MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 93646d8edfd148a906968160192b313ada5a60277d0529bb0c8c28bd54b92cd6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 93646d8edfd148a906968160192b313ada5a60277d0529bb0c8c28bd54b92cd6
SHA3-384 hash: 5de4a44c3863dcbd80fba2d252a9a6279cee10a11da0e2751725c5437cd9cb7c1f953049e603d1e779185a9fd831544f
SHA1 hash: ef1929c1d31fde3a74d8e59302510edf29b6dca7
MD5 hash: 419b4165ae1be6a35ab64c9630dcdfe9
humanhash: xray-fix-crazy-alanine
File name:run.sh
Download: download sample
Signature Mirai
File size:3'594 bytes
First seen:2025-10-18 00:00:31 UTC
Last seen:2025-10-18 16:06:00 UTC
File type: sh
MIME type:text/plain
ssdeep 48:EVuGRUYJgMl2VIfT81HCnv2FtGuZXg9hM37:EVuGRUYJgMl2/GuZt
TLSH T1F871868A1A448732DB048B2D23F07174A10F20C297FFCB92FD6055694EC595CB987F72
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.116.214/xnxnxnxnxnxnxnxnarcxnxn5ec1ecce4e59bee778a76d9fe73c2b1a7c8531d056257da9d632f8ff123a577a Miraielf mirai ua-wget
http://196.251.116.214/xnxnxnxnxnxnxnxnarmv4lxnxn09a8c9e56877681cb1895775dbb2336ae23e8c3754676d37baf913cdb67d15e8 Miraielf mirai
http://196.251.116.214/xnxnxnxnxnxnxnxnarmv5lxnxn408f7bd342f7c2f113c2535c103719ed14cb5b458a1b61bbe2c7faa8a718c3ba Miraielf mirai
http://196.251.116.214/xnxnxnxnxnxnxnxnarmv6lxnxn1daeded36693d6867c415808aa2b99fe62f29ed404063f6ef6d2a1c8119d4257 Miraielf mirai
http://196.251.116.214/xnxnxnxnxnxnxnxnarmv7lxnxn1f526cdfd0deb389802d7171ed6f34706df909ee4e99237954faa28696550449 Miraielf mirai
http://196.251.116.214/xnxnxnxnxnxnxnxni486xnxnn/an/aelf ua-wget
http://196.251.116.214/xnxnxnxnxnxnxnxni586xnxnd10f5fd9a2eeee7627a8e082e1c03211d5333bcf7e6b457ca2a78816c4bfbdec Miraielf mirai
http://196.251.116.214/xnxnxnxnxnxnxnxni686xnxnba44c3267db8f0495e6d6894aa2c6971fa95c8c9f03d97b6a6e1030c8df10683 Miraielf gafgyt mirai
http://196.251.116.214/xnxnxnxnxnxnxnxnm68kxnxnc8f5d1383cb5d8ba44ab05246bc22208943612b6e01977e5be2f09a458ce6cf6 Miraielf mirai
http://196.251.116.214/xnxnxnxnxnxnxnxnmipsxnxnn/an/aelf gafgyt
http://196.251.116.214/xnxnxnxnxnxnxnxnmipselxnxnn/an/aelf gafgyt
http://196.251.116.214/xnxnxnxnxnxnxnxnpowerpcxnxnn/an/aelf gafgyt
http://196.251.116.214/xnxnxnxnxnxnxnxnsh4xnxn87928558390d6b27693000ba9175f5c3fc2a9997e5abec0214eb9c57abab4c3d Miraielf mirai
http://196.251.116.214/xnxnxnxnxnxnxnxnsparcxnxnn/an/aelf ua-wget
http://196.251.116.214/xnxnxnxnxnxnxnxnx86_64xnxnn/an/aelf gafgyt mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-10-17T21:13:00Z UTC
Last seen:
2025-10-17T21:19:00Z UTC
Hits:
~10
Threat name:
Script-Shell.Trojan.Geninst
Status:
Malicious
First seen:
2025-10-17 23:54:23 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 93646d8edfd148a906968160192b313ada5a60277d0529bb0c8c28bd54b92cd6

(this sample)

  
Delivery method
Distributed via web download

Comments