MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 49b99eef310d7af29903672ec2595a39ec44c1683423ba9556f73e00887c2347. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 49b99eef310d7af29903672ec2595a39ec44c1683423ba9556f73e00887c2347
SHA3-384 hash: fc57f67fe20a361935f3689a2d4264a918aae68943c058f19f100d9cbe54fb40a8769743d6c781a995b18f15881ef41e
SHA1 hash: c469bcd35c24688fa9b158132e53ef4e27a3bc6c
MD5 hash: 72e7e44681a5d66ed33b37e12d8a60db
humanhash: double-comet-echo-avocado
File name:x
Download: download sample
Signature Mirai
File size:4'513 bytes
First seen:2025-12-14 23:31:33 UTC
Last seen:2025-12-15 11:19:12 UTC
File type: sh
MIME type:text/plain
ssdeep 96:1xJEcEs0c6S+sVMw4Egg6mtsYhGUGE2/pmi:lD+sVMw4Ej6mtXhGUGE2/pmi
TLSH T1859128EDB5B217B7CEB09E69F266827520C2C3885C63CF95E42D70B5B8EBD44B200B14
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.94.208.162/mips67d14607625e9959f595650cae0dab34d9dbaed8baca79270c9aee9a5f8dab6f Mirai32-bit elf mirai Mozi
http://158.94.208.162/mpsld737b65bddabf106eb6642a551b2b4c848101ae57e00de37c9d9a2670a52f9d9 Miraielf mirai ua-wget
http://158.94.208.162/x86_6413d151f0910a9ec48ea9a1854ec4ed04c50b920673a2d963bcc7fa233d217126 Miraielf mirai ua-wget
http://158.94.208.162/arm4n/an/an/a
http://158.94.208.162/arm571ecf29f0548ecb0051046067bf46b3966c596a554bde739db08900b38198918 Miraielf mirai ua-wget
http://158.94.208.162/arm65e40a628404e0381d24f344df4e0250f01e94137aa3f98602b631c71a5c329c1 Miraielf mirai ua-wget
http://158.94.208.162/arm72f220f990fa4b3dd2db426c36428a4a66a0a55fbbb98dc3b5f1fbc240f692002 Miraielf mirai ua-wget
ftp://8.94.208.162:8021/mipsn/an/an/a
ftp://8.94.208.162:8021/mpsln/an/an/a
ftp://8.94.208.162:8021/arm4n/an/an/a
ftp://8.94.208.162:8021/arm5n/an/an/a
ftp://8.94.208.162:8021/arm7n/an/an/a
ftp://8.94.208.162:8021/arm6n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox medusa mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-14T16:55:00Z UTC
Last seen:
2025-12-15T00:37:00Z UTC
Hits:
~10
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-12-15 00:18:10 UTC
File Type:
Text (Shell)
AV detection:
12 of 23 (52.17%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 49b99eef310d7af29903672ec2595a39ec44c1683423ba9556f73e00887c2347

(this sample)

  
Delivery method
Distributed via web download

Comments