MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 83bfe81f9d729d349eda5147a6f023081ff431d993e5a49a2f0e36a4ef7912bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 83bfe81f9d729d349eda5147a6f023081ff431d993e5a49a2f0e36a4ef7912bc
SHA3-384 hash: 0aff06d1ea2f69a0b0de1c5a93d0c3c9c719e7b2498f2f4eddf7fbc46bec0d0cbbaecf068a5911c26c90cfb2c662e077
SHA1 hash: fc3a7a96c2c494704bfe522b334dd28becfcbf22
MD5 hash: 818793fabdbb85a0b6bbde05ba5e3167
humanhash: mississippi-dakota-football-minnesota
File name:lterouter
Download: download sample
File size:164 bytes
First seen:2026-08-04 19:04:35 UTC
Last seen:2026-08-05 19:07:07 UTC
File type: sh
MIME type:text/plain
ssdeep 3:O22exARhTLTeURJUtNA3FOdJ2GL9rSZTLTeURJUtUuBFS/TWUKT6VVI9LJdvvvF:O25ifst12GLNSZfstUsTT6IZJn
TLSH T1B4C08CC707917200C0E9AC287256809E42938680B8BE1F08F8EC0722DBCE940F020B01
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.148.145/n2/mips3cf154dfdf1790f2fd185f6f5ac618c75c0d6ff83ca19812e272da6bdb8bd4b5 Miraielf mips mirai ua-wget

Intelligence


File Origin
# of uploads :
260
# of downloads :
4
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader evasive
Status:
terminated
Behavior Graph:
%3 guuid=d69c74e3-1600-0000-0a78-bb253f0d0000 pid=3391 /usr/bin/sudo guuid=371769e7-1600-0000-0a78-bb25460d0000 pid=3398 /tmp/sample.bin guuid=d69c74e3-1600-0000-0a78-bb253f0d0000 pid=3391->guuid=371769e7-1600-0000-0a78-bb25460d0000 pid=3398 execve guuid=6f179ae7-1600-0000-0a78-bb25470d0000 pid=3399 /usr/bin/wget guuid=371769e7-1600-0000-0a78-bb25460d0000 pid=3398->guuid=6f179ae7-1600-0000-0a78-bb25470d0000 pid=3399 execve
Gathering data
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-08-04 20:08:05 UTC
AV detection:
6 of 38 (15.79%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 83bfe81f9d729d349eda5147a6f023081ff431d993e5a49a2f0e36a4ef7912bc

(this sample)

  
Delivery method
Distributed via web download

Comments