MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 80e201379b6e583f56ec3d42439b66690b294eea11fbec4965c8d202ccca808c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 80e201379b6e583f56ec3d42439b66690b294eea11fbec4965c8d202ccca808c
SHA3-384 hash: ca2945ff876f3515708878d6ad1aceadc1989d1bb322d6da2eda06fa54c3f04801a4d146daf3e0bc019d84332a60a9dd
SHA1 hash: b61e666d5155f4e28fb34b476871b33409bd2861
MD5 hash: 46ab3c5b8f6e83dad5d4cc3705254144
humanhash: single-batman-sixteen-lemon
File name:lterouter
Download: download sample
Signature Mirai
File size:164 bytes
First seen:2026-08-13 19:23:29 UTC
Last seen:2026-08-14 06:24:13 UTC
File type: sh
MIME type:text/plain
ssdeep 3:O22exARgCxLEq3FOdJ2GL9rSYCxLEbBFS/TWUKT6VVI9LJdvvvF:O25F2GLNSATT6IZJn
TLSH T1A3C08CCB1BA97200818D6C3832B700DE4293A70035E80F0EF8DA2A12CA8A940F17DB11
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.119.71.134/n2/mips6754b6bc55c6843c6730d1204d4fd442e2f040e89d9fb7e2084555aa8f9249f4 Miraielf mips mirai ua-wget

Intelligence


File Origin
# of uploads :
325
# of downloads :
6
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader dropper evasive
Status:
terminated
Behavior Graph:
%3 guuid=a6ac6193-1800-0000-1c69-880b820c0000 pid=3202 /usr/bin/sudo guuid=21a4c296-1800-0000-1c69-880b860c0000 pid=3206 /tmp/sample.bin guuid=a6ac6193-1800-0000-1c69-880b820c0000 pid=3202->guuid=21a4c296-1800-0000-1c69-880b860c0000 pid=3206 execve guuid=cddd0c97-1800-0000-1c69-880b870c0000 pid=3207 /usr/bin/wget net send-data write-file guuid=21a4c296-1800-0000-1c69-880b860c0000 pid=3206->guuid=cddd0c97-1800-0000-1c69-880b870c0000 pid=3207 execve guuid=b7690c9f-1800-0000-1c69-880b890c0000 pid=3209 /usr/bin/chmod guuid=21a4c296-1800-0000-1c69-880b860c0000 pid=3206->guuid=b7690c9f-1800-0000-1c69-880b890c0000 pid=3209 execve guuid=7c1c4e9f-1800-0000-1c69-880b8a0c0000 pid=3210 /usr/bin/dash guuid=21a4c296-1800-0000-1c69-880b860c0000 pid=3206->guuid=7c1c4e9f-1800-0000-1c69-880b8a0c0000 pid=3210 clone guuid=2db3ec9f-1800-0000-1c69-880b8d0c0000 pid=3213 /usr/bin/wget net send-data write-file guuid=21a4c296-1800-0000-1c69-880b860c0000 pid=3206->guuid=2db3ec9f-1800-0000-1c69-880b8d0c0000 pid=3213 execve guuid=c27b38a5-1800-0000-1c69-880b9c0c0000 pid=3228 /usr/bin/chmod guuid=21a4c296-1800-0000-1c69-880b860c0000 pid=3206->guuid=c27b38a5-1800-0000-1c69-880b9c0c0000 pid=3228 execve guuid=399294a5-1800-0000-1c69-880b9e0c0000 pid=3230 /usr/bin/dash guuid=21a4c296-1800-0000-1c69-880b860c0000 pid=3206->guuid=399294a5-1800-0000-1c69-880b9e0c0000 pid=3230 clone guuid=dd4062a7-1800-0000-1c69-880ba20c0000 pid=3234 /usr/bin/rm delete-file guuid=21a4c296-1800-0000-1c69-880b860c0000 pid=3206->guuid=dd4062a7-1800-0000-1c69-880ba20c0000 pid=3234 execve db230cf6-0fd0-5e56-a0c1-c53d77e701e8 160.119.71.134:80 guuid=cddd0c97-1800-0000-1c69-880b870c0000 pid=3207->db230cf6-0fd0-5e56-a0c1-c53d77e701e8 send: 136B guuid=2db3ec9f-1800-0000-1c69-880b8d0c0000 pid=3213->db230cf6-0fd0-5e56-a0c1-c53d77e701e8 send: 136B
Gathering data
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-08-13 22:08:22 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 80e201379b6e583f56ec3d42439b66690b294eea11fbec4965c8d202ccca808c

(this sample)

  
Delivery method
Distributed via web download

Comments