MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3de6338ef03006f2dca23d19704e4dca3b2823afc6a9a3fe5ac3b34bf65164e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b3de6338ef03006f2dca23d19704e4dca3b2823afc6a9a3fe5ac3b34bf65164e
SHA3-384 hash: dd95155b4ae49c815da37bfe20ca1db08a88791842016e2fbf0e08c3071b4ecb3caafd9a85424015d746872f9de54834
SHA1 hash: 0277a188dade67c2a58c584609a1c56deec27d3b
MD5 hash: dbe03681f401b5903f71d0ef64b89d2d
humanhash: quebec-sad-nevada-shade
File name:3.sh
Download: download sample
Signature Mirai
File size:828 bytes
First seen:2026-08-03 05:00:22 UTC
Last seen:2026-08-03 16:27:52 UTC
File type: sh
MIME type:text/plain
ssdeep 24:3J30C9GfCjsYJNIxVVXK3K0ddfhFzTks23hp3Lt6KspyhMehThj:fN+bXwfvTkxxX6FkhMephj
TLSH T1B4018EDD405563061740CE25FC938C79642BA9EA317AE658F296BCF88DCC2092D396FF
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://31.56.209.153/nz/nz.armb38b7d77a9aa85aa16630a3e94d3cf354f68a3a40d29235a37ce9f55e5d38326 Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.arm577b199ce132fa548e4ac57f8ef90beafe4c619b3257d1c0ca12a1ac414ecf0f1 Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.arm6804d8830744c3f429686379f84b6b6bbdccc8c5c05af2a443ad4a2e73026b19e Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.arm7131c71f16cb132c6258ddae86b6e21aca7c07b3cf50b1d2efb66ecb55af78fee Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.m68kb1e7123c09c5cc0d00ba274aa17f7f0c6b1871251063d071398d3199449115b9 Miraielf m68k mirai opendir ua-wget
http://31.56.209.153/nz/nz.mips7b651e4f66c0bcc2befa5a981caaf7ea1180b8bb530bb1e384ba42e70f097db1 Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.mpslf4af27bb0f0bcc102b0596a909c738fc5aa0956fed74010c0e314cac01d86323 Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.ppcbe0826d7b02fc8380b8ef9003d2e54c8602c7891c3db7b62fc6616f49244b9da Miraielf mirai opendir PowerPC ua-wget
http://31.56.209.153/nz/nz.sh4a9fc9779102c5ff1f6e03bc8d1880bb52ac7c0dfe543eb93c07aa28766e8a876 Miraielf mirai opendir SuperH ua-wget
http://31.56.209.153/nz/nz.spc465be896c32b979119f0995df5772237695442d4ac79bc9881df25b0d22035a2 Miraielf mirai opendir sparc ua-wget
http://31.56.209.153/nz/nz.x8686a98b0a9d3b4cba259ace302a120d0ed77561198f3e6a17b855f4ebd4bbbb50 Miraielf mirai opendir ua-wget x86
http://31.56.209.153/nz/nz.x86_645413190d593ced48661818bccc75ad1b7a582ec879e9d5980be9b0b0bc663379 Miraielf mirai opendir ua-wget x86

Intelligence


File Origin
# of uploads :
3
# of downloads :
78
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader
Verdict:
Malicious
File Type:
ps1
First seen:
2026-08-03T03:08:00Z UTC
Last seen:
2026-08-03T06:33:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=f6d42eed-1700-0000-8b3e-007b690c0000 pid=3177 /usr/bin/sudo guuid=fa64bcef-1700-0000-8b3e-007b6e0c0000 pid=3182 /tmp/sample.bin guuid=f6d42eed-1700-0000-8b3e-007b690c0000 pid=3177->guuid=fa64bcef-1700-0000-8b3e-007b6e0c0000 pid=3182 execve guuid=0db004f0-1700-0000-8b3e-007b6f0c0000 pid=3183 /usr/bin/curl net guuid=fa64bcef-1700-0000-8b3e-007b6e0c0000 pid=3182->guuid=0db004f0-1700-0000-8b3e-007b6f0c0000 pid=3183 execve 866c226d-28aa-5624-b4fe-d4dba4601813 31.56.209.153:80 guuid=0db004f0-1700-0000-8b3e-007b6f0c0000 pid=3183->866c226d-28aa-5624-b4fe-d4dba4601813 con
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-08-03 05:00:50 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b3de6338ef03006f2dca23d19704e4dca3b2823afc6a9a3fe5ac3b34bf65164e

(this sample)

  
Delivery method
Distributed via web download

Comments