MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4eed6ec3a843e5fcc6acd8010674868f7f8db69baa8a989f65df63712cf41967. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 4eed6ec3a843e5fcc6acd8010674868f7f8db69baa8a989f65df63712cf41967
SHA3-384 hash: 1772fd45f4190a3608c411e41bed0d2e59c09733ae3c18030939b8148cf215d9955d40e0ba0559636616c93ac89315ca
SHA1 hash: fe3685b12d7af80eeca2543a27cd3c2c16d00d13
MD5 hash: 954b28e20acaba90f30993503ec9363a
humanhash: yankee-six-wisconsin-autumn
File name:uni
Download: download sample
Signature Mirai
File size:370 bytes
First seen:2025-10-18 00:52:30 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:NqasMHHslVx4y2XD1DLZDI1DLyHk7vD7jD1DxUDI1Dx3Hk7vD9Xh:NpsMs7WVZDMyHkLDTC23HkLDv
TLSH T1DFE0D8FF11D402795490892E3E134D26A60C07F269F44B9FF09E2672AB8894DF805FAE
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://42.112.26.45/mips0b92cb77fec808a81df7037d623f112a33c759a5f7cf13681d2ff71c8471fcef Miraielf gafgyt mirai ua-wget
http://42.112.26.45/mipsel46f9306573975efd01e93530fbb3417b76f5e605f51059ea18c74f8481622403 Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Status:
terminated
Behavior Graph:
%3 guuid=25e8b848-1a00-0000-7803-4789c70c0000 pid=3271 /usr/bin/sudo guuid=496c2c4b-1a00-0000-7803-4789d00c0000 pid=3280 /tmp/sample.bin guuid=25e8b848-1a00-0000-7803-4789c70c0000 pid=3271->guuid=496c2c4b-1a00-0000-7803-4789d00c0000 pid=3280 execve guuid=a90a6e4b-1a00-0000-7803-4789d10c0000 pid=3281 /usr/bin/cp guuid=496c2c4b-1a00-0000-7803-4789d00c0000 pid=3280->guuid=a90a6e4b-1a00-0000-7803-4789d10c0000 pid=3281 execve guuid=f3f99851-1a00-0000-7803-4789df0c0000 pid=3295 /usr/bin/dash guuid=496c2c4b-1a00-0000-7803-4789d00c0000 pid=3280->guuid=f3f99851-1a00-0000-7803-4789df0c0000 pid=3295 clone guuid=5acfdd93-1a00-0000-7803-4789550d0000 pid=3413 /usr/bin/chmod guuid=496c2c4b-1a00-0000-7803-4789d00c0000 pid=3280->guuid=5acfdd93-1a00-0000-7803-4789550d0000 pid=3413 execve guuid=e49e3794-1a00-0000-7803-4789570d0000 pid=3415 /usr/bin/dash guuid=496c2c4b-1a00-0000-7803-4789d00c0000 pid=3280->guuid=e49e3794-1a00-0000-7803-4789570d0000 pid=3415 clone guuid=7b170f95-1a00-0000-7803-47895a0d0000 pid=3418 /usr/bin/rm delete-file guuid=496c2c4b-1a00-0000-7803-4789d00c0000 pid=3280->guuid=7b170f95-1a00-0000-7803-47895a0d0000 pid=3418 execve guuid=46a86495-1a00-0000-7803-47895c0d0000 pid=3420 /usr/bin/dash guuid=496c2c4b-1a00-0000-7803-4789d00c0000 pid=3280->guuid=46a86495-1a00-0000-7803-47895c0d0000 pid=3420 clone guuid=507c6fd6-1a00-0000-7803-4789cd0d0000 pid=3533 /usr/bin/chmod guuid=496c2c4b-1a00-0000-7803-4789d00c0000 pid=3280->guuid=507c6fd6-1a00-0000-7803-4789cd0d0000 pid=3533 execve guuid=114807d7-1a00-0000-7803-4789cf0d0000 pid=3535 /usr/bin/dash guuid=496c2c4b-1a00-0000-7803-4789d00c0000 pid=3280->guuid=114807d7-1a00-0000-7803-4789cf0d0000 pid=3535 clone guuid=5e6284d7-1a00-0000-7803-4789d20d0000 pid=3538 /usr/bin/rm delete-file guuid=496c2c4b-1a00-0000-7803-4789d00c0000 pid=3280->guuid=5e6284d7-1a00-0000-7803-4789d20d0000 pid=3538 execve guuid=4bc1d4d7-1a00-0000-7803-4789d40d0000 pid=3540 /usr/bin/rm delete-file guuid=496c2c4b-1a00-0000-7803-4789d00c0000 pid=3280->guuid=4bc1d4d7-1a00-0000-7803-4789d40d0000 pid=3540 execve guuid=3e4ea251-1a00-0000-7803-4789e00c0000 pid=3296 /usr/bin/wget net send-data write-file guuid=f3f99851-1a00-0000-7803-4789df0c0000 pid=3295->guuid=3e4ea251-1a00-0000-7803-4789e00c0000 pid=3296 execve 7e1f030a-193f-5ef8-b58f-206d09d04b13 42.112.26.45:80 guuid=3e4ea251-1a00-0000-7803-4789e00c0000 pid=3296->7e1f030a-193f-5ef8-b58f-206d09d04b13 send: 131B guuid=5fd57895-1a00-0000-7803-47895d0d0000 pid=3421 /usr/bin/wget net send-data write-file guuid=46a86495-1a00-0000-7803-47895c0d0000 pid=3420->guuid=5fd57895-1a00-0000-7803-47895d0d0000 pid=3421 execve guuid=5fd57895-1a00-0000-7803-47895d0d0000 pid=3421->7e1f030a-193f-5ef8-b58f-206d09d04b13 send: 133B
Threat name:
Linux.Downloader.ShellAgnt
Status:
Malicious
First seen:
2025-10-18 00:48:05 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4eed6ec3a843e5fcc6acd8010674868f7f8db69baa8a989f65df63712cf41967

(this sample)

  
Delivery method
Distributed via web download

Comments