MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 91bbcbce758e5f576644ecea54934a618efea85e32dd62fa1b149a4a52abf5ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 91bbcbce758e5f576644ecea54934a618efea85e32dd62fa1b149a4a52abf5ea
SHA3-384 hash: e24368b1f8cf3b7f17755f6c8a0fc62bc82b1b2db718346dbbafc44bd1e25a2c4dbcd5712ca82767a6d2e1146d606f4b
SHA1 hash: ffcbcc51dd9e61f0cbc3ee57d3a63dc6511ca7c6
MD5 hash: f215d1193490ff1fb70a7fb0d4fc5fc8
humanhash: tennis-six-washington-echo
File name:skidb.sh
Download: download sample
Signature Mirai
File size:186 bytes
First seen:2025-12-05 18:22:32 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:L08ND5yg/w8ZBBFSa+TSJarjKPJVtOVRXyg/pOdFSa5T69/KO:LdD55/w+2f+PJVty5/8MKO
TLSH T11FC0C9B8001E7585C084AF15B029305EF2A6475B21374740E9C830A2F84D521A232E50
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.64/splmips633397cf2ca1b26757c7f32fe2e980ea66f783becff9455e11ded00b20032417 Miraielf mirai ua-wget
http://213.209.143.64/splmpsl61d0e0c8b1e9fdf341c8bbaacc50fe6cc5c5f73d4b7cb0f80808e6fedbf70d3c Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-05T20:58:00Z UTC
Last seen:
2025-12-06T03:19:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=29420c65-1900-0000-ca48-9c6aa3090000 pid=2467 /usr/bin/sudo guuid=41c9ec66-1900-0000-ca48-9c6aaa090000 pid=2474 /tmp/sample.bin guuid=29420c65-1900-0000-ca48-9c6aa3090000 pid=2467->guuid=41c9ec66-1900-0000-ca48-9c6aaa090000 pid=2474 execve guuid=a8402567-1900-0000-ca48-9c6aab090000 pid=2475 /usr/bin/rm guuid=41c9ec66-1900-0000-ca48-9c6aaa090000 pid=2474->guuid=a8402567-1900-0000-ca48-9c6aab090000 pid=2475 execve guuid=f3698867-1900-0000-ca48-9c6aad090000 pid=2477 /usr/bin/wget net send-data write-file guuid=41c9ec66-1900-0000-ca48-9c6aaa090000 pid=2474->guuid=f3698867-1900-0000-ca48-9c6aad090000 pid=2477 execve guuid=2b69876f-1900-0000-ca48-9c6abb090000 pid=2491 /usr/bin/chmod guuid=41c9ec66-1900-0000-ca48-9c6aaa090000 pid=2474->guuid=2b69876f-1900-0000-ca48-9c6abb090000 pid=2491 execve guuid=9f5cc66f-1900-0000-ca48-9c6abd090000 pid=2493 /usr/bin/dash guuid=41c9ec66-1900-0000-ca48-9c6aaa090000 pid=2474->guuid=9f5cc66f-1900-0000-ca48-9c6abd090000 pid=2493 clone guuid=a3ed5d70-1900-0000-ca48-9c6abf090000 pid=2495 /usr/bin/rm guuid=41c9ec66-1900-0000-ca48-9c6aaa090000 pid=2474->guuid=a3ed5d70-1900-0000-ca48-9c6abf090000 pid=2495 execve guuid=8f34b570-1900-0000-ca48-9c6ac0090000 pid=2496 /usr/bin/wget net send-data write-file guuid=41c9ec66-1900-0000-ca48-9c6aaa090000 pid=2474->guuid=8f34b570-1900-0000-ca48-9c6ac0090000 pid=2496 execve guuid=209b1c75-1900-0000-ca48-9c6ac6090000 pid=2502 /usr/bin/chmod guuid=41c9ec66-1900-0000-ca48-9c6aaa090000 pid=2474->guuid=209b1c75-1900-0000-ca48-9c6ac6090000 pid=2502 execve guuid=b86f7075-1900-0000-ca48-9c6ac8090000 pid=2504 /usr/bin/dash guuid=41c9ec66-1900-0000-ca48-9c6aaa090000 pid=2474->guuid=b86f7075-1900-0000-ca48-9c6ac8090000 pid=2504 clone b3bc708e-8ccc-5219-9688-8bb7f25e7035 213.209.143.64:80 guuid=f3698867-1900-0000-ca48-9c6aad090000 pid=2477->b3bc708e-8ccc-5219-9688-8bb7f25e7035 send: 136B guuid=8f34b570-1900-0000-ca48-9c6ac0090000 pid=2496->b3bc708e-8ccc-5219-9688-8bb7f25e7035 send: 136B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-12-05 18:26:23 UTC
File Type:
Text (Shell)
AV detection:
6 of 38 (15.79%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 91bbcbce758e5f576644ecea54934a618efea85e32dd62fa1b149a4a52abf5ea

(this sample)

  
Delivery method
Distributed via web download

Comments