MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2272cf84ed710394a08d70054cf2f54e96fd65af399e5addfcfdffe284266a56. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2272cf84ed710394a08d70054cf2f54e96fd65af399e5addfcfdffe284266a56
SHA3-384 hash: b0295ba84e99008e4189f7c7442d34a2d1c4642525d122513a45a3afe3108855bf081ce04a63eb2fc50c1936b79427dd
SHA1 hash: 939e7866ea439680b944b28f362712f042ca6e69
MD5 hash: c1bd9b2e7d6c48633c6dc7d211f768c9
humanhash: bacon-high-maine-mango
File name:lterouter
Download: download sample
Signature Mirai
File size:162 bytes
First seen:2026-08-05 02:19:44 UTC
Last seen:2026-08-05 06:38:33 UTC
File type: sh
MIME type:text/plain
ssdeep 3:O22exARiZejeIVA3FOdJ2GL9rSaZejeIMuBFS/TWUKT6VVI9LJdvvvF:O25LO92GLNSkOMsTT6IZJn
TLSH T141C08CC706117B2080E96C2C7296802E828B862035E00F4EF8BA0612AE8A968F830B01
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://144.172.67.25/n2/mipsab1b6934bc586d442ec14067cb8075b94f66e0981c41fb308758ba7949eaa437 Miraielf mips mirai ua-wget

Intelligence


File Origin
# of uploads :
106
# of downloads :
10
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-08-04T21:00:00Z UTC
Last seen:
2026-08-05T12:59:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=e48310c2-1b00-0000-e2c6-60cb150c0000 pid=3093 /usr/bin/sudo guuid=451dc0c6-1b00-0000-e2c6-60cb160c0000 pid=3094 /tmp/sample.bin guuid=e48310c2-1b00-0000-e2c6-60cb150c0000 pid=3093->guuid=451dc0c6-1b00-0000-e2c6-60cb160c0000 pid=3094 execve guuid=637f61c7-1b00-0000-e2c6-60cb170c0000 pid=3095 /usr/bin/wget net send-data write-file guuid=451dc0c6-1b00-0000-e2c6-60cb160c0000 pid=3094->guuid=637f61c7-1b00-0000-e2c6-60cb170c0000 pid=3095 execve guuid=e2fe36ef-1b00-0000-e2c6-60cb3a0c0000 pid=3130 /usr/bin/chmod guuid=451dc0c6-1b00-0000-e2c6-60cb160c0000 pid=3094->guuid=e2fe36ef-1b00-0000-e2c6-60cb3a0c0000 pid=3130 execve guuid=0cf01ef0-1b00-0000-e2c6-60cb3c0c0000 pid=3132 /usr/bin/dash guuid=451dc0c6-1b00-0000-e2c6-60cb160c0000 pid=3094->guuid=0cf01ef0-1b00-0000-e2c6-60cb3c0c0000 pid=3132 clone guuid=ee274af1-1b00-0000-e2c6-60cb400c0000 pid=3136 /usr/bin/wget net send-data write-file guuid=451dc0c6-1b00-0000-e2c6-60cb160c0000 pid=3094->guuid=ee274af1-1b00-0000-e2c6-60cb400c0000 pid=3136 execve guuid=8b1afa10-1c00-0000-e2c6-60cb6c0c0000 pid=3180 /usr/bin/chmod guuid=451dc0c6-1b00-0000-e2c6-60cb160c0000 pid=3094->guuid=8b1afa10-1c00-0000-e2c6-60cb6c0c0000 pid=3180 execve guuid=18493711-1c00-0000-e2c6-60cb6d0c0000 pid=3181 /usr/bin/dash guuid=451dc0c6-1b00-0000-e2c6-60cb160c0000 pid=3094->guuid=18493711-1c00-0000-e2c6-60cb6d0c0000 pid=3181 clone guuid=cf4f4512-1c00-0000-e2c6-60cb6f0c0000 pid=3183 /usr/bin/rm delete-file guuid=451dc0c6-1b00-0000-e2c6-60cb160c0000 pid=3094->guuid=cf4f4512-1c00-0000-e2c6-60cb6f0c0000 pid=3183 execve 95359159-00a7-5bfe-b549-4435d3537c4d 144.172.67.25:80 guuid=637f61c7-1b00-0000-e2c6-60cb170c0000 pid=3095->95359159-00a7-5bfe-b549-4435d3537c4d send: 135B guuid=ee274af1-1b00-0000-e2c6-60cb400c0000 pid=3136->95359159-00a7-5bfe-b549-4435d3537c4d send: 135B
Gathering data
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-08-05 03:33:37 UTC
AV detection:
6 of 38 (15.79%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2272cf84ed710394a08d70054cf2f54e96fd65af399e5addfcfdffe284266a56

(this sample)

  
Delivery method
Distributed via web download

Comments