MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 45ce79bbac91e3ca67d3cc7dd150ada9109cf6a52b09d3e6eaad8adb4df30777. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 45ce79bbac91e3ca67d3cc7dd150ada9109cf6a52b09d3e6eaad8adb4df30777
SHA3-384 hash: b1d95615d36230a0b36ba579edb2b5e13aff9e072609e291380126e2db0c22a1f80d914277fe60750400e5900fc19e0a
SHA1 hash: 43b49da0b67b0fe4428cd9939cdb00a39e79ff24
MD5 hash: 83a52d42c62bec87c510d55965565c0f
humanhash: high-magnesium-six-table
File name:mload.sh
Download: download sample
Signature Mirai
File size:1'723 bytes
First seen:2026-07-20 01:55:21 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:QvQhnojhnojhnojhno0jDGEeECEhEoEgoEP:AQhnAhnAhnAhn/jqEeECEhEoErEP
TLSH T1BA314B0DC2C2EA2095815CE6F0C69112B913D7DCBBA31E74FE0AE7B1782C8497132D72
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.150.195.235/tmipsd8a8cea14b12aa75047979f929bdf10b9003884580398c3c13d2b4fb04209410 Miraielf gafgyt mips mirai ua-wget
http://45.150.195.235/tmpsl932e3c4ae1d5404ceade8dfd386182800b91eb93794c914b7f09b094996b061e Miraielf gafgyt mips mirai ua-wget
http://45.150.195.235/tarmb651c6d5c7499a41b6e3d840c0254fe53db6e8d0ab298fd2327f10b3c6892e5d Miraiarm elf gafgyt mirai ua-wget
http://45.150.195.235/tarm537f30b3dca6521b319bdf1b967e205a156c953519fe0acbdad581d6f488da8ba Miraiarm elf gafgyt mirai ua-wget
http://45.150.195.235/tarm650fa67706d725e7a22247a361c6d6907eab4633c20c471705cae8b10228627f0 Miraiarm elf gafgyt mirai ua-wget
http://45.150.195.235/tarm775f5413dcdf4c69f8b49ab6bec5c9a9948c768d5abbbbd0c093c971b39e4398e Miraiarm elf gafgyt mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-07-19T23:40:00Z UTC
Last seen:
2026-07-20T06:15:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=af27081b-1700-0000-3bbf-4768c80c0000 pid=3272 /usr/bin/sudo guuid=432ba81d-1700-0000-3bbf-4768ce0c0000 pid=3278 /tmp/sample.bin guuid=af27081b-1700-0000-3bbf-4768c80c0000 pid=3272->guuid=432ba81d-1700-0000-3bbf-4768ce0c0000 pid=3278 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-20 01:55:48 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 45ce79bbac91e3ca67d3cc7dd150ada9109cf6a52b09d3e6eaad8adb4df30777

(this sample)

  
Delivery method
Distributed via web download

Comments