb1c0335bab4dc8b644404b8d8b41a496543 Miraiarm elf geofenced mirai ua-wget USA
http://143.20.185.78/bins/frost.arm630d1e33d231e28919cf36bf997a44965ad39c7f8dad59484906fd1e8e2826ed4 Miraiarm elf geofenced mirai ua-wget USA
http://143.20.185.78/bins/frost.arm7c9a4f7b1626cfc17d700850cf30703632e96354ae80b1c49532acb3b464d19ec Miraiarm elf geofenced mirai ua-wget USA
http://143.20.185.78/bins/frost.m68kd265fd196d8c4113f2a52dd397cfd60d75c125983f944e4869adf929e78ce039 Miraielf geofenced m68k mirai ua-wget USA
http://143.20.185.78/bins/frost.mips37c634fbfbfce823c3e25f381578336d285b49208ad9bb155493ab2b3923d23a Miraielf geofenced mips mirai ua-wget USA
http://143.20.185.78/bins/frost.mpsl881c736b0ef28f73fd09a7ed06dc6b4935f0a9e95bcd8ad05ed9bd022e3a4a7f Miraielf mirai ua-wget
http://143.20.185.78/bins/frost.ppccf642a2210f02af51797257777169041c7d55d1558d030e36ce69d2321ff8601 Miraielf geofenced mirai PowerPC ua-wget USA
http://143.20.185.78/bins/frost.sh4ab4454e6726ed09e3045755d53d4168e30b74fb5c3f2fb82d472789b65059075 Miraielf geofenced mirai SuperH ua-wget USA
http://143.20.185.78/bins/frost.spc199380dcab2a4acf4d919972002884eff2d01a7e4f1b9228514bf187efef6ff6 Miraielf geofenced mirai sparc ua-wget USA
http://143.20.185.78/bins/frost.x86eec7f66f18d53e7a73987d079bbea53d3cb060b83388fd0d850cff7a5aac1f8e Miraielf geofenced mirai ua-wget USA x86
http://143.20.185.78/bins/frost.x86_642bdb5c71ddc686e9387663a1d114aa12f8c9f5466a47b3da0e9050c6694cd6c4 Miraielf geofenced mirai ua-wget USA x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
busybox mirai
Verdict:
Malicious
File Type:
ps1
First seen:
2025-12-21T00:18:00Z UTC
Last seen:
2025-12-21T15:06:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a4780d0d-1900-0000-57cd-8f7a5d140000 pid=5213 /usr/bin/sudo guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214 /tmp/sample.bin guuid=a4780d0d-1900-0000-57cd-8f7a5d140000 pid=5213->guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214 execve guuid=cf55560f-1900-0000-57cd-8f7a5f140000 pid=5215 /usr/bin/busybox net send-data write-file guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=cf55560f-1900-0000-57cd-8f7a5f140000 pid=5215 execve guuid=22d2311f-1900-0000-57cd-8f7a60140000 pid=5216 /usr/bin/chmod guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=22d2311f-1900-0000-57cd-8f7a60140000 pid=5216 execve guuid=49b6d81f-1900-0000-57cd-8f7a61140000 pid=5217 /usr/bin/dash guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=49b6d81f-1900-0000-57cd-8f7a61140000 pid=5217 clone guuid=079ca520-1900-0000-57cd-8f7a63140000 pid=5219 /usr/bin/busybox net send-data write-file guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=079ca520-1900-0000-57cd-8f7a63140000 pid=5219 execve guuid=582dc02d-1900-0000-57cd-8f7a64140000 pid=5220 /usr/bin/chmod guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=582dc02d-1900-0000-57cd-8f7a64140000 pid=5220 execve guuid=de62032e-1900-0000-57cd-8f7a65140000 pid=5221 /usr/bin/dash guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=de62032e-1900-0000-57cd-8f7a65140000 pid=5221 clone guuid=36e8bd2e-1900-0000-57cd-8f7a67140000 pid=5223 /usr/bin/busybox net send-data write-file guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=36e8bd2e-1900-0000-57cd-8f7a67140000 pid=5223 execve guuid=0fa53c3b-1900-0000-57cd-8f7a68140000 pid=5224 /usr/bin/chmod guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=0fa53c3b-1900-0000-57cd-8f7a68140000 pid=5224 execve guuid=b8ff9b3b-1900-0000-57cd-8f7a69140000 pid=5225 /usr/bin/dash guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=b8ff9b3b-1900-0000-57cd-8f7a69140000 pid=5225 clone guuid=8f428c3c-1900-0000-57cd-8f7a6b140000 pid=5227 /usr/bin/busybox net send-data write-file guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=8f428c3c-1900-0000-57cd-8f7a6b140000 pid=5227 execve guuid=4be19a4a-1900-0000-57cd-8f7a6c140000 pid=5228 /usr/bin/chmod guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=4be19a4a-1900-0000-57cd-8f7a6c140000 pid=5228 execve guuid=5aa5e24a-1900-0000-57cd-8f7a6d140000 pid=5229 /usr/bin/dash guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=5aa5e24a-1900-0000-57cd-8f7a6d140000 pid=5229 clone guuid=bfae724b-1900-0000-57cd-8f7a6f140000 pid=5231 /usr/bin/busybox net send-data write-file guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=bfae724b-1900-0000-57cd-8f7a6f140000 pid=5231 execve guuid=3531125c-1900-0000-57cd-8f7a70140000 pid=5232 /usr/bin/chmod guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=3531125c-1900-0000-57cd-8f7a70140000 pid=5232 execve guuid=31bf565c-1900-0000-57cd-8f7a71140000 pid=5233 /usr/bin/dash guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=31bf565c-1900-0000-57cd-8f7a71140000 pid=5233 clone guuid=43dfd45d-1900-0000-57cd-8f7a73140000 pid=5235 /usr/bin/busybox net send-data write-file guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=43dfd45d-1900-0000-57cd-8f7a73140000 pid=5235 execve guuid=0364626d-1900-0000-57cd-8f7a74140000 pid=5236 /usr/bin/chmod guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=0364626d-1900-0000-57cd-8f7a74140000 pid=5236 execve guuid=b106a76d-1900-0000-57cd-8f7a75140000 pid=5237 /usr/bin/dash guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=b106a76d-1900-0000-57cd-8f7a75140000 pid=5237 clone guuid=40b74e6e-1900-0000-57cd-8f7a77140000 pid=5239 /usr/bin/busybox net send-data guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=40b74e6e-1900-0000-57cd-8f7a77140000 pid=5239 execve guuid=62fa2e74-1900-0000-57cd-8f7a78140000 pid=5240 /usr/bin/chmod guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=62fa2e74-1900-0000-57cd-8f7a78140000 pid=5240 execve guuid=36ad7875-1900-0000-57cd-8f7a79140000 pid=5241 /usr/bin/dash guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=36ad7875-1900-0000-57cd-8f7a79140000 pid=5241 clone guuid=cae78775-1900-0000-57cd-8f7a7a140000 pid=5242 /usr/bin/busybox net send-data write-file guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=cae78775-1900-0000-57cd-8f7a7a140000 pid=5242 execve guuid=7a072a83-1900-0000-57cd-8f7a7b140000 pid=5243 /usr/bin/chmod guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=7a072a83-1900-0000-57cd-8f7a7b140000 pid=5243 execve guuid=a526db83-1900-0000-57cd-8f7a7c140000 pid=5244 /usr/bin/dash guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=a526db83-1900-0000-57cd-8f7a7c140000 pid=5244 clone guuid=7eb3bb86-1900-0000-57cd-8f7a7e140000 pid=5246 /usr/bin/busybox net send-data write-file guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=7eb3bb86-1900-0000-57cd-8f7a7e140000 pid=5246 execve guuid=2daddd93-1900-0000-57cd-8f7a7f140000 pid=5247 /usr/bin/chmod guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=2daddd93-1900-0000-57cd-8f7a7f140000 pid=5247 execve guuid=fb489f94-1900-0000-57cd-8f7a80140000 pid=5248 /usr/bin/dash guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=fb489f94-1900-0000-57cd-8f7a80140000 pid=5248 clone guuid=071b7b97-1900-0000-57cd-8f7a82140000 pid=5250 /usr/bin/busybox net send-data write-file guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=071b7b97-1900-0000-57cd-8f7a82140000 pid=5250 execve guuid=f34fe0a7-1900-0000-57cd-8f7a83140000 pid=5251 /usr/bin/chmod guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=f34fe0a7-1900-0000-57cd-8f7a83140000 pid=5251 execve guuid=908b2da8-1900-0000-57cd-8f7a84140000 pid=5252 /usr/bin/dash guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=908b2da8-1900-0000-57cd-8f7a84140000 pid=5252 clone guuid=ffc41fa9-1900-0000-57cd-8f7a86140000 pid=5254 /usr/bin/busybox net send-data write-file guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=ffc41fa9-1900-0000-57cd-8f7a86140000 pid=5254 execve guuid=cfb422b6-1900-0000-57cd-8f7a87140000 pid=5255 /usr/bin/chmod guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=cfb422b6-1900-0000-57cd-8f7a87140000 pid=5255 execve guuid=8f0874b6-1900-0000-57cd-8f7a88140000 pid=5256 /home/sandbox/frost.x86 net guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=8f0874b6-1900-0000-57cd-8f7a88140000 pid=5256 execve guuid=2e68162e-1a00-0000-57cd-8f7a94140000 pid=5268 /usr/bin/busybox net send-data write-file guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=2e68162e-1a00-0000-57cd-8f7a94140000 pid=5268 execve guuid=ef70d63d-1a00-0000-57cd-8f7a96140000 pid=5270 /usr/bin/chmod guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=ef70d63d-1a00-0000-57cd-8f7a96140000 pid=5270 execve guuid=72619b3f-1a00-0000-57cd-8f7a97140000 pid=5271 /home/sandbox/frost.x86_64 net guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=72619b3f-1a00-0000-57cd-8f7a97140000 pid=5271 execve guuid=4deb33b7-1a00-0000-57cd-8f7aa0140000 pid=5280 /usr/bin/rm guuid=a7a31e0f-1900-0000-57cd-8f7a5e140000 pid=5214->guuid=4deb33b7-1a00-0000-57cd-8f7aa0140000 pid=5280 execve 697679a7-cc0f-5478-83af-785833bd0767 143.20.185.78:80 guuid=cf55560f-1900-0000-57cd-8f7a5f140000 pid=5215->697679a7-cc0f-5478-83af-785833bd0767 send: 90B guuid=079ca520-1900-0000-57cd-8f7a63140000 pid=5219->697679a7-cc0f-5478-83af-785833bd0767 send: 91B guuid=36e8bd2e-1900-0000-57cd-8f7a67140000 pid=5223->697679a7-cc0f-5478-83af-785833bd0767 send: 91B guuid=8f428c3c-1900-0000-57cd-8f7a6b140000 pid=5227->697679a7-cc0f-5478-83af-785833bd0767 send: 91B guuid=bfae724b-1900-0000-57cd-8f7a6f140000 pid=5231->697679a7-cc0f-5478-83af-785833bd0767 send: 91B guuid=43dfd45d-1900-0000-57cd-8f7a73140000 pid=5235->697679a7-cc0f-5478-83af-785833bd0767 send: 91B guuid=40b74e6e-1900-0000-57cd-8f7a77140000 pid=5239->697679a7-cc0f-5478-83af-785833bd0767 send: 91B guuid=cae78775-1900-0000-57cd-8f7a7a140000 pid=5242->697679a7-cc0f-5478-83af-785833bd0767 send: 90B guuid=7eb3bb86-1900-0000-57cd-8f7a7e140000 pid=5246->697679a7-cc0f-5478-83af-785833bd0767 send: 90B guuid=071b7b97-1900-0000-57cd-8f7a82140000 pid=5250->697679a7-cc0f-5478-83af-785833bd0767 send: 90B guuid=ffc41fa9-1900-0000-57cd-8f7a86140000 pid=5254->697679a7-cc0f-5478-83af-785833bd0767 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=8f0874b6-1900-0000-57cd-8f7a88140000 pid=5256->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fe59a4b6-1900-0000-57cd-8f7a89140000 pid=5257 /home/sandbox/frost.x86 guuid=8f0874b6-1900-0000-57cd-8f7a88140000 pid=5256->guuid=fe59a4b6-1900-0000-57cd-8f7a89140000 pid=5257 clone guuid=b1e24ef2-1900-0000-57cd-8f7a91140000 pid=5265 /home/sandbox/frost.x86 guuid=8f0874b6-1900-0000-57cd-8f7a88140000 pid=5256->guuid=b1e24ef2-1900-0000-57cd-8f7a91140000 pid=5265 clone guuid=f8dffc2d-1a00-0000-57cd-8f7a92140000 pid=5266 /home/sandbox/frost.x86 guuid=8f0874b6-1900-0000-57cd-8f7a88140000 pid=5256->guuid=f8dffc2d-1a00-0000-57cd-8f7a92140000 pid=5266 clone guuid=25aa062e-1a00-0000-57cd-8f7a93140000 pid=5267 /home/sandbox/frost.x86 net zombie guuid=8f0874b6-1900-0000-57cd-8f7a88140000 pid=5256->guuid=25aa062e-1a00-0000-57cd-8f7a93140000 pid=5267 clone a7b3d5bf-498c-5749-9bad-9fa497b96e1d 143.20.185.78:1999 guuid=25aa062e-1a00-0000-57cd-8f7a93140000 pid=5267->a7b3d5bf-498c-5749-9bad-9fa497b96e1d con guuid=b144292e-1a00-0000-57cd-8f7a95140000 pid=5269 /home/sandbox/frost.x86 guuid=25aa062e-1a00-0000-57cd-8f7a93140000 pid=5267->guuid=b144292e-1a00-0000-57cd-8f7a95140000 pid=5269 clone guuid=f36ece69-1a00-0000-57cd-8f7a99140000 pid=5273 /home/sandbox/frost.x86 guuid=25aa062e-1a00-0000-57cd-8f7a93140000 pid=5267->guuid=f36ece69-1a00-0000-57cd-8f7a99140000 pid=5273 clone guuid=ce1979a5-1a00-0000-57cd-8f7a9b140000 pid=5275 /home/sandbox/frost.x86 guuid=25aa062e-1a00-0000-57cd-8f7a93140000 pid=5267->guuid=ce1979a5-1a00-0000-57cd-8f7a9b140000 pid=5275 clone guuid=2e68162e-1a00-0000-57cd-8f7a94140000 pid=5268->697679a7-cc0f-5478-83af-785833bd0767 send: 93B guuid=72619b3f-1a00-0000-57cd-8f7a97140000 pid=5271->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e5fdcc3f-1a00-0000-57cd-8f7a98140000 pid=5272 /home/sandbox/frost.x86_64 guuid=72619b3f-1a00-0000-57cd-8f7a97140000 pid=5271->guuid=e5fdcc3f-1a00-0000-57cd-8f7a98140000 pid=5272 clone guuid=24a5717b-1a00-0000-57cd-8f7a9a140000 pid=5274 /home/sandbox/frost.x86_64 guuid=72619b3f-1a00-0000-57cd-8f7a97140000 pid=5271->guuid=24a5717b-1a00-0000-57cd-8f7a9a140000 pid=5274 clone guuid=8a2c19b7-1a00-0000-57cd-8f7a9d140000 pid=5277 /home/sandbox/frost.x86_64 guuid=72619b3f-1a00-0000-57cd-8f7a97140000 pid=5271->guuid=8a2c19b7-1a00-0000-57cd-8f7a9d140000 pid=5277 clone guuid=fce31fb7-1a00-0000-57cd-8f7a9e140000 pid=5278 /home/sandbox/frost.x86_64 net zombie guuid=72619b3f-1a00-0000-57cd-8f7a97140000 pid=5271->guuid=fce31fb7-1a00-0000-57cd-8f7a9e140000 pid=5278 clone guuid=fce31fb7-1a00-0000-57cd-8f7a9e140000 pid=5278->a7b3d5bf-498c-5749-9bad-9fa497b96e1d con guuid=e1d92ab7-1a00-0000-57cd-8f7a9f140000 pid=5279 /home/sandbox/frost.x86_64 guuid=fce31fb7-1a00-0000-57cd-8f7a9e140000 pid=5278->guuid=e1d92ab7-1a00-0000-57cd-8f7a9f140000 pid=5279 clone guuid=10c0e6f2-1a00-0000-57cd-8f7aaf140000 pid=5295 /home/sandbox/frost.x86_64 guuid=fce31fb7-1a00-0000-57cd-8f7a9e140000 pid=5278->guuid=10c0e6f2-1a00-0000-57cd-8f7aaf140000 pid=5295 clone guuid=a1d4922e-1b00-0000-57cd-8f7ac1140000 pid=5313 /home/sandbox/frost.x86_64 guuid=fce31fb7-1a00-0000-57cd-8f7a9e140000 pid=5278->guuid=a1d4922e-1b00-0000-57cd-8f7ac1140000 pid=5313 clone
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-12-21 03:15:10 UTC
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ff86b365045d30bad56d386f863d9aaf133f19b6653b9f5a16a3a41c323653ac

(this sample)

  
Delivery method
Distributed via web download

Comments