🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 32995ee3a0858c8c7f5594aa1bb4d38de616d66d60b920c5ffefe9bb41fccf38. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 32995ee3a0858c8c7f5594aa1bb4d38de616d66d60b920c5ffefe9bb41fccf38
SHA3-384 hash: b325957bf723b6dc699be132eb225ec42f6243da75550ef463c5339ba81cd510c960d47d5248ba11664d18999295f7c9
SHA1 hash: da615b44c37fb15116e20246905753f06990e720
MD5 hash: 3e51a9fa1407971b95657e6b355aed84
humanhash: diet-uncle-lemon-arizona
File name:w.sh
Download: download sample
Signature Mirai
File size:937 bytes
First seen:2026-09-07 03:46:49 UTC
Last seen:2026-09-07 18:25:31 UTC
File type: sh
MIME type:text/plain
ssdeep 24:8Ilc0acoEcHcbDc1Ric3c65cTKgczNI75c17c/oR:8IlcBcvcHc/c1Ric3cccTLcy5c17c/0
TLSH T1CF1170CF16D4A053C89CCD48746FC818A64487D374961F5EEC8CA8FAA9C5B1CF166F49
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.206/bins/x8643504a845226be9206b4e894da129cf1f59128ad94e54057a1befafc1a9a1849 Miraimirai ua-wget
http://176.65.139.206/bins/x86_648b927c46033c4fbfea2fb1978c75e0b46cd5b28baf3bb6df9d581a8172acd403 Miraimirai
http://176.65.139.206/bins/i6864d7a22b069c067690b721c63efc9ff9dd56808c4016663706ca2e69eb0b7ef43 Mirai176-65-139-206 elf mirai ua-wget
http://176.65.139.206/bins/sh40f0bdc5b704b2ae22f25918f1773f4b17ff9fe4b352028ccb14ec7ce78e32587 Miraimirai ua-wget
http://176.65.139.206/bins/ppcd557d766694f5b1a99989f583bb7ddfb182685b34dded97753ade7c21a033c10 Miraimirai ua-wget
http://176.65.139.206/bins/mpsln/an/amirai ua-wget
http://176.65.139.206/bins/mipsf88e058fc4346aa5e3268e32d3ce6ffa4f944475b6455ce3c9ace70cee071159 Miraimirai ua-wget
http://176.65.139.206/bins/m68kee96e95603c056061d87638ba5cd84ae4c607f2e8e6f4fbbc8f0b67fea8dffac Miraimirai ua-wget
http://176.65.139.206/bins/arm7de7e912de2a5f9e9a47b49ccc4d151a572a71b9b80c726ecbccf75056808e9da Miraimirai ua-wget
http://176.65.139.206/bins/arm63411f3e9c399fa3fdc6a88b5bd9d6f159e2ea45d9d932cdc882af14bc4347d36 Miraimirai ua-wget
http://176.65.139.206/bins/arm58ecf36802e901e2ee381f52908013185e091da1e5cb5bba065ce121fce055a25 Miraimirai ua-wget
http://176.65.139.206/bins/armb61799d222f582cf567b312b825d19a2095b784a2fe531bdc299d844c0f9a554 Miraimirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox downloader mirai
Verdict:
Malicious
File Type:
text
First seen:
2026-09-07T01:20:00Z UTC
Last seen:
2026-09-07T03:53:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=0dce4a05-1900-0000-53b4-2174130c0000 pid=3091 /usr/bin/sudo guuid=fb3be60b-1900-0000-53b4-2174140c0000 pid=3092 /tmp/sample.bin guuid=0dce4a05-1900-0000-53b4-2174130c0000 pid=3091->guuid=fb3be60b-1900-0000-53b4-2174140c0000 pid=3092 execve guuid=24fc280c-1900-0000-53b4-2174150c0000 pid=3093 /usr/bin/busybox net send-data guuid=fb3be60b-1900-0000-53b4-2174140c0000 pid=3092->guuid=24fc280c-1900-0000-53b4-2174150c0000 pid=3093 execve 154ae0c8-0a48-5314-8e17-6b610ebcef8a 176.65.139.206:80 guuid=24fc280c-1900-0000-53b4-2174150c0000 pid=3093->154ae0c8-0a48-5314-8e17-6b610ebcef8a send: 85B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-09-07 03:47:17 UTC
File Type:
Text (Shell)
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 32995ee3a0858c8c7f5594aa1bb4d38de616d66d60b920c5ffefe9bb41fccf38

(this sample)

  
Delivery method
Distributed via web download

Comments