MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 14acb457792a4857aa226eb7cc24bdbe8642adf896e3905a79d09e4dd9e9e511. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 14acb457792a4857aa226eb7cc24bdbe8642adf896e3905a79d09e4dd9e9e511
SHA3-384 hash: ba80b12ce7e2cb8ed2a534e54b00ae3543bc0f011bee36aaa71650bc27e16fda697132651d95d96b71d4d96468c606ed
SHA1 hash: 021ed91215b705aa2151e073ef78dbd6c2d6c04a
MD5 hash: 64dd490fe20b776addc29f3e7eeb7ea7
humanhash: blossom-robert-cup-sad
File name:c.sh
Download: download sample
Signature Mirai
File size:318 bytes
First seen:2026-07-27 00:39:56 UTC
Last seen:2026-07-29 01:10:56 UTC
File type: sh
MIME type:text/plain
ssdeep 6:VSLA3JP8khELVBQLA3DQ8ksWQELLcBQLA3cxh9yLcMBQLA3dxhbQxIMBUA:VSLAZPfhE3QLAzQ8ksxgwQLAyhgLcAQJ
TLSH T15FE026CB001AB3404B889E04FC5A883E78AB82D130329618B202F4F4C9CD109383AFDF
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://31.56.209.153/nz/nz.mips7b651e4f66c0bcc2befa5a981caaf7ea1180b8bb530bb1e384ba42e70f097db1 Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.mpslf4af27bb0f0bcc102b0596a909c738fc5aa0956fed74010c0e314cac01d86323 Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.x8686a98b0a9d3b4cba259ace302a120d0ed77561198f3e6a17b855f4ebd4bbbb50 Miraielf mirai opendir ua-wget x86
http://31.56.209.153/nz/nz.x86_645413190d593ced48661818bccc75ad1b7a582ec879e9d5980be9b0b0bc663379 Miraielf mirai opendir ua-wget x86

Intelligence


File Origin
# of uploads :
3
# of downloads :
78
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader mirai
Verdict:
Malicious
File Type:
ps1
First seen:
2026-07-26T21:04:00Z UTC
Last seen:
2026-07-27T18:59:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=d09d6f31-1800-0000-73c9-2c71030b0000 pid=2819 /usr/bin/sudo guuid=8d9ea633-1800-0000-73c9-2c710c0b0000 pid=2828 /tmp/sample.bin guuid=d09d6f31-1800-0000-73c9-2c71030b0000 pid=2819->guuid=8d9ea633-1800-0000-73c9-2c710c0b0000 pid=2828 execve guuid=4df1fb35-1800-0000-73c9-2c71140b0000 pid=2836 /usr/bin/curl net guuid=8d9ea633-1800-0000-73c9-2c710c0b0000 pid=2828->guuid=4df1fb35-1800-0000-73c9-2c71140b0000 pid=2836 execve 866c226d-28aa-5624-b4fe-d4dba4601813 31.56.209.153:80 guuid=4df1fb35-1800-0000-73c9-2c71140b0000 pid=2836->866c226d-28aa-5624-b4fe-d4dba4601813 con
Threat name:
Document-HTML.Browser.Heuristic
Status:
Malicious
First seen:
2026-07-26 23:45:30 UTC
File Type:
Text (Shell)
AV detection:
5 of 36 (13.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 14acb457792a4857aa226eb7cc24bdbe8642adf896e3905a79d09e4dd9e9e511

(this sample)

Comments