MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 96be545ce342f0eb9039c6a8b9f3da65a892431a89dfd0556fa2d7e17d4c4f41. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 96be545ce342f0eb9039c6a8b9f3da65a892431a89dfd0556fa2d7e17d4c4f41
SHA3-384 hash: 5dc64aee5beeffc8d68f5d2d084dd9771909b61eede4cbcf57a90151bd7b63563e678f7cfba2fd27cbdd9839f70993eb
SHA1 hash: 3ffcb388fe7aaaa56b8e432e2cddfd3a289bbc45
MD5 hash: fe9055450816f06c43da6ecc4b99c88c
humanhash: nevada-delta-pizza-shade
File name:w.sh
Download: download sample
Signature Mirai
File size:678 bytes
First seen:2025-08-01 12:40:00 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:7SSPA0SeapFE0SyTA0SXK9H0SwKA0Szl0Sdqn0SgFmP0Smjq0SYecAUR:71RjaBpkK9UCR4+N0WsNfRR
TLSH T1030162CF1A6772D28A8C6D94326BC850F646D3C4B0BB17CAEA844C7592D4611F0D8FB6
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://66.63.187.141/larm4a2f79b984b9120fdbe336b6801f4f745751be878d22fae1200951c3671af16dd MiraiDEU elf gafgyt geofenced mirai ua-wget
http://66.63.187.141/larm5def2ada2b4b3e56153d1acfb2ff5c0c6a5ef279a026899c8b98e7e79822ffcc5 MiraiDEU elf gafgyt geofenced mirai ua-wget
http://66.63.187.141/larm6dfc1186a9e6afbe40937682af7edb89f9fb2931bdf58946354b574014a89667c Miraielf mirai ua-wget
http://66.63.187.141/larm78ddeac81221f80b234e76ee908d12d1075adcacd05b541fde9c3001839f03dbc MiraiDEU elf geofenced mirai ua-wget
http://66.63.187.141/lsh46205a1abcf294fd929f9335c64c0a0b77c42e1604613d110a5a99ed419a26628 Miraielf mirai ua-wget
http://66.63.187.141/larca2d0fc472eca4df3beb5008a02ada4c140418c12aaac11b38b4d41a4244ebadb Miraielf gafgyt mirai ua-wget
http://66.63.187.141/lmips2371828e7734b156b6d1a53c54970ba164c6b28e4fdc6db385ae9549ccdc3c69 MiraiDEU elf geofenced mirai ua-wget
http://66.63.187.141/lmpsladb5177ed548c8ef27c0bd431503021d0e3af507b7f0f865967fa3a02059165e MiraiDEU elf geofenced mirai ua-wget
http://66.63.187.141/lspceab8c7128e534c5e3cf8fb995bdd16aa467ce786ad8ea834df2132870927eb4f Miraielf mirai ua-wget
http://66.63.187.141/lx86584342ec4fd8fefc59c7fbfbcab72f41f277439780500f25469b92ef30a67fab Miraielf gafgyt mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-08-01 12:30:53 UTC
File Type:
Text (Shell)
AV detection:
7 of 38 (18.42%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 96be545ce342f0eb9039c6a8b9f3da65a892431a89dfd0556fa2d7e17d4c4f41

(this sample)

  
Delivery method
Distributed via web download

Comments