MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 baf4004008576db571fa03d8581169e5164da6842d026fa58e61fd1191fbdbaf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: baf4004008576db571fa03d8581169e5164da6842d026fa58e61fd1191fbdbaf
SHA3-384 hash: f431effcd1bc9ce63a7ea10606da2677728ee7e3f2145ed7ac2cf9003677d696f7dcf066cb4138e6fe3cfff212a24dfa
SHA1 hash: f88100193cf0126ee80c9f607ca6652499c78240
MD5 hash: 434a0f5c2511f50bb537e752b7bacdb1
humanhash: michigan-muppet-nineteen-butter
File name:lterouter
Download: download sample
Signature Mirai
File size:160 bytes
First seen:2026-08-06 06:40:56 UTC
Last seen:2026-08-06 07:16:40 UTC
File type: sh
MIME type:text/plain
ssdeep 3:O22exARvUkZTK2Iq3FOdJ2GL9rSXUkZTK2IbBFS/TWUKT6VVI9LJdvvvF:O25sUktA2GLNSXUktQTT6IZJn
TLSH T1FCC08CF70A91700081C9ACA97257022E43A3863074B81F48F8D926A7CA8A940F818F11
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://191.96.11.84/n2/mips791be1e6f2839b929c5c6e65cfed9f27d16789e36443dfdc852051ceb53b5745 Miraielf mips mirai ua-wget

Intelligence


File Origin
# of uploads :
19
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader evasive
Status:
terminated
Behavior Graph:
%3 guuid=7cb44704-1900-0000-ad1f-c27adb0c0000 pid=3291 /usr/bin/sudo guuid=dbc4e805-1900-0000-ad1f-c27ae20c0000 pid=3298 /tmp/sample.bin guuid=7cb44704-1900-0000-ad1f-c27adb0c0000 pid=3291->guuid=dbc4e805-1900-0000-ad1f-c27ae20c0000 pid=3298 execve guuid=77e91906-1900-0000-ad1f-c27ae40c0000 pid=3300 /usr/bin/wget net send-data write-file guuid=dbc4e805-1900-0000-ad1f-c27ae20c0000 pid=3298->guuid=77e91906-1900-0000-ad1f-c27ae40c0000 pid=3300 execve guuid=8c426b33-1900-0000-ad1f-c27a4b0d0000 pid=3403 /usr/bin/chmod guuid=dbc4e805-1900-0000-ad1f-c27ae20c0000 pid=3298->guuid=8c426b33-1900-0000-ad1f-c27a4b0d0000 pid=3403 execve guuid=39ead033-1900-0000-ad1f-c27a4c0d0000 pid=3404 /usr/bin/dash guuid=dbc4e805-1900-0000-ad1f-c27ae20c0000 pid=3298->guuid=39ead033-1900-0000-ad1f-c27a4c0d0000 pid=3404 clone guuid=4673b334-1900-0000-ad1f-c27a510d0000 pid=3409 /usr/bin/wget net send-data write-file guuid=dbc4e805-1900-0000-ad1f-c27ae20c0000 pid=3298->guuid=4673b334-1900-0000-ad1f-c27a510d0000 pid=3409 execve guuid=4d2ea150-1900-0000-ad1f-c27a940d0000 pid=3476 /usr/bin/chmod guuid=dbc4e805-1900-0000-ad1f-c27ae20c0000 pid=3298->guuid=4d2ea150-1900-0000-ad1f-c27a940d0000 pid=3476 execve guuid=93ddfe50-1900-0000-ad1f-c27a960d0000 pid=3478 /usr/bin/dash guuid=dbc4e805-1900-0000-ad1f-c27ae20c0000 pid=3298->guuid=93ddfe50-1900-0000-ad1f-c27a960d0000 pid=3478 clone guuid=66e2c151-1900-0000-ad1f-c27a9a0d0000 pid=3482 /usr/bin/rm delete-file guuid=dbc4e805-1900-0000-ad1f-c27ae20c0000 pid=3298->guuid=66e2c151-1900-0000-ad1f-c27a9a0d0000 pid=3482 execve a0d5ebaf-0f90-538e-95c1-c39f8e673abb 191.96.11.84:80 guuid=77e91906-1900-0000-ad1f-c27ae40c0000 pid=3300->a0d5ebaf-0f90-538e-95c1-c39f8e673abb send: 134B guuid=4673b334-1900-0000-ad1f-c27a510d0000 pid=3409->a0d5ebaf-0f90-538e-95c1-c39f8e673abb send: 134B
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-08-06 07:17:31 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh baf4004008576db571fa03d8581169e5164da6842d026fa58e61fd1191fbdbaf

(this sample)

  
Delivery method
Distributed via web download

Comments