MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c68a8b04afec72d5ef5043e3479160bb8a15641e602c1128e5fac9a5a4fd7bd3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: c68a8b04afec72d5ef5043e3479160bb8a15641e602c1128e5fac9a5a4fd7bd3
SHA3-384 hash: 65ab0dc89d992f155a683d5c53afbfa44d520c873617401148e177a1911e4d937d13c21f8d09062652e808b00151faa8
SHA1 hash: ca3c06dbdab912cd0f533c6725ded17726129837
MD5 hash: 32651dc9a12f3b6972db2410107fb7a8
humanhash: coffee-batman-mockingbird-mango
File name:update.sh
Download: download sample
Signature Mirai
File size:2'076 bytes
First seen:2026-02-28 20:56:29 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vPspPlIePgjPnzPmEcPjrPtUthPz7vPvDPyZP4a:vPspPlIePgjPnzPmzPjrPCPPzLPvDPyR
TLSH T13241C0D4139906B0BC5789AA65FA5C44B4F892D758C44F6A8EFB3CB8414EE0836C07CB
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter juroots
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://51.255.131.179/bins/armn/an/an/a
http://51.255.131.179/bins/arm5be75c36a98af6797dfee6a7cde7b0547b460bae66bc8f37a8a949a91b433cb0b Miraimirai
http://51.255.131.179/bins/arm6a6f5c3ec37d0b63b6d17d93f2b9b5c1c17326191fc83779e436ff3b1ad27d748 Miraimirai
http://51.255.131.179/bins/arm7f56a8b969702c6e14fd6be7fa8b680273814c41410525cf514664d097554bc91 Miraimirai
http://51.255.131.179/bins/m68k3ef96e6c900626eb01a3b9984c9cf31356805d36b6076cb530aff301cc17e088 Miraimirai
http://51.255.131.179/bins/mips557ff907fb7b490f44577aecca1bfac899aa704f7bb8a91ec3ab9c8c5d5f83aa Miraimirai
http://51.255.131.179/bins/mpsle4a8695056cb8312a8fadc12c313c52b38903b89ef1a9cbef75db87e2f21a5cd Miraimirai
http://51.255.131.179/bins/ppc6b57867bf395c70c37fcb41483d0adf4c3a152cf343bce8b036bcc16f3537404 Miraimirai
http://51.255.131.179/bins/sh400993b24466a8ed1bc543d86a6dffb6f0e30a395a3555fc394418c9f12217f8d Miraimirai
http://51.255.131.179/bins/spc53df5003797d3b72668355dfe75699a9a685da1346d77731e4123555b2e2a112 Miraimirai
http://51.255.131.179/bins/x8646fc54d651998671c7c7a07a0f126e0f73fd21a4e3a7579c6dbc4e62e32c1a3d Miraimirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
US US
Vendor Threat Intelligence
No detections
Result
Gathering data
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-02-28 00:53:00 UTC
File Type:
Text (Shell)
AV detection:
22 of 36 (61.11%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c68a8b04afec72d5ef5043e3479160bb8a15641e602c1128e5fac9a5a4fd7bd3

(this sample)

  
Delivery method
Distributed via web download

Comments