MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4bb2c93651a674ec43091e56d39d5e54f537b38fa7af3fd193970fbd46368bb4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4bb2c93651a674ec43091e56d39d5e54f537b38fa7af3fd193970fbd46368bb4
SHA3-384 hash: a134d7aa9b956d62e66ee9556605226c6208d210f653c1312d86da737ac06d68ba613e357df27f21c2f5c8ec61b6d2bc
SHA1 hash: 69eb4aa8da70cbf356df3c764802fd116c9ab5e9
MD5 hash: 8b7af4e97569e0dbbd8d92badbbd0938
humanhash: jersey-fish-blue-wolfram
File name:tplink
Download: download sample
Signature Mirai
File size:4'010 bytes
First seen:2025-12-07 16:08:20 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:Qva569Q0tz0tz0tz0tz0tBoTiAMcyHjHYi+sYdiGZYbi8p408e9H/eejTZ6snoap:AE69QmzmzmzmzmIRxZCp
TLSH T125819DFE3662263278168D4FB5D1C9B8A87FE4DC24115FA4FA4EBCE486544837010B77
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.125.66.90/mips67df849f3252e566ca8f73336ab31eb7b5ddb277c91f90a9dac885c9d9de3837 Miraiddos elf mirai
http://45.125.66.90/mpsl449e30caaa96c2833e4f381071095addc874ad4bab41e21225acf6356145c0ed Miraiddos elf mirai
http://45.125.66.90/arm4a3d5e3c3e422d72ef0e095e164f2706e250839eaf52e24dd7624f6e3e250f8da Miraielf mirai ua-wget
http://45.125.66.90/arm5788e47fcc1f7e85da5b575ddeb98980fafc9cab532c378855556d679da2a59be Miraiddos elf mirai
http://45.125.66.90/arm75967869b8f30e997ac1fa2395316234ac61d6de55ec8a38a10b0b4f4e8ee57d7 Miraiddos elf mirai
http://45.125.66.90/x86b8a839dd0e839c887d7101ca0389f7b7185cd82a4a4c294631afffc85c9bcdac Miraiddos elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox expand lolbin mirai
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-07 16:25:22 UTC
File Type:
Text (Shell)
AV detection:
10 of 36 (27.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4bb2c93651a674ec43091e56d39d5e54f537b38fa7af3fd193970fbd46368bb4

(this sample)

  
Delivery method
Distributed via web download

Comments