MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1a59dbd778699f8e4a4fe8ee82fe49cff516d76a9f59e9a212e9381cc2c46c29. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 1a59dbd778699f8e4a4fe8ee82fe49cff516d76a9f59e9a212e9381cc2c46c29
SHA3-384 hash: 76abb75ddfb6ab93108df51df249eba3984841c73ebbc1871722ca9e553e445e9ee0e2ab355fdf827fde7519dcda9b4d
SHA1 hash: 7bda5e9c094bb3343ff06c15d57301d327e71791
MD5 hash: 5109fce9d4461bead35cb50219e4aacd
humanhash: freddie-wolfram-stairway-nineteen
File name:o
Download: download sample
Signature Mirai
File size:116 bytes
First seen:2026-07-17 23:09:27 UTC
Last seen:2026-07-18 17:41:05 UTC
File type: sh
MIME type:text/plain
ssdeep 3:L3X442PSATNUC1+gVCx8e8BzSOV+LPFzIFCP3:L5AB4gm8NmLPFEM
TLSH T148B092AE78247D41C428384623A1208D74428684B82A1F9A98580235D9F665CB814ADF
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.249.125.141/gmipsfd0ff75925ea15760d72c1a9ffbcc0e751abebb2f4cd49f0bd11274a04706217 Miraicensys elf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
442
# of downloads :
16
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-07-17T21:07:00Z UTC
Last seen:
2026-07-18T17:07:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=8975e25d-1b00-0000-f997-1315b70a0000 pid=2743 /usr/bin/sudo guuid=52a68160-1b00-0000-f997-1315bd0a0000 pid=2749 /tmp/sample.bin guuid=8975e25d-1b00-0000-f997-1315b70a0000 pid=2743->guuid=52a68160-1b00-0000-f997-1315bd0a0000 pid=2749 execve guuid=2592cd60-1b00-0000-f997-1315bf0a0000 pid=2751 /usr/bin/rm guuid=52a68160-1b00-0000-f997-1315bd0a0000 pid=2749->guuid=2592cd60-1b00-0000-f997-1315bf0a0000 pid=2751 execve guuid=b2c10661-1b00-0000-f997-1315c10a0000 pid=2753 /usr/bin/dash guuid=52a68160-1b00-0000-f997-1315bd0a0000 pid=2749->guuid=b2c10661-1b00-0000-f997-1315c10a0000 pid=2753 clone guuid=a5e91361-1b00-0000-f997-1315c20a0000 pid=2754 /usr/bin/chmod guuid=52a68160-1b00-0000-f997-1315bd0a0000 pid=2749->guuid=a5e91361-1b00-0000-f997-1315c20a0000 pid=2754 execve guuid=e4de4961-1b00-0000-f997-1315c30a0000 pid=2755 /usr/bin/dash guuid=52a68160-1b00-0000-f997-1315bd0a0000 pid=2749->guuid=e4de4961-1b00-0000-f997-1315c30a0000 pid=2755 clone guuid=f4f75761-1b00-0000-f997-1315c40a0000 pid=2756 /usr/bin/rm guuid=52a68160-1b00-0000-f997-1315bd0a0000 pid=2749->guuid=f4f75761-1b00-0000-f997-1315c40a0000 pid=2756 execve
Gathering data
Threat name:
Script-BAT.Dropper.Tsunami
Status:
Malicious
First seen:
2026-07-18 02:38:39 UTC
AV detection:
6 of 38 (15.79%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1a59dbd778699f8e4a4fe8ee82fe49cff516d76a9f59e9a212e9381cc2c46c29

(this sample)

  
Delivery method
Distributed via web download

Comments