MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f369751f1b58e23d838e25846c03bd66f8e84dc08c878ab2d58073e37b59389. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 3f369751f1b58e23d838e25846c03bd66f8e84dc08c878ab2d58073e37b59389
SHA3-384 hash: 2f55810dd90e3599044bc0d445b6715850a65c2b7160b4ecb4e94cc61b66c970860046fa190267e5381abcb4905176f0
SHA1 hash: 79d658c1d7668e1f5348e11eef0ceceebe6b77ac
MD5 hash: bc8de4085beb82ca68b454968c995249
humanhash: chicken-delaware-oxygen-steak
File name:run.sh
Download: download sample
Signature Mirai
File size:2'881 bytes
First seen:2025-12-22 05:37:54 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:6909n9iO9i2JMY97C97biBc9HL9HuZU9OEd9OEnE2EhEv9O9xt9aL9abwP9F9H9g:ot2JMM+biB8puZHHcvyAAbwlohM3K
TLSH T13F51819F11089F31A74E858EB7F031B4A54AA5D35BEB8A14EF90085E2EC5E4C37C9E50
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.16/bins/xnxnxnxnxnxnxnxnaarch64xnxn05fae73efc1356bc66de8543d49d2b8ad09b0aa8fa8446c27dfe25a5fbac8160 Miraielf ua-wget
http://130.12.180.16/bins/xnxnxnxnxnxnxnxni386xnxnccdbacff8e06c494edb527baa8f68a1b8d35fc4d60654b975470274b9d0e4356 Miraielf mirai ua-wget
http://130.12.180.16/bins/xnxnxnxnxnxnxnxnloongarch64xnxn10ddabc05fe89e6a9ecc5365944ab5859cfeeac4104f945665b4ea87a5a23028 Miraielf ua-wget
http://130.12.180.16/bins/xnxnxnxnxnxnxnxnm68kxnxn137180c258a5680c572d618115d269a02fd7e3f4d55e342b3db666bf68be7001 Miraielf mirai ua-wget
http://130.12.180.16/bins/xnxnxnxnxnxnxnxnmicroblazexnxn462cc9496008db5d12d32b7a1691abcd769acc5b7c6b8df9ebc59d46553f89e0 Miraielf ua-wget
http://130.12.180.16/bins/xnxnxnxnxnxnxnxnmipsxnxn69e71de8450be9341f492cefcb02d605dee6cdc02baeedef7a42bdb8edbbfb63 Miraielf mirai ua-wget
http://130.12.180.16/bins/xnxnxnxnxnxnxnxnor1kxnxn57f56c7a97484f12de3ce3816631516f6a486ab0f6dab87b1bc3792a9db5b9ce Miraielf ua-wget
http://130.12.180.16/bins/xnxnxnxnxnxnxnxnpowerpcxnxn991124c385ac015fb0d1d962473dedd65bb6040934a74e36b250256df513a451 Miraielf ua-wget
http://130.12.180.16/bins/xnxnxnxnxnxnxnxnriscv32xnxnacd519a388fba0fd364ca61cd9f5e937b6d704d3477f78430610667298cbe856 Miraielf ua-wget
http://130.12.180.16/bins/xnxnxnxnxnxnxnxnriscv64xnxn2293262893fa3122583ca09e128fea53947932cc3e33a444ec787320d9d19ef6 Miraielf mirai ua-wget
http://130.12.180.16/bins/xnxnxnxnxnxnxnxnsh2xnxn70050c57be934b308494bdb2e975bfa9d0be7e8fef2ff6d03744574b180bfb52 Miraielf ua-wget
http://130.12.180.16/bins/xnxnxnxnxnxnxnxnsh4xnxn876f9daefe6d989351fd34a94c8370b3da90fd16195802da6baa3bbb2690151b Miraielf ua-wget
http://130.12.180.16/bins/xnxnxnxnxnxnxnxnx86_64xnxn6739482cc3fe3f034c884e4ee6aef7bd0c76de6780591e4d88153cd2e0c61fe1 Miraielf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-22T04:15:00Z UTC
Last seen:
2025-12-22T04:57:00Z UTC
Hits:
~10
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-12-22 05:38:11 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 3f369751f1b58e23d838e25846c03bd66f8e84dc08c878ab2d58073e37b59389

(this sample)

  
Delivery method
Distributed via web download

Comments