MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 afaea86058dc0a8475b6a07a7404e37624cf8a70aa9fb9f3a2038ec61862eb4c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: afaea86058dc0a8475b6a07a7404e37624cf8a70aa9fb9f3a2038ec61862eb4c
SHA3-384 hash: a44fbef00aaa562d94fb7c9be84559e4dee60c400635e43fd07b8f13d8f98d138302e52e72c74f9d42b7ce6623ebc5a5
SHA1 hash: eaea1966505cca62e2f950acb02abe79aba35cf2
MD5 hash: 10c1d25dfd571af943ee6193731c56fb
humanhash: seventeen-yankee-jupiter-don
File name:c.sh
Download: download sample
Signature Mirai
File size:912 bytes
First seen:2026-07-26 21:11:55 UTC
Last seen:2026-07-27 08:43:05 UTC
File type: sh
MIME type:text/plain
ssdeep 24:3J30C9GHjsFJNIxKVXKn0ydfh6zTks20hp3AtZEsGyhOfThlHA:fQDCXJeqTkxiAZTjhGhlg
TLSH T15A11B2DA4118A3461B488D14FC5B8C3D796B96E67136E514B286F8F48DCC2052D39FEF
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://31.56.209.153/nz/nz.arm33ca2fc5dc3a455f87656c4796de77ced899dca05516389b6fdb3d0ae332e5c3 Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.arm54febc0a0ec7d79a38575b16f516c509fe25d1658d638993dd88b002f7906298e Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.arm67c523fd967fedaa44c4b03988cad297bd3e75bb411b666ead7ca276a7167fa21 Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.arm75a395c826117e12109b896d177ec44700cabb07a1ce61414c8358df7bbfc2b91 Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.m68k4e7f5ea43897e1e55cf846ed552d85e675f3bd1918d923127c6e1f37f8215cd2 Miraielf m68k mirai opendir ua-wget
http://31.56.209.153/nz/nz.mips8c0da2c903eaf8aeeaef90db5ff708313ff807673da59e70edf2a2569d77b332 Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.mpsl24984afdb5b42c21eb382f517edd16567f3b5001a9de15d59d78b266b67b15ae Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.ppc094fa6d0cb7ead6c425ad9d25d5619c322445f6a32578c973a668322d0f8ba8a Miraielf mirai opendir PowerPC ua-wget
http://31.56.209.153/nz/nz.sh4b69cd4d631af1acb5c2098ca4f0e5820bbb0de2d399d0d333f3d639a92aea6e4 Miraielf mirai opendir SuperH ua-wget
http://31.56.209.153/nz/nz.spc2cc810c31b632782b05d1eefd30b63f691e1b150239cb0261cf46b603ad2cbdb Miraielf mirai opendir sparc ua-wget
http://31.56.209.153/nz/nz.x86d1272c36897a7a76a35c07e47815c05a86b15138854438c104790e94d3e286b6 Miraielf mirai opendir ua-wget x86
http://31.56.209.153/nz/nz.x86_646ef41d3251793644f01d1a20990882ebf15abfb564a5e4001b4aca76242013dd Miraielf mirai opendir ua-wget x86

Intelligence


File Origin
# of uploads :
3
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader mirai
Verdict:
Malicious
File Type:
ps1
First seen:
2026-07-26T19:35:00Z UTC
Last seen:
2026-07-27T03:33:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=181d1cea-1600-0000-ac8f-dd6ca50d0000 pid=3493 /usr/bin/sudo guuid=a8b91bed-1600-0000-ac8f-dd6cb20d0000 pid=3506 /tmp/sample.bin guuid=181d1cea-1600-0000-ac8f-dd6ca50d0000 pid=3493->guuid=a8b91bed-1600-0000-ac8f-dd6cb20d0000 pid=3506 execve guuid=6ee698ed-1600-0000-ac8f-dd6cb40d0000 pid=3508 /usr/bin/curl net guuid=a8b91bed-1600-0000-ac8f-dd6cb20d0000 pid=3506->guuid=6ee698ed-1600-0000-ac8f-dd6cb40d0000 pid=3508 execve 866c226d-28aa-5624-b4fe-d4dba4601813 31.56.209.153:80 guuid=6ee698ed-1600-0000-ac8f-dd6cb40d0000 pid=3508->866c226d-28aa-5624-b4fe-d4dba4601813 con
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-07-26 21:12:34 UTC
File Type:
Text (Shell)
AV detection:
11 of 36 (30.56%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh afaea86058dc0a8475b6a07a7404e37624cf8a70aa9fb9f3a2038ec61862eb4c

(this sample)

  
Delivery method
Distributed via web download

Comments