MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d22a081bd991a9b3f95a28c9f1000da56e09a14a0017dd158a8e84bfadfae236. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: d22a081bd991a9b3f95a28c9f1000da56e09a14a0017dd158a8e84bfadfae236
SHA3-384 hash: 89f95486b7f3ca75e29f903ef45de66cbc6025a05dd556adff5c882654e745515123a59a4c205db6e29cc58125e4c57e
SHA1 hash: 189afe529567d40c0e2080387edfb347e9788e83
MD5 hash: 21f8db9fcb6592cd202b617e728f9e08
humanhash: river-bulldog-georgia-romeo
File name:h.sh
Download: download sample
Signature Mirai
File size:637 bytes
First seen:2025-12-21 15:14:03 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3nKjQnqLqQnYNIl5zAQnB0LKjQn+taKAQn87nQnsCQnWFEQneWjQnCziAUR:3J3nKIqLlYNI7DYKI+tB3yksNCDSCzaR
TLSH T1F3F0448F325597E32F4C4D64F9AA540C7A8586D175700E24F57AE4A158D9300379CF75
Magika batch
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/arm26fab8de175aca6ef673bb6e6c59d86b913499b1415ea468714ed96c03c4826d Miraielf gafgyt mirai ua-wget
http://130.12.180.64/arm5dadbc08dc2068913a10a9def07534f92430f2eb186991c4466b9400f86455152 Miraielf gafgyt mirai ua-wget
http://130.12.180.64/arm6267f134519d86c6c219e437ba64132f8715c58bd67b116e7faca50ebe0ea2f37 Miraielf mirai ua-wget
http://130.12.180.64/arm7c6a54cd9814f2e3d9331776b118ba6025eb898e92a123355da5c057c4a081f0a Miraielf mirai ua-wget
http://130.12.180.64/sh425ccc358bb9e503cc426dfb4345a61d40a78f7f3e0dbfa5a2e54303f992bc497 Miraielf mirai ua-wget
http://130.12.180.64/arcn/an/aelf ua-wget
http://130.12.180.64/mips8853c8b568f92f75189381de18e994f0a311ee9b93ae96abdc1ce30ec61127a5 Miraielf mirai ua-wget
http://130.12.180.64/mipsln/an/aelf ua-wget
http://130.12.180.64/sparcn/an/aelf ua-wget
http://130.12.180.64/x8645203f7da056c3a55ebef72780b57e70bbc3b90cb32aed2be3adc3cffcc9e8be Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-21T13:35:00Z UTC
Last seen:
2025-12-21T15:02:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=ba5ccc10-1b00-0000-b3c6-249a570c0000 pid=3159 /usr/bin/sudo guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162 /tmp/sample.bin guuid=ba5ccc10-1b00-0000-b3c6-249a570c0000 pid=3159->guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162 execve guuid=27892913-1b00-0000-b3c6-249a5b0c0000 pid=3163 /usr/bin/curl net send-data guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=27892913-1b00-0000-b3c6-249a5b0c0000 pid=3163 execve guuid=dcb33b1d-1b00-0000-b3c6-249a660c0000 pid=3174 /usr/bin/chmod guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=dcb33b1d-1b00-0000-b3c6-249a660c0000 pid=3174 execve guuid=3501871d-1b00-0000-b3c6-249a680c0000 pid=3176 /usr/bin/dash guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=3501871d-1b00-0000-b3c6-249a680c0000 pid=3176 clone guuid=eb9d971d-1b00-0000-b3c6-249a690c0000 pid=3177 /usr/bin/curl net send-data guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=eb9d971d-1b00-0000-b3c6-249a690c0000 pid=3177 execve guuid=f1df8122-1b00-0000-b3c6-249a710c0000 pid=3185 /usr/bin/chmod guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=f1df8122-1b00-0000-b3c6-249a710c0000 pid=3185 execve guuid=0228d622-1b00-0000-b3c6-249a730c0000 pid=3187 /usr/bin/dash guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=0228d622-1b00-0000-b3c6-249a730c0000 pid=3187 clone guuid=0cf7e122-1b00-0000-b3c6-249a740c0000 pid=3188 /usr/bin/curl net send-data guuid=7891cf12-1b00-0000-b3c6-249a5a0c0000 pid=3162->guuid=0cf7e122-1b00-0000-b3c6-249a740c0000 pid=3188 execve f22fee75-ab34-540d-95fe-696883c6f4ad 130.12.180.64:80 guuid=27892913-1b00-0000-b3c6-249a5b0c0000 pid=3163->f22fee75-ab34-540d-95fe-696883c6f4ad send: 80B guuid=eb9d971d-1b00-0000-b3c6-249a690c0000 pid=3177->f22fee75-ab34-540d-95fe-696883c6f4ad send: 81B guuid=0cf7e122-1b00-0000-b3c6-249a740c0000 pid=3188->f22fee75-ab34-540d-95fe-696883c6f4ad send: 81B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-21 15:18:18 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d22a081bd991a9b3f95a28c9f1000da56e09a14a0017dd158a8e84bfadfae236

(this sample)

  
Delivery method
Distributed via web download

Comments