MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b21c939fb54dc4d8a37e2fb80395fd6622fba5fa545dd67a74f81473330d7f1f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b21c939fb54dc4d8a37e2fb80395fd6622fba5fa545dd67a74f81473330d7f1f
SHA3-384 hash: b3fa0f9e51154cf88dacc5d2d93c7b707ee55de9752d68057ba81de0eb6631d377d25d7a7f310bbc592f1e62bc5a49ff
SHA1 hash: 2b00f8861b931eee5ea766869e17c1d4e88a774c
MD5 hash: e0fa2f9c53ca30a6eceb0a8940dda727
humanhash: fish-five-cat-quebec
File name:kla.sh
Download: download sample
Signature Mirai
File size:5'050 bytes
First seen:2026-06-09 20:11:52 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:IKhEcfEnsTE1O1mj1m580yGoAYQuSsE6e8E:d/
TLSH T1CAA15DC9139358707CE69C276169C814F6C9B68AEEC14F4490DCF4F9A48CF09BE42AB3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.32.41.16/bins/px86f8ab3ea192f76674ee80b18a803b93b9f3287758d6744e2f20517a470b260210 Miraielf mirai opendir ua-wget x86
http://89.32.41.16/bins/pmips36c5aea74bc2ad656c110809f9fb59ba3a26454ba977525da25dc817e43dd794 Miraielf mips mirai opendir ua-wget
http://89.32.41.16/bins/pmpslc7ab0d251c14f2caac2265830ecedcd9626e3fbbc0d88bf51fc48fc473139ecb Miraielf mips mirai opendir ua-wget
http://89.32.41.16/bins/parm85a4b1ae3ad71c491ad162e6ca992667c0656357d4806a240d4e2b3bb4b4163a Miraielf mirai ua-wget
http://89.32.41.16/bins/parm5233a0b0b247416afb807bb6b8d056f35b171f0c74f91841ef698288be172cb14 Miraielf mirai ua-wget
http://89.32.41.16/bins/parm6c9cba6112c73bd56fc11ff9d0ab1070e3e55de850461360f90d7b7af5ee3ebdc Miraiarm elf mirai opendir ua-wget
http://89.32.41.16/bins/parm73f2f76194be8ef9dcca6820a0ff688ea4c7995c970096cb4d5ff87cb3efa1af3 Miraielf mirai ua-wget
http://89.32.41.16/bins/pm68kn/an/aelf ua-wget
http://89.32.41.16/bins/psh4e31baaf0b4c81494cbc21047b396cfe0f8ad8d83592c28a829a55a2090f3c0e4 Miraielf mirai opendir SuperH ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-06-09 20:12:25 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b21c939fb54dc4d8a37e2fb80395fd6622fba5fa545dd67a74f81473330d7f1f

(this sample)

  
Delivery method
Distributed via web download

Comments