MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 83bfe81f9d729d349eda5147a6f023081ff431d993e5a49a2f0e36a4ef7912bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 5
| SHA256 hash: | 83bfe81f9d729d349eda5147a6f023081ff431d993e5a49a2f0e36a4ef7912bc |
|---|---|
| SHA3-384 hash: | 0aff06d1ea2f69a0b0de1c5a93d0c3c9c719e7b2498f2f4eddf7fbc46bec0d0cbbaecf068a5911c26c90cfb2c662e077 |
| SHA1 hash: | fc3a7a96c2c494704bfe522b334dd28becfcbf22 |
| MD5 hash: | 818793fabdbb85a0b6bbde05ba5e3167 |
| humanhash: | mississippi-dakota-football-minnesota |
| File name: | lterouter |
| Download: | download sample |
| File size: | 164 bytes |
| First seen: | 2026-08-04 19:04:35 UTC |
| Last seen: | 2026-08-05 19:07:07 UTC |
| File type: | sh |
| MIME type: | text/plain |
| ssdeep | 3:O22exARhTLTeURJUtNA3FOdJ2GL9rSZTLTeURJUtUuBFS/TWUKT6VVI9LJdvvvF:O25ifst12GLNSZfstUsTT6IZJn |
| TLSH | T1B4C08CC707917200C0E9AC287256809E42938680B8BE1F08F8EC0722DBCE940F020B01 |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://176.65.148.145/n2/mips | 3cf154dfdf1790f2fd185f6f5ac618c75c0d6ff83ca19812e272da6bdb8bd4b5 | Mirai | elf mips mirai ua-wget |
Intelligence
File Origin
# of uploads :
260
# of downloads :
4
Origin country :
DEVendor Threat Intelligence
No detections
Detection(s):
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
downloader evasive
Status:
terminated
Behavior Graph:
Score:
100%
Verdict:
Malware
File Type:
SCRIPT
Gathering data
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-08-04 20:08:05 UTC
AV detection:
6 of 38 (15.79%)
Threat level:
2/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 83bfe81f9d729d349eda5147a6f023081ff431d993e5a49a2f0e36a4ef7912bc
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.