MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a10aedb49a9c772881350b9f78d43bf8dc805a9d7555ea709cf13d101f9a10d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 7a10aedb49a9c772881350b9f78d43bf8dc805a9d7555ea709cf13d101f9a10d
SHA3-384 hash: a4e82b5d94a4b8d83eedf9f3fa90eb5277810334b8bd2b2ba675803d496fc29cb3113fc9a10aac5f66e6b05520a2c402
SHA1 hash: d7ddc3d24bf72f310d7276e7cf68dd5a347d9250
MD5 hash: 36d06c0a520050450a40762b3ce62c86
humanhash: florida-white-montana-friend
File name:wget.sh
Download: download sample
Signature Mirai
File size:315 bytes
First seen:2026-07-28 14:19:45 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:KbA3JP8khELVB+nA3DQ8ksWQELLcB+nA3cxh9yLcMB+nA3Ij7BxhbQxIMBnUv:KbAZPfhE3+nAzQ8ksxgw+nAyhgLcA+nF
TLSH T179E0DFDB0011630846889D00785A0A392A6F82A030379B1C2242A4F6CAC911DA83AFCF
Magika shell
Reporter BlinkzSec
URLMalware sample (SHA256 hash)SignatureTags
http://31.56.209.153/nz/nz.mips7b651e4f66c0bcc2befa5a981caaf7ea1180b8bb530bb1e384ba42e70f097db1 Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.mpslf4af27bb0f0bcc102b0596a909c738fc5aa0956fed74010c0e314cac01d86323 Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.x8686a98b0a9d3b4cba259ace302a120d0ed77561198f3e6a17b855f4ebd4bbbb50 Miraielf mirai opendir ua-wget x86
http://31.56.209.153/nz/mz.x86_64n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
GB GB
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=9b88adf2-1800-0000-4df0-21cc320c0000 pid=3122 /usr/bin/sudo guuid=6e3ccaf5-1800-0000-4df0-21cc350c0000 pid=3125 /tmp/sample.bin guuid=9b88adf2-1800-0000-4df0-21cc320c0000 pid=3122->guuid=6e3ccaf5-1800-0000-4df0-21cc350c0000 pid=3125 execve guuid=ab96a1f6-1800-0000-4df0-21cc370c0000 pid=3127 /usr/bin/wget guuid=6e3ccaf5-1800-0000-4df0-21cc350c0000 pid=3125->guuid=ab96a1f6-1800-0000-4df0-21cc370c0000 pid=3127 execve
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2026-07-26 23:45:30 UTC
File Type:
Text (Shell)
AV detection:
8 of 36 (22.22%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments