MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 afaea86058dc0a8475b6a07a7404e37624cf8a70aa9fb9f3a2038ec61862eb4c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: afaea86058dc0a8475b6a07a7404e37624cf8a70aa9fb9f3a2038ec61862eb4c
SHA3-384 hash: a44fbef00aaa562d94fb7c9be84559e4dee60c400635e43fd07b8f13d8f98d138302e52e72c74f9d42b7ce6623ebc5a5
SHA1 hash: eaea1966505cca62e2f950acb02abe79aba35cf2
MD5 hash: 10c1d25dfd571af943ee6193731c56fb
humanhash: seventeen-yankee-jupiter-don
File name:c.sh
Download: download sample
Signature Mirai
File size:912 bytes
First seen:2026-07-26 21:11:55 UTC
Last seen:2026-08-02 04:32:27 UTC
File type: sh
MIME type:text/plain
ssdeep 24:3J30C9GHjsFJNIxKVXKn0ydfh6zTks20hp3AtZEsGyhOfThlHA:fQDCXJeqTkxiAZTjhGhlg
TLSH T15A11B2DA4118A3461B488D14FC5B8C3D796B96E67136E514B286F8F48DCC2052D39FEF
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://31.56.209.153/nz/nz.armb38b7d77a9aa85aa16630a3e94d3cf354f68a3a40d29235a37ce9f55e5d38326 Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.arm577b199ce132fa548e4ac57f8ef90beafe4c619b3257d1c0ca12a1ac414ecf0f1 Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.arm6804d8830744c3f429686379f84b6b6bbdccc8c5c05af2a443ad4a2e73026b19e Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.arm7131c71f16cb132c6258ddae86b6e21aca7c07b3cf50b1d2efb66ecb55af78fee Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.m68kb1e7123c09c5cc0d00ba274aa17f7f0c6b1871251063d071398d3199449115b9 Miraielf m68k mirai opendir ua-wget
http://31.56.209.153/nz/nz.mips7b651e4f66c0bcc2befa5a981caaf7ea1180b8bb530bb1e384ba42e70f097db1 Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.mpslf4af27bb0f0bcc102b0596a909c738fc5aa0956fed74010c0e314cac01d86323 Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.ppcbe0826d7b02fc8380b8ef9003d2e54c8602c7891c3db7b62fc6616f49244b9da Miraielf mirai opendir PowerPC ua-wget
http://31.56.209.153/nz/nz.sh4a9fc9779102c5ff1f6e03bc8d1880bb52ac7c0dfe543eb93c07aa28766e8a876 Miraielf mirai opendir SuperH ua-wget
http://31.56.209.153/nz/nz.spc465be896c32b979119f0995df5772237695442d4ac79bc9881df25b0d22035a2 Miraielf mirai opendir sparc ua-wget
http://31.56.209.153/nz/nz.x8686a98b0a9d3b4cba259ace302a120d0ed77561198f3e6a17b855f4ebd4bbbb50 Miraielf mirai opendir ua-wget x86
http://31.56.209.153/nz/nz.x86_645413190d593ced48661818bccc75ad1b7a582ec879e9d5980be9b0b0bc663379 Miraielf mirai opendir ua-wget x86

Intelligence


File Origin
# of uploads :
6
# of downloads :
81
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader mirai
Verdict:
Malicious
File Type:
ps1
First seen:
2026-07-26T19:35:00Z UTC
Last seen:
2026-07-27T03:33:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=181d1cea-1600-0000-ac8f-dd6ca50d0000 pid=3493 /usr/bin/sudo guuid=a8b91bed-1600-0000-ac8f-dd6cb20d0000 pid=3506 /tmp/sample.bin guuid=181d1cea-1600-0000-ac8f-dd6ca50d0000 pid=3493->guuid=a8b91bed-1600-0000-ac8f-dd6cb20d0000 pid=3506 execve guuid=6ee698ed-1600-0000-ac8f-dd6cb40d0000 pid=3508 /usr/bin/curl net guuid=a8b91bed-1600-0000-ac8f-dd6cb20d0000 pid=3506->guuid=6ee698ed-1600-0000-ac8f-dd6cb40d0000 pid=3508 execve 866c226d-28aa-5624-b4fe-d4dba4601813 31.56.209.153:80 guuid=6ee698ed-1600-0000-ac8f-dd6cb40d0000 pid=3508->866c226d-28aa-5624-b4fe-d4dba4601813 con
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-07-26 21:12:34 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh afaea86058dc0a8475b6a07a7404e37624cf8a70aa9fb9f3a2038ec61862eb4c

(this sample)

  
Delivery method
Distributed via web download

Comments