MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d4227631c8eeb36f738da95e8281487046a8939c9b8e4a193dfec887c2e30921. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: d4227631c8eeb36f738da95e8281487046a8939c9b8e4a193dfec887c2e30921
SHA3-384 hash: ae770fe453cf544a676279419905288322c7e497bef3f7d691396cc01bc987f933f9fd7b4b01e54e9d723986db0b47d9
SHA1 hash: fbc02b5d2ae96e4181684c0b56f27636ff60b94b
MD5 hash: 7cfe58932396d897291d83a502571f26
humanhash: football-delta-oregon-maryland
File name:ru.sh
Download: download sample
Signature Mirai
File size:4'905 bytes
First seen:2025-12-14 23:49:35 UTC
Last seen:2025-12-15 12:11:52 UTC
File type: sh
MIME type:text/plain
ssdeep 96:1xORHodbc/pX690uE73/ImtjkRfg7dX/wgEX5+4bcrKM5e:qzX690uE73wmtjkR47dX4bX5+4bcrKMs
TLSH T1B7A115EDB8711737CDE1AE29FA158D2F2042C2C48C66EF94E46D30BCB4ABE65A240905
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.94.208.162/z/89/mips1ef86f38b7e44a7511f09e4bec9a1da105e70db6d522467ac14b4ea42df632c9 Miraielf mirai ua-wget
http://158.94.208.162/z/89/mpslb3af651dbf2ffce881ed5539fcb7a3371f94f301eb4f7ac757d6aba63e5e1038 Miraielf mirai ua-wget
http://158.94.208.162/z/89/x86_649c033cf8304f0ed83cbba11c153b4fa29d766a90e57b1e8b715b9d25ef05ed76 Miraielf mirai ua-wget
http://158.94.208.162/z/89/arm4n/an/aelf ua-wget
http://158.94.208.162/z/89/arm571ecf29f0548ecb0051046067bf46b3966c596a554bde739db08900b38198918 Miraielf mirai ua-wget
http://158.94.208.162/z/89/arm628d8a15cfb38b9e56722fac60e7b53c84f53fcd678a62f67e82312be67b88bd7 Miraielf mirai ua-wget
http://158.94.208.162/z/89/arm78730e029d0f40e909494760198bd41b3a6aa44843a8968910cff20dea0fc35ca Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox medusa mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-14T16:55:00Z UTC
Last seen:
2025-12-16T11:57:00Z UTC
Hits:
~10
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-12-14 23:50:18 UTC
File Type:
Text (Shell)
AV detection:
12 of 23 (52.17%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d4227631c8eeb36f738da95e8281487046a8939c9b8e4a193dfec887c2e30921

(this sample)

  
Delivery method
Distributed via web download

Comments