MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 db1e2b7987eabf0eaeb3652b2e1a458e72890f32e6586017363e7566f0a02852. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: db1e2b7987eabf0eaeb3652b2e1a458e72890f32e6586017363e7566f0a02852
SHA3-384 hash: 15e493c17182c262e353d301ccf457fa9318fb582e567d36808026db4d9aa878e2a015372a0c95a1a56aa5242f6ccac6
SHA1 hash: 1c81a88c7272c0c8a1ed10192b1ff9a3fbedbb3f
MD5 hash: 59349edec2d01e0023d1100ffb264534
humanhash: football-paris-avocado-delaware
File name:lterouter
Download: download sample
Signature Mirai
File size:166 bytes
First seen:2026-04-25 20:43:13 UTC
Last seen:2026-04-26 18:11:47 UTC
File type: sh
MIME type:text/plain
ssdeep 3:O22exARg/LCQNLXm3FOdJ2GL9rSY/LCQNLXnBFS/TWUKT6VVI9LJdvvvF:O25y82GLNSnMTT6IZJn
TLSH T1CDC080C70731B51040577C197165116E52875B3038D4CF08F8AD05615E499C0F020B51
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.101.153/n2/mips69a3f8207de0386d28e743b27f532b3413d83f5b57b88213f633c6061fdb3361 Miraielf mips mirai ua-wget

Intelligence


File Origin
# of uploads :
133
# of downloads :
10
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=fdd788cf-1700-0000-8ac6-6da9a60e0000 pid=3750 /usr/bin/sudo guuid=87d332d2-1700-0000-8ac6-6da9af0e0000 pid=3759 /tmp/sample.bin guuid=fdd788cf-1700-0000-8ac6-6da9a60e0000 pid=3750->guuid=87d332d2-1700-0000-8ac6-6da9af0e0000 pid=3759 execve guuid=7fad99d2-1700-0000-8ac6-6da9b10e0000 pid=3761 /usr/bin/wget net send-data write-file guuid=87d332d2-1700-0000-8ac6-6da9af0e0000 pid=3759->guuid=7fad99d2-1700-0000-8ac6-6da9b10e0000 pid=3761 execve guuid=62ff53ea-1700-0000-8ac6-6da90d0f0000 pid=3853 /usr/bin/chmod guuid=87d332d2-1700-0000-8ac6-6da9af0e0000 pid=3759->guuid=62ff53ea-1700-0000-8ac6-6da90d0f0000 pid=3853 execve guuid=028aa4ea-1700-0000-8ac6-6da90f0f0000 pid=3855 /usr/bin/dash guuid=87d332d2-1700-0000-8ac6-6da9af0e0000 pid=3759->guuid=028aa4ea-1700-0000-8ac6-6da90f0f0000 pid=3855 clone guuid=933866eb-1700-0000-8ac6-6da9130f0000 pid=3859 /usr/bin/wget net send-data write-file guuid=87d332d2-1700-0000-8ac6-6da9af0e0000 pid=3759->guuid=933866eb-1700-0000-8ac6-6da9130f0000 pid=3859 execve guuid=a0d1f301-1800-0000-8ac6-6da96b0f0000 pid=3947 /usr/bin/chmod guuid=87d332d2-1700-0000-8ac6-6da9af0e0000 pid=3759->guuid=a0d1f301-1800-0000-8ac6-6da96b0f0000 pid=3947 execve guuid=20002a02-1800-0000-8ac6-6da96d0f0000 pid=3949 /usr/bin/dash guuid=87d332d2-1700-0000-8ac6-6da9af0e0000 pid=3759->guuid=20002a02-1800-0000-8ac6-6da96d0f0000 pid=3949 clone guuid=53d6dd02-1800-0000-8ac6-6da9720f0000 pid=3954 /usr/bin/rm delete-file guuid=87d332d2-1700-0000-8ac6-6da9af0e0000 pid=3759->guuid=53d6dd02-1800-0000-8ac6-6da9720f0000 pid=3954 execve 878b6614-6e66-5c2d-8323-6325abb24bfa 162.248.101.153:80 guuid=7fad99d2-1700-0000-8ac6-6da9b10e0000 pid=3761->878b6614-6e66-5c2d-8323-6325abb24bfa send: 137B guuid=933866eb-1700-0000-8ac6-6da9130f0000 pid=3859->878b6614-6e66-5c2d-8323-6325abb24bfa send: 137B
Gathering data
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-04-25 22:15:35 UTC
File Type:
Text (Shell)
AV detection:
2 of 24 (8.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh db1e2b7987eabf0eaeb3652b2e1a458e72890f32e6586017363e7566f0a02852

(this sample)

  
Delivery method
Distributed via web download

Comments