MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 074e8f95d246535508da84a0c6d8ec13674ef4c5334b2e051f10f8edbd5c7ac9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 074e8f95d246535508da84a0c6d8ec13674ef4c5334b2e051f10f8edbd5c7ac9
SHA3-384 hash: 361e1f559e5e7a3ec99bcf08be2f20b0b7186670e824fee7afce27c2b0e6f3fdc9b2caeb6633ceea5c7daddfd8765a73
SHA1 hash: d844febc8e67b15fedd59ec09d7f1e0303ff38ac
MD5 hash: bd4255eb00ec36e690b784f7b8012d02
humanhash: september-blossom-football-fix
File name:run.sh
Download: download sample
Signature Mirai
File size:4'068 bytes
First seen:2025-10-28 12:46:27 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:FS2JMZnbiBxQuZ44cvyZpbwzFhM3OT/TbTKTNTb:FS2JMZnbiBxQuZhpbws
TLSH T1CB814F8E0644D731D70D8A1EF7F2B1B4910FA283E6EBCF46B954186C0EC5D4CB686E52
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnaarch64xnxnn/an/aelf ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxni386xnxnn/an/aelf ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnloongarch64xnxn8baceab3c5fc2c2f0a922f885af62a5d04d55c2417881308252f80f89e7c41ad Miraielf mirai ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnm68kxnxn0d5f90b844bf0664e51af4ab6849902b124a9b358540dc475e12be709ea45e6d Miraielf mirai ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnmicroblazexnxn4ee68a0324780ca8d6d5c84508e888f5e5275622239a40126da8f326bf907ceb Miraielf mirai ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnmipsxnxnn/an/aelf ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnor1kxnxn5e5684195b4195fb3213ded585f3d739936d45b6ea088aa774c7fbdad867b923 Miraielf mirai ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnpowerpcxnxnn/an/aelf ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnpowerpc64xnxnn/an/aelf ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnriscv32xnxnaa6ddb30d15ce6c0a83afbe6dd9a560e1e5d9fd48bf3a86cac2e7b89be4d4115 Miraielf mirai ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnriscv64xnxnd078a3e7322a77f9a9eb36622e3e19ee75fa6725c6309c2d486460085687cd42 Miraielf mirai ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxns390xnxnn/an/aelf ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnsh2xnxn2a344233a93dd8f98b6797e4aa5ed6f21d2360972d150bd268537a3881dc74f0 Miraielf mirai ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnsh4xnxn57a118c474cdb8c7fefb7995a14db626ad4ef30aabbe0180422c6761e8e355fa Miraielf mirai ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnsparcxnxnn/an/aelf ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnsparc64xnxnn/an/aelf ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnx86_64xnxnn/an/aelf ua-wget
http://196.251.115.216/bins/xnxnxnxnxnxnxnxnxtensaxnxnn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-10-28T10:51:00Z UTC
Last seen:
2025-10-28T11:10:00Z UTC
Hits:
~10
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-10-28 12:47:46 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 074e8f95d246535508da84a0c6d8ec13674ef4c5334b2e051f10f8edbd5c7ac9

(this sample)

  
Delivery method
Distributed via web download

Comments