MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3de6338ef03006f2dca23d19704e4dca3b2823afc6a9a3fe5ac3b34bf65164e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: b3de6338ef03006f2dca23d19704e4dca3b2823afc6a9a3fe5ac3b34bf65164e
SHA3-384 hash: dd95155b4ae49c815da37bfe20ca1db08a88791842016e2fbf0e08c3071b4ecb3caafd9a85424015d746872f9de54834
SHA1 hash: 0277a188dade67c2a58c584609a1c56deec27d3b
MD5 hash: dbe03681f401b5903f71d0ef64b89d2d
humanhash: quebec-sad-nevada-shade
File name:3.sh
Download: download sample
Signature Mirai
File size:828 bytes
First seen:2026-08-03 05:00:22 UTC
Last seen:2026-08-03 16:27:52 UTC
File type: sh
MIME type:text/plain
ssdeep 24:3J30C9GfCjsYJNIxVVXK3K0ddfhFzTks23hp3Lt6KspyhMehThj:fN+bXwfvTkxxX6FkhMephj
TLSH T1B4018EDD405563061740CE25FC938C79642BA9EA317AE658F296BCF88DCC2092D396FF
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://31.56.209.153/nz/nz.arm3799f7600cb8a8e0582bacf44e373ab26f414f456ebeab4f0d6095a239647813 Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.arm57e149890b2a6443eaf6d2569c824d5d578c7f6f1a55452e552a452c4f930d922 Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.arm62b873c8e53c32d1947f8b0edbaea7fbf208ab1e202ff1cb07adde58d84894140 Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.arm71722375fa81d3e17092350c51ee6d7068c556c1d137c6d47aa027a18f84f4817 Miraiarm elf mirai opendir ua-wget
http://31.56.209.153/nz/nz.m68k1d87d05a3772a774667df44d1ebdec9a31eb460d8e6fb4ea4ed4ab9314dcaa78 Miraielf m68k mirai opendir ua-wget
http://31.56.209.153/nz/nz.mips99e62f03ab120c32193fa4170496e4fdcc80b4a952956874d7f3585c8a07dff7 Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.mpslb46800eb4eb3fbc6decc75bad5ebb5b400e27200c50da23199bd1f6a07537820 Miraielf mips mirai opendir ua-wget
http://31.56.209.153/nz/nz.ppc17e95878a491590bfdc24a82270bc318e59fd426a850dc219c65b711e9425f25 Miraielf mirai opendir PowerPC ua-wget
http://31.56.209.153/nz/nz.sh4443f9eafda59dc44d6da1c0d0363e02d3cee019405c872676ba45e11c03b39e8 Miraielf mirai opendir SuperH ua-wget
http://31.56.209.153/nz/nz.spc379d88307d819bdc60fd02afef40a9ff593bfb637f463daa21e42248b24fda5d Miraielf mirai opendir sparc ua-wget
http://31.56.209.153/nz/nz.x862c19cd42e8cbfd4f3b6d72ba98f4d90540bc711af6d7ccb7d94202257397b9c9 Miraielf mirai opendir ua-wget x86
http://31.56.209.153/nz/nz.x86_6498cf52a25bbc4e4287656eb28daaeb01bebfe6c7aa9a0af31f5f811b520cb783 Miraielf mirai opendir ua-wget x86

Intelligence


File Origin
# of uploads :
3
# of downloads :
69
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader
Status:
terminated
Behavior Graph:
%3 guuid=f6d42eed-1700-0000-8b3e-007b690c0000 pid=3177 /usr/bin/sudo guuid=fa64bcef-1700-0000-8b3e-007b6e0c0000 pid=3182 /tmp/sample.bin guuid=f6d42eed-1700-0000-8b3e-007b690c0000 pid=3177->guuid=fa64bcef-1700-0000-8b3e-007b6e0c0000 pid=3182 execve guuid=0db004f0-1700-0000-8b3e-007b6f0c0000 pid=3183 /usr/bin/curl net guuid=fa64bcef-1700-0000-8b3e-007b6e0c0000 pid=3182->guuid=0db004f0-1700-0000-8b3e-007b6f0c0000 pid=3183 execve 866c226d-28aa-5624-b4fe-d4dba4601813 31.56.209.153:80 guuid=0db004f0-1700-0000-8b3e-007b6f0c0000 pid=3183->866c226d-28aa-5624-b4fe-d4dba4601813 con
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-08-03 05:00:50 UTC
File Type:
Text (Shell)
AV detection:
11 of 36 (30.56%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b3de6338ef03006f2dca23d19704e4dca3b2823afc6a9a3fe5ac3b34bf65164e

(this sample)

  
Delivery method
Distributed via web download

Comments