MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 688a1caabb35c524537f8a290b8ef52f469cc1ba378f13fa069bf2f3279b2683. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 688a1caabb35c524537f8a290b8ef52f469cc1ba378f13fa069bf2f3279b2683
SHA3-384 hash: 7676e493256f232dd978d59b02fbaf4fa99addfe5c15b8e6569214c8e29cee6eebf6c2ca56905a6342c4d15302783545
SHA1 hash: db575fc38735b4a9a95a182b2e081da0d98f9f81
MD5 hash: d3f856d42e9b8b71a2fcadc241f0eb7d
humanhash: eight-spaghetti-virginia-maryland
File name:w.sh
Download: download sample
Signature Mirai
File size:584 bytes
First seen:2025-12-14 06:35:14 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:A8x/yoEQDNIjlT0AJwiKl24Qddn9iQr0/Rhwv:1xahONIpBXKlGA+v
TLSH T1FEF0C2F91527120A8B1DAE5FA4294418F423FBC3D231CE1C9894312A69C66263032F87
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.76/bins/parm7e726aa3cabc1c4d00e79297d039f7b06d38443cea526685c15aa0b6f04a8d36 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.76/bins/parm52c11d90736e755b6a9d67f4fcbce7a6ee0d9532d037484c33f63e60776623103 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.76/bins/parm6903b545afbd359b6a8c8646d1702df20f0c52f1582fbe127fc627ae9c757fb49 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.76/bins/parm7d89594e6f9072780b3847372b7d1ea66407f2aa2c6f943e4d1f33f36db76839c Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.76/bins/psh4a5e84dced348c34b895de7bc03f998137d25c75dbecd6b722e76d6e2fdc02ba7 Miraielf geofenced mirai opendir SuperH ua-wget USA
http://213.209.143.76/bins/pmips52530ad8ceff8d15119ad92f8562c7edc3bcd1bc892aeac108f3b28b87326506 Miraielf geofenced mips mirai opendir ua-wget USA
http://213.209.143.76/bins/pmipseln/an/aelf ua-wget
http://213.209.143.76/bins/px86889c487760bb3cc5a621fded2387069f70660225f2cb6ee8b2aff8cc005de690 Miraielf geofenced mirai opendir ua-wget USA x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
ps1
First seen:
2025-12-13T21:59:00Z UTC
Last seen:
2025-12-15T12:13:00Z UTC
Hits:
~100
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-12-14 03:29:54 UTC
AV detection:
10 of 24 (41.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 688a1caabb35c524537f8a290b8ef52f469cc1ba378f13fa069bf2f3279b2683

(this sample)

  
Delivery method
Distributed via web download

Comments