MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 db4f3093ee1bc5f6181b05f03156f8dd5605a7d92a24757b39e4b45505c63221. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: db4f3093ee1bc5f6181b05f03156f8dd5605a7d92a24757b39e4b45505c63221
SHA3-384 hash: 0ed9c70045e17c4d015ce4d3489cba31d08a7ae39724a1b93bcfac21f112e12c2aa0e6084055a35b00edbc298eae0989
SHA1 hash: 36c183959dad2f9eec82e9ae604270b72b7f5646
MD5 hash: 84367cb60c1187fe53b77ba0aba13d5b
humanhash: washington-purple-crazy-vermont
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'685 bytes
First seen:2026-02-06 13:59:24 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:v2sms096s2ZFacs/qFLcsAvmsg2sUNB9sWvsQesalsI4siusG9su2KsaQ:v2sms096s2VsQ4sAvmsg2sO7sWvsQesN
TLSH T19251898443A10B3A2EE2D51E72E5C89476B854EFFCE45F04A9DD7CBF409DF681848E4A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.59.248.53/bins/main_x86dca82e4cea1f26889f0c8cf8e24a6c8ecb054bf9236af12a45141748f69c0087 Miraicensys elf mirai ua-wget
http://5.59.248.53/bins/main_mips4d76fda4c4ab7e1099e7b007855ee285d14a3f19b83fa72b1297c636c67e9948 Miraielf mirai ua-wget
http://5.59.248.53/bins/main_arcn/an/aelf ua-wget
http://5.59.248.53/bins/main_i468n/an/aelf ua-wget
http://5.59.248.53/bins/main_i686n/an/aelf ua-wget
http://5.59.248.53/bins/main_x86_6427b8c721c1d3ea2d7554bb42c6ce55498cace81cda175268dca354aa5ddf047e Miraielf mirai ua-wget
http://5.59.248.53/bins/main_mpsl941ae9e1c7ef343db21c0d5f6217bc868f5be9844c887c7230f9cac7ffa5a28b Miraielf mirai ua-wget
http://5.59.248.53/bins/main_arm59367073b13b3ed8e71eb3d54650e6a7182eb55654f3a179e83cbac654c8cfb4 Miraielf mirai ua-wget
http://5.59.248.53/bins/main_arm576635f4d402449c8efdd24f8d43cde176c79cf73ed7e7c6b27c6f39ade0a0522 Miraielf mirai ua-wget
http://5.59.248.53/bins/main_arm67d7e14ffe814dae7aee3da258efd486905483bf4d8796ad2a0e54278f3d84da8 Miraielf mirai ua-wget
http://5.59.248.53/bins/main_arm77e8e8b30c50a6e9cfa4de1c9fd59a3a2c0854440e52dd15dff7c8de4a75d580e Miraicensys elf mirai ua-wget
http://5.59.248.53/bins/main_ppcf7f1fe7955d25ac8c44ae66aa20f6da36bd6eed17eae31f13ce919335ff18c54 Miraielf mirai ua-wget
http://5.59.248.53/bins/main_spcn/an/aelf ua-wget
http://5.59.248.53/bins/main_m68k4ae348c6bec7cba69b030a8556bb72c384923bda6b2aad78f91f0fad880c120e Miraielf mirai ua-wget
http://5.59.248.53/bins/main_sh4cd80ff8048e37c5867be108d2ac3302a51d10c3e32a738f573f4f1c3d7571f63 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Traces itself
Mirai
Mirai family
Malware Config
C2 Extraction:
5.59.248.53
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh db4f3093ee1bc5f6181b05f03156f8dd5605a7d92a24757b39e4b45505c63221

(this sample)

  
Delivery method
Distributed via web download

Comments