MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3549b9938dfbc48b0a6c831c4a9fe0e7aa5aff52c66cef29844f3e6aefa6294a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 3549b9938dfbc48b0a6c831c4a9fe0e7aa5aff52c66cef29844f3e6aefa6294a
SHA3-384 hash: 18298c89c1042a9af1df093b6a41719ab646cb976c20ba61b29e651fddac79af44006bfa9f03b421f464c47c9d399f2c
SHA1 hash: 3c5845f626c1e99ab578a6bbc3b87eecb6424286
MD5 hash: d12d23e8322d78ef87952d5b740efb95
humanhash: kansas-comet-delaware-quebec
File name:wget.sh
Download: download sample
Signature Mirai
File size:765 bytes
First seen:2025-05-11 16:57:17 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:6fKaj+JfK6Lq+JfKoNIl5zA+JfKx0LKj+JfKIOs+JfK8C+JfK7a/+JfK7SE+JfKA:GKayK6LxKoNI7PKoKyKIkK85K+GK7uKA
TLSH T1D101999E2771568D8B0C8E1870AA0E84664A93C1F874EF19AC4C98F76CD9A05B05CF7F
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://161.248.238.64/arm2f00e4fb95309d91ab81dc08851ccfd6680ef23469986904a31749c6d78e8559 Miraielf mirai
http://161.248.238.64/arm557aee870589a2560b3674f6038b69b19e6653d96cb97ed06291ca361868f3ef5 Miraielf mirai
http://161.248.238.64/arm69f53039e036b76911846e9da33ee5239f7123a6e7a845854e385a45532611354 Miraielf mirai
http://161.248.238.64/arm787a4f596f7843ab69e4cc37fcdbeb6f049adb36d90f3f8cef361897bca47ba58 Miraielf mirai
http://161.248.238.64/m68k08d599c98659bbf14d79de79202561ec33c2d39927461c796633949ba4c34d10 Miraielf mirai
http://161.248.238.64/mips46229e24b48ba7c1f238b66acb508be355544a303a93a3348adc8b80d819af59 Miraielf mirai
http://161.248.238.64/mpsl757e960e32d068988534c366cc408939e22e9081e657ccff7780aba90dc21649 Miraielf mirai
http://161.248.238.64/ppcafb123ebe8623dc644deceb092f170a3e4689a94f97323e94c2fbe28613ece9a Miraielf mirai
http://161.248.238.64/sh4a69dcd95a865f1af32e87bd70e4cf237a0ca249f0296fda1d407c5af690f7c5d Miraielf mirai
http://161.248.238.64/spcn/an/an/a
http://161.248.238.64/x86b099b8efafeef0b5d17747c9b2ab8813b40fa89b3d7db63d04fc253c7b7027b0 Miraielf mirai
http://161.248.238.64/x86_6437166e1ed7557cb7dbc2521f38f0e2f6e818f3025e4803cbb7503f591a84ad2f Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
116
Origin country :
DE DE
Vendor Threat Intelligence
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-05-11 16:58:13 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 3549b9938dfbc48b0a6c831c4a9fe0e7aa5aff52c66cef29844f3e6aefa6294a

(this sample)

  
Delivery method
Distributed via web download

Comments