MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2b68a68a3a138c1149b1483e074fd1c84ca67a59652f83a2bb38dc2a2f7c2a80. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 2b68a68a3a138c1149b1483e074fd1c84ca67a59652f83a2bb38dc2a2f7c2a80
SHA3-384 hash: a1757d400dc44f18d53d701894dd422b913c581dd6512d0c32fc26adec4d94571e8b20a9c82be7382cd2708c95d4f6b0
SHA1 hash: 5674a6179c3ed46c3794368335ee2465d976d51f
MD5 hash: 005ce539d40aa0a3c2caea1face9e898
humanhash: tennessee-three-ohio-mirror
File name:weed
Download: download sample
Signature Mirai
File size:997 bytes
First seen:2025-12-23 01:44:43 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:+7NdJOa7AtJOa7rJOa7oJOa7vRDJOa7wJOa7goJOa7boJOa7AJOa73dJOa7njJOf:+wa1a8a/abqavaGaja3aLqakf
TLSH T1B211219E1301DD90888DD47A77D1820DB4818FDD297B07656D5251B954E06CE737891A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/zerarm8c24a9977fa29dba230772a68f2df0d26fd6ff11d9470c3e5afdf4784e0139ba Miraielf mirai ua-wget
http://130.12.180.64/zerarm57bd2924ecc2c70b802880e00c3be4ed81f888870e2e5ac8dcf593da9d0745568 Miraielf mirai ua-wget
http://130.12.180.64/zerarm6abb35faea8f0cee05277d697a3ee43dcbf2bb435b7dd467a476b4d51f85bc020 Miraielf mirai ua-wget
http://130.12.180.64/zerarm7fb9f9fe26d5e965e4cf9a1cf5812ba3ce88c99e8e54669ea0cd8bb0f806fa075 Miraielf mirai ua-wget
http://130.12.180.64/zerm68k894e31da072638bcf6a6d399a4efd0c62abfcf1007746884838099d0274b34ab Miraielf mirai ua-wget
http://130.12.180.64/zermips2f5a2f3a9853061e89102a0d41e6027c3e9cc94d7a2d4ee91663e17768cee255 Miraielf mirai ua-wget
http://130.12.180.64/zermpsl45aea10db623fdcd7122375d517f2c54ab3540411345e70952a091ec8557ee74 Miraielf mirai ua-wget
http://130.12.180.64/zerppceeeebb5aeb2e8e0f5ac9d5baed9ab50540357fab439fb30c9dbf5f2a3e67cedc Miraielf mirai ua-wget
http://130.12.180.64/zersh4fb961a1fa4a39b037ea4ea268bb554c17286531e783b784dd16472c9b515ada1 Miraielf mirai ua-wget
http://130.12.180.64/zerspcccccf45350809f344040fbaeb04706f880f1da0bd54e8847d5a6bc0c5c96f69c Miraielf mirai ua-wget
http://130.12.180.64/zerx86c5646c3369ed0fb9b1b17eaef47426005614ade772737674bfed0733dd0d73bb Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-22T23:23:00Z UTC
Last seen:
2025-12-22T23:49:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=fcdffb53-1a00-0000-a25d-4e4acd090000 pid=2509 /usr/bin/sudo guuid=5a06c256-1a00-0000-a25d-4e4ad2090000 pid=2514 /tmp/sample.bin guuid=fcdffb53-1a00-0000-a25d-4e4acd090000 pid=2509->guuid=5a06c256-1a00-0000-a25d-4e4ad2090000 pid=2514 execve
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-23 02:10:15 UTC
File Type:
Text (Shell)
AV detection:
17 of 36 (47.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2b68a68a3a138c1149b1483e074fd1c84ca67a59652f83a2bb38dc2a2f7c2a80

(this sample)

  
Delivery method
Distributed via web download

Comments