MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8ed141ee728ea1767e4cfb4e505622124fb3eb01455f0772a6360c30d709e24e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 8ed141ee728ea1767e4cfb4e505622124fb3eb01455f0772a6360c30d709e24e
SHA3-384 hash: 8b137b31132adfe7a2d71c07c1f95a4b63856fb71cf18ea083daa14143d40a783ed099a0532640bdd8f161f16c23bda4
SHA1 hash: c89738756b2f224d9301c0044fe2f761c618718f
MD5 hash: 272742ca4e51ebf1b6e04ccd1c5f619c
humanhash: tennessee-pluto-lima-thirteen
File name:4g
Download: download sample
Signature Mirai
File size:154 bytes
First seen:2025-12-05 18:22:39 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:LxAjtyg/w8NBzSa+ANjaziDxAjtyg/pONBzSa5Ap9Mn:LA5/wkPjmiDA5/Myyn
TLSH T17BC08CBD002B2241C000BE107026305DB233CBC720B28B0A96C83033F48C420B222E00
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.64/splmips633397cf2ca1b26757c7f32fe2e980ea66f783becff9455e11ded00b20032417 Miraielf mirai ua-wget
http://213.209.143.64/splmpsl61d0e0c8b1e9fdf341c8bbaacc50fe6cc5c5f73d4b7cb0f80808e6fedbf70d3c Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-05T20:54:00Z UTC
Last seen:
2025-12-07T12:40:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=cd1c1582-1800-0000-7813-3cd4fa090000 pid=2554 /usr/bin/sudo guuid=a3e4e784-1800-0000-7813-3cd4010a0000 pid=2561 /tmp/sample.bin guuid=cd1c1582-1800-0000-7813-3cd4fa090000 pid=2554->guuid=a3e4e784-1800-0000-7813-3cd4010a0000 pid=2561 execve guuid=e4263d85-1800-0000-7813-3cd4020a0000 pid=2562 /usr/bin/wget net send-data write-file guuid=a3e4e784-1800-0000-7813-3cd4010a0000 pid=2561->guuid=e4263d85-1800-0000-7813-3cd4020a0000 pid=2562 execve guuid=05eb2f8c-1800-0000-7813-3cd4130a0000 pid=2579 /usr/bin/chmod guuid=a3e4e784-1800-0000-7813-3cd4010a0000 pid=2561->guuid=05eb2f8c-1800-0000-7813-3cd4130a0000 pid=2579 execve guuid=2dd07c8c-1800-0000-7813-3cd4140a0000 pid=2580 /usr/bin/dash guuid=a3e4e784-1800-0000-7813-3cd4010a0000 pid=2561->guuid=2dd07c8c-1800-0000-7813-3cd4140a0000 pid=2580 clone guuid=13201b8d-1800-0000-7813-3cd4170a0000 pid=2583 /usr/bin/wget net send-data write-file guuid=a3e4e784-1800-0000-7813-3cd4010a0000 pid=2561->guuid=13201b8d-1800-0000-7813-3cd4170a0000 pid=2583 execve guuid=87657093-1800-0000-7813-3cd4280a0000 pid=2600 /usr/bin/chmod guuid=a3e4e784-1800-0000-7813-3cd4010a0000 pid=2561->guuid=87657093-1800-0000-7813-3cd4280a0000 pid=2600 execve guuid=0e33d193-1800-0000-7813-3cd42a0a0000 pid=2602 /usr/bin/dash guuid=a3e4e784-1800-0000-7813-3cd4010a0000 pid=2561->guuid=0e33d193-1800-0000-7813-3cd42a0a0000 pid=2602 clone b3bc708e-8ccc-5219-9688-8bb7f25e7035 213.209.143.64:80 guuid=e4263d85-1800-0000-7813-3cd4020a0000 pid=2562->b3bc708e-8ccc-5219-9688-8bb7f25e7035 send: 136B guuid=13201b8d-1800-0000-7813-3cd4170a0000 pid=2583->b3bc708e-8ccc-5219-9688-8bb7f25e7035 send: 136B
Threat name:
Script.Trojan.Malgent
Status:
Malicious
First seen:
2025-12-05 18:33:28 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8ed141ee728ea1767e4cfb4e505622124fb3eb01455f0772a6360c30d709e24e

(this sample)

  
Delivery method
Distributed via web download

Comments