MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3a8d1a58f3e5d1b768c9e9d04a2705d6fcdcd38767502f110396ad88f67a84af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 3a8d1a58f3e5d1b768c9e9d04a2705d6fcdcd38767502f110396ad88f67a84af
SHA3-384 hash: 4fefe0e009618ce227c3f4bdfad430c5b4552705e84f8b744388626ccd8b29484adb5345ae93ad093a9e0a7210e04b27
SHA1 hash: 4f989f2d54d74e31db4a6e1f4d5e72f86f19dbf4
MD5 hash: b6b2b17dd302a494ea15e8f8edf95d45
humanhash: maryland-chicken-louisiana-blossom
File name:lilin.sh
Download: download sample
Signature Mirai
File size:686 bytes
First seen:2025-04-17 09:59:42 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3WKDbnPZrQhEvfQhEMDNkKCQht8TfQht8gDNkKCQtKZDfQtjDNkDQtECfQtERDNs:GIbjtmkK3f7kKBKZUFkc+YkKC
TLSH T1670162DE21B688166C424E95B0E34824E085DEF465C6CE4FD48E0977B04DD18B952F49
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://95.215.108.183/skid.armv5l9878b4183be068b638e04656a02c5679f02a5a982e472cc1c497cc654345f3b6 Miraiddos elf mirai
http://95.215.108.183/skid.armv7ln/an/addos elf mirai
http://95.215.108.183/skid.mipsn/an/addos elf mirai
http://95.215.108.183/skid.mipseln/an/addos elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
95.7%
Tags:
downloader mirai agent hype
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-04-17 10:00:48 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 3a8d1a58f3e5d1b768c9e9d04a2705d6fcdcd38767502f110396ad88f67a84af

(this sample)

  
Delivery method
Distributed via web download

Comments