MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d22a081bd991a9b3f95a28c9f1000da56e09a14a0017dd158a8e84bfadfae236. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: d22a081bd991a9b3f95a28c9f1000da56e09a14a0017dd158a8e84bfadfae236
SHA3-384 hash: 89f95486b7f3ca75e29f903ef45de66cbc6025a05dd556adff5c882654e745515123a59a4c205db6e29cc58125e4c57e
SHA1 hash: 189afe529567d40c0e2080387edfb347e9788e83
MD5 hash: 21f8db9fcb6592cd202b617e728f9e08
humanhash: river-bulldog-georgia-romeo
File name:h.sh
Download: download sample
Signature Mirai
File size:637 bytes
First seen:2025-12-21 15:14:03 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3nKjQnqLqQnYNIl5zAQnB0LKjQn+taKAQn87nQnsCQnWFEQneWjQnCziAUR:3J3nKIqLlYNI7DYKI+tB3yksNCDSCzaR
TLSH T1F3F0448F325597E32F4C4D64F9AA540C7A8586D175700E24F57AE4A158D9300379CF75
Magika batch
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/arm1df127cac97ecff975ccdc39b1412068397b948821490910a9c0e3e11114e5f9 Miraielf mirai ua-wget
http://130.12.180.64/arm5f95187f0489f498c932ec698245e824170ca97d28405bf984fd89e9bb8488ff6 Miraielf mirai ua-wget
http://130.12.180.64/arm6ac713128acaa4ac62947c969c4fbb1b6c0707c99c1cb81328256f832483768b3 Miraielf mirai ua-wget
http://130.12.180.64/arm7f90e1a41579de7210c570506f9b4f7267e7a473d8a2b213c4d8ba63c947af70a Miraielf mirai ua-wget
http://130.12.180.64/sh459994b6ceca4298fe13f6ac8f22b9c944e3150f7e788734202399d558b3cbdca Miraielf mirai ua-wget
http://130.12.180.64/arcn/an/aelf ua-wget
http://130.12.180.64/mips67a7a0f8fc730923427afee83ea893b0f20779e37eeeaf88065ec1208bacefcc Miraielf mirai ua-wget
http://130.12.180.64/mipsln/an/aelf ua-wget
http://130.12.180.64/sparcn/an/aelf ua-wget
http://130.12.180.64/x869e3ff6dc222dcf4614389fbeaa0c4c30ec0f4166067fb80bf76f6453f7cf6296 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-21T13:35:00Z UTC
Last seen:
2025-12-21T15:02:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=ba5ccc10-1b00-0000-b3c6-249a570c0000 pid=3159 /usr/bin/sudo guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162 /tmp/sample.bin guuid=ba5ccc10-1b00-0000-b3c6-249a570c0000 pid=3159->guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162 execve guuid=27892913-1b00-0000-b3c6-249a5b0c0000 pid=3163 /usr/bin/curl net send-data guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=27892913-1b00-0000-b3c6-249a5b0c0000 pid=3163 execve guuid=dcb33b1d-1b00-0000-b3c6-249a660c0000 pid=3174 /usr/bin/chmod guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=dcb33b1d-1b00-0000-b3c6-249a660c0000 pid=3174 execve guuid=3501871d-1b00-0000-b3c6-249a680c0000 pid=3176 /usr/bin/dash guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=3501871d-1b00-0000-b3c6-249a680c0000 pid=3176 clone guuid=eb9d971d-1b00-0000-b3c6-249a690c0000 pid=3177 /usr/bin/curl net send-data guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=eb9d971d-1b00-0000-b3c6-249a690c0000 pid=3177 execve guuid=f1df8122-1b00-0000-b3c6-249a710c0000 pid=3185 /usr/bin/chmod guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=f1df8122-1b00-0000-b3c6-249a710c0000 pid=3185 execve guuid=0228d622-1b00-0000-b3c6-249a730c0000 pid=3187 /usr/bin/dash guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=0228d622-1b00-0000-b3c6-249a730c0000 pid=3187 clone guuid=0cf7e122-1b00-0000-b3c6-249a740c0000 pid=3188 /usr/bin/curl net send-data guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=0cf7e122-1b00-0000-b3c6-249a740c0000 pid=3188 execve f22fee75-ab34-540d-95fe-696883c6f4ad 130.12.180.64:80 guuid=27892913-1b00-0000-b3c6-249a5b0c0000 pid=3163->f22fee75-ab34-540d-95fe-696883c6f4ad send: 80B guuid=eb9d971d-1b00-0000-b3c6-249a690c0000 pid=3177->f22fee75-ab34-540d-95fe-696883c6f4ad send: 81B guuid=0cf7e122-1b00-0000-b3c6-249a740c0000 pid=3188->f22fee75-ab34-540d-95fe-696883c6f4ad send: 81B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-21 15:18:18 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d22a081bd991a9b3f95a28c9f1000da56e09a14a0017dd158a8e84bfadfae236

(this sample)

  
Delivery method
Distributed via web download

Comments