MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 14acb457792a4857aa226eb7cc24bdbe8642adf896e3905a79d09e4dd9e9e511. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 14acb457792a4857aa226eb7cc24bdbe8642adf896e3905a79d09e4dd9e9e511
SHA3-384 hash: ba80b12ce7e2cb8ed2a534e54b00ae3543bc0f011bee36aaa71650bc27e16fda697132651d95d96b71d4d96468c606ed
SHA1 hash: 021ed91215b705aa2151e073ef78dbd6c2d6c04a
MD5 hash: 64dd490fe20b776addc29f3e7eeb7ea7
humanhash: blossom-robert-cup-sad
File name:c.sh
Download: download sample
Signature Mirai
File size:318 bytes
First seen:2026-07-27 00:39:56 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:VSLA3JP8khELVBQLA3DQ8ksWQELLcBQLA3cxh9yLcMBQLA3dxhbQxIMBUA:VSLAZPfhE3QLAzQ8ksxgwQLAyhgLcAQJ
TLSH T15FE026CB001AB3404B889E04FC5A883E78AB82D130329618B202F4F4C9CD109383AFDF
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://31.56.209.153/nz/nz.mips8c0da2c903eaf8aeeaef90db5ff708313ff807673da59e70edf2a2569d77b332 Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.mpsl24984afdb5b42c21eb382f517edd16567f3b5001a9de15d59d78b266b67b15ae Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.x86d1272c36897a7a76a35c07e47815c05a86b15138854438c104790e94d3e286b6 Miraielf mirai opendir ua-wget x86
http://31.56.209.153/nz/nz.x86_646ef41d3251793644f01d1a20990882ebf15abfb564a5e4001b4aca76242013dd Miraielf mirai opendir ua-wget x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader mirai
Status:
terminated
Behavior Graph:
%3 guuid=d09d6f31-1800-0000-73c9-2c71030b0000 pid=2819 /usr/bin/sudo guuid=8d9ea633-1800-0000-73c9-2c710c0b0000 pid=2828 /tmp/sample.bin guuid=d09d6f31-1800-0000-73c9-2c71030b0000 pid=2819->guuid=8d9ea633-1800-0000-73c9-2c710c0b0000 pid=2828 execve guuid=4df1fb35-1800-0000-73c9-2c71140b0000 pid=2836 /usr/bin/curl net guuid=8d9ea633-1800-0000-73c9-2c710c0b0000 pid=2828->guuid=4df1fb35-1800-0000-73c9-2c71140b0000 pid=2836 execve 866c226d-28aa-5624-b4fe-d4dba4601813 31.56.209.153:80 guuid=4df1fb35-1800-0000-73c9-2c71140b0000 pid=2836->866c226d-28aa-5624-b4fe-d4dba4601813 con
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2026-07-26 23:45:30 UTC
AV detection:
5 of 38 (13.16%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 14acb457792a4857aa226eb7cc24bdbe8642adf896e3905a79d09e4dd9e9e511

(this sample)

  
Delivery method
Distributed via web download

Comments