MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 454aa25721156dff0eb2dec32628e40bcb5154f718da445c5481079a62b32d74. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 454aa25721156dff0eb2dec32628e40bcb5154f718da445c5481079a62b32d74
SHA3-384 hash: 791e9937162ee4018f2b506a195813c16907fb9b101cd615301b6ef74e9a90ce1166cb7cb03655ad3de785cb51b28abb
SHA1 hash: 4465cda8a2880cf380cbac055e9ca9ef53089d0d
MD5 hash: 0ac68a243e419baf56ce088929dbf998
humanhash: helium-equal-twenty-saturn
File name:lterouter
Download: download sample
File size:162 bytes
First seen:2026-05-29 03:18:33 UTC
Last seen:2026-05-29 06:28:30 UTC
File type: sh
MIME type:text/plain
ssdeep 3:O22exART6EQi3FOdJ2GL9rSL6EQzBFS/TWUKT6VVI9LJdvvvF:O2546N12GLNSL6NZTT6IZJn
TLSH T14FC080CB0B253434C042EC1875D5012E428F774034B44F0C78D40F51E649940F425F42
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://51.81.104.123/n2/mips69a3f8207de0386d28e743b27f532b3413d83f5b57b88213f633c6061fdb3361 Miraielf mips mirai ua-wget

Intelligence


File Origin
# of uploads :
71
# of downloads :
8
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=9cf9ae74-1b00-0000-4cfe-e7b3450a0000 pid=2629 /usr/bin/sudo guuid=cd662177-1b00-0000-4cfe-e7b34d0a0000 pid=2637 /tmp/sample.bin guuid=9cf9ae74-1b00-0000-4cfe-e7b3450a0000 pid=2629->guuid=cd662177-1b00-0000-4cfe-e7b34d0a0000 pid=2637 execve guuid=38d78077-1b00-0000-4cfe-e7b34f0a0000 pid=2639 /usr/bin/wget net send-data write-file guuid=cd662177-1b00-0000-4cfe-e7b34d0a0000 pid=2637->guuid=38d78077-1b00-0000-4cfe-e7b34f0a0000 pid=2639 execve guuid=c6b1b190-1b00-0000-4cfe-e7b3970a0000 pid=2711 /usr/bin/chmod guuid=cd662177-1b00-0000-4cfe-e7b34d0a0000 pid=2637->guuid=c6b1b190-1b00-0000-4cfe-e7b3970a0000 pid=2711 execve guuid=d371fa90-1b00-0000-4cfe-e7b3980a0000 pid=2712 /usr/bin/dash guuid=cd662177-1b00-0000-4cfe-e7b34d0a0000 pid=2637->guuid=d371fa90-1b00-0000-4cfe-e7b3980a0000 pid=2712 clone guuid=3a654792-1b00-0000-4cfe-e7b39e0a0000 pid=2718 /usr/bin/wget net send-data write-file guuid=cd662177-1b00-0000-4cfe-e7b34d0a0000 pid=2637->guuid=3a654792-1b00-0000-4cfe-e7b39e0a0000 pid=2718 execve guuid=f35a42a9-1b00-0000-4cfe-e7b3d20a0000 pid=2770 /usr/bin/chmod guuid=cd662177-1b00-0000-4cfe-e7b34d0a0000 pid=2637->guuid=f35a42a9-1b00-0000-4cfe-e7b3d20a0000 pid=2770 execve guuid=dfd7a3a9-1b00-0000-4cfe-e7b3d40a0000 pid=2772 /usr/bin/dash guuid=cd662177-1b00-0000-4cfe-e7b34d0a0000 pid=2637->guuid=dfd7a3a9-1b00-0000-4cfe-e7b3d40a0000 pid=2772 clone guuid=7e52f9aa-1b00-0000-4cfe-e7b3d80a0000 pid=2776 /usr/bin/rm delete-file guuid=cd662177-1b00-0000-4cfe-e7b34d0a0000 pid=2637->guuid=7e52f9aa-1b00-0000-4cfe-e7b3d80a0000 pid=2776 execve d08d03e7-131c-5ec2-9c03-bf9a6163518b 51.81.104.123:80 guuid=38d78077-1b00-0000-4cfe-e7b34f0a0000 pid=2639->d08d03e7-131c-5ec2-9c03-bf9a6163518b send: 135B guuid=3a654792-1b00-0000-4cfe-e7b39e0a0000 pid=2718->d08d03e7-131c-5ec2-9c03-bf9a6163518b send: 135B
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-05-29 04:44:20 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 454aa25721156dff0eb2dec32628e40bcb5154f718da445c5481079a62b32d74

(this sample)

  
Delivery method
Distributed via web download

Comments