MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6686d13aae29aa3d67bbae7b00287308d70298abd052d8086850a8dbed595a90. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 6686d13aae29aa3d67bbae7b00287308d70298abd052d8086850a8dbed595a90
SHA3-384 hash: 3e90b1f0a3b0a05131b6c79c1871befe642407bfaa26e6f60fcb6aa79ae52a189e8eaa564de9f194799c7a468b4b3d0c
SHA1 hash: 95956ca5b92d4e99daf9ddc87598f9e9a8d02d12
MD5 hash: 4d1a4ef71ed2ce8173dbe935302acdbb
humanhash: bulldog-harry-purple-double
File name:massload
Download: download sample
Signature Mirai
File size:1'669 bytes
First seen:2025-04-25 12:22:53 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:QvZi4w8avtULEy8CvsUqHyfC2lul21l8lnGlbTlh:AZix6s6SccqbBh
TLSH T10F3173A57C61AF776AC2EE44F1F3C146A0C3FAC254544E19A6F9687AE8FC9083421A17
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://212.18.104.182/mips4db20e28703aefb852e4b3e6de0db31095f19c83dc09b2556c619647bf24855e Miraielf geofenced mirai ua-wget USA
http://212.18.104.182/mpsl4e5104f9e5b922366f6fab21ebaac7dcbddbae80cbc9349e5fa4c859e721302b Miraielf geofenced mirai ua-wget USA
http://212.18.104.182/arm42cecf382d90634a980c0d851a89a07372ee63858ee4750d066e242d17836c023 Miraielf geofenced mirai ua-wget USA
http://212.18.104.182/arm5c8486bee71381117c6ac3d925b5bddf2f86fcb9e5d428140c4c9aa1b0001c968 Miraielf geofenced mirai ua-wget USA
http://212.18.104.182/arm748435dbe00dc88d447da49eff2d7bd8964cc68b0f38bdc82e99539abc6812d37 Miraielf geofenced mirai ua-wget USA
ftp://2.18.104.182:8021/mipsn/an/an/a
ftp://2.18.104.182:8021/mpsln/an/an/a
ftp://2.18.104.182:8021/arm4n/an/an/a
ftp://2.18.104.182:8021/arm5n/an/an/a
ftp://2.18.104.182:8021/arm7n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
trojan mirai agent virus
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-04-25 15:18:12 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6686d13aae29aa3d67bbae7b00287308d70298abd052d8086850a8dbed595a90

(this sample)

  
Delivery method
Distributed via web download

Comments