MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 99aae495cbefa91ff718d1cfef7bbcf3af5e9ac4df46da612f66d11a8562089e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 99aae495cbefa91ff718d1cfef7bbcf3af5e9ac4df46da612f66d11a8562089e
SHA3-384 hash: a7095dddcd1034eff43a1aa3bc3fa017174715ce0451e3c5537bc64da8b38da7220bc65076259433b141ed56aa7a46f5
SHA1 hash: 38689a2284ae319e456b526fcdfa9ee6ef49e94f
MD5 hash: 7dfbfdb5be7575f415aad7176b15632b
humanhash: spaghetti-colorado-mississippi-whiskey
File name:ssh.sh
Download: download sample
Signature Mirai
File size:1'963 bytes
First seen:2025-11-30 02:00:47 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:xbVbX/Bv/Bd3KuB5LBxvBB9pBz/BqiqeBZJRBpy2BtvnBZ7/BJHBtQ:plXYd/K4u0
TLSH T1E74141FE517456A2C0C8EE21FEA0D1D69C857BCEF2E42FB1964AAD31C8A9DB030117D5
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://212.85.24.46:82/irannet.x86_64829d6a7d2552d0675c67583b2ca5f387900014009acf5a8dbf0ce0fd2033cd18 Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.aarch64c13c0884dd95f92bbe6d223768fc66b99c4dcda935e989b9eee10df2c2fe0d50 Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.m68k8f16989a971cb30ba1aaa38899c9995c4ee028cca3c94bde669a7fb0bf33616c Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.mips6b6299d1004bff5762d6d60160154368d0ae0a364370cc684f57a2a65fa13f30 Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.mipsel3850e949caaa065013d3cd154c5aa29092ee72b5ce68a087e9079b60e89cb2e4 Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.powerpce4c6cae8de7e3a94f3211f79b35d8cf5760a4d93f8f62ab48ca7d17f978692d3 Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.sparc3cc343008709a3cd016bcc0e709f36eebbca19d6cd234d98df12bcf54242da04 Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.sh4a18d5070611e2965db17746f859bc5bd975c799b8c5bf45ade173721acb4ba2e Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.arc29c5fdc7b454c6b38753c8680729a695f27795bf9031c0de443b613753b96ee2 Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.i48644c0be5602fc0794d50542c38f161537ca46401866edd2130c855236a909bdeb Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.armv4l40e4741e1d2dd729186d95c205279ce1fef99d27bc188ebb1f409e40856296f9 Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.armv5l8704e88601ef5f71f2843dacbf7d373c9de68abce5f6961009e86cdc7dbb8b35 Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.armv6l730b9a633810475de79891eb9c75d6c643c5a297a59481a7a329e164eaa2d70c Miraielf geofenced mirai ua-wget USA
http://212.85.24.46:82/irannet.armv7l7447fcd33946aa9bac48e645c87c908306b0c6538e10059117f0dc81c087ad2c Miraielf geofenced mirai ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-11-30 02:01:22 UTC
AV detection:
10 of 36 (27.78%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 99aae495cbefa91ff718d1cfef7bbcf3af5e9ac4df46da612f66d11a8562089e

(this sample)

  
Delivery method
Distributed via web download

Comments