MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a40e30f4dc8c3e64937e8a2b8511ff6ad1304179de707fdd1fc5f355c046cb46. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: a40e30f4dc8c3e64937e8a2b8511ff6ad1304179de707fdd1fc5f355c046cb46
SHA3-384 hash: 6d45257221a2eeb803f3eea3ac3c27d49b5e4356dd8ca728f0f01a88ad03331a605e628fa713fc2de36a2d1a6bb3b2e6
SHA1 hash: cf69d384f9a00fc8a0ec957ddf7b0d78391c279e
MD5 hash: 4ec89417d07e36370f896a5b4181fc2d
humanhash: indigo-fourteen-stream-lemon
File name:tplinkr.sh
Download: download sample
Signature Mirai
File size:1'007 bytes
First seen:2026-05-24 11:51:11 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:QvQhBhE1Ja75briBFK1bEJf7aUriCFKebr:QvQhnBi7Z7i6X
TLSH T15A11279A28A536663598CECCF261EE05D086F9CF22956627FBC8752A7C842507816F06
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://92.42.100.131/meow/mips71336a558d000a7b075c59e9e365686a73581b799a73ce4ffb7415090e01b6c6 Miraielf mips mirai ua-wget
http://92.42.100.131/meow/mpslada8c6352285beb3d8bfbd45116af9433da8746f3fd34eca586dbf5dc107bd95 Miraielf mips mirai ua-wget
http://92.42.100.131/meow/armdeb6fc9e25f9e9df3006debc6415b5a85b10b31d9233b65e0e161a370364d31d Miraiarm elf mirai ua-wget
http://92.42.100.131/meow/arm55c3f43baef89d2042784be33b0fa6b814e6c03c285bfbb0033640709794f36c2 Miraiarm elf mirai ua-wget
http://92.42.100.131/meow/arm71c5080b6fa705f69758a8add633e3314f1953308ff68750be9455340bc91536b Miraiarm elf mirai ua-wget
http://92.42.100.131/meow/x86283878b622d6838d8bed8df3fc16b94eec9ea301bd8082027d4ec03be96d8a26 Miraielf mirai ua-wget x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-05-24T03:44:00Z UTC
Last seen:
2026-05-25T06:00:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=06ef6b78-1700-0000-c1db-9bbdb10d0000 pid=3505 /usr/bin/sudo guuid=a28d8c7a-1700-0000-c1db-9bbdb40d0000 pid=3508 /tmp/sample.bin guuid=06ef6b78-1700-0000-c1db-9bbdb10d0000 pid=3505->guuid=a28d8c7a-1700-0000-c1db-9bbdb40d0000 pid=3508 execve
Threat name:
Script-BAT.Worm.Mirai
Status:
Malicious
First seen:
2026-05-23 07:55:15 UTC
File Type:
Text (Shell)
AV detection:
12 of 36 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh a40e30f4dc8c3e64937e8a2b8511ff6ad1304179de707fdd1fc5f355c046cb46

(this sample)

  
Delivery method
Distributed via web download

Comments