MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e3bbe8226e888e117cdee910260b056036ee5029969d5f6a7946ce739a0e03a5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e3bbe8226e888e117cdee910260b056036ee5029969d5f6a7946ce739a0e03a5
SHA3-384 hash: f280c4f954e41e1cae3b463f2514fb55f6ea3ff0cffa96d85038638f84e2e54519534ffad54fb38a4347de721c370b3b
SHA1 hash: aa94447c5c023f77aba2cb9c9ec6b95a249a763c
MD5 hash: 8b485349608c58a7a7af192feb182df7
humanhash: venus-beer-november-pizza
File name:cat.sh
Download: download sample
Signature Mirai
File size:2'080 bytes
First seen:2025-08-30 13:53:09 UTC
Last seen:2025-08-31 19:05:20 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:rhL8QoKtsozDZmYNf9b5SiHzbm5KZdtlYBoAdco9LRlD:rhnBZdED
TLSH T1A241C5C8D390CFD1C292CEA0B4A1D7C453FED5CABA92CBF1A44A1925E8CD940BC35729
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.248.150.68:84/x86_64b67f7fe1169e6c6139b92f3d3daee8ba1bb19b3c1c3267f29cbbd1a4f7d09b93 Miraielf geofenced mirai ua-wget USA
http://87.248.150.68:84/aarch64f38db67a038dec44df5b6d3e4a36b81f05574f7105da26bd75d64bd701ae1399 Miraielf mirai ua-wget
http://87.248.150.68:84/m68kc9328f788c095471ba7ba4a9bf702bcda6e5e7d20119da8db261279bd1333211 Miraielf geofenced mirai ua-wget USA
http://87.248.150.68:84/mips42fbc617be354079673bd2fe0ddca9980e834e631681cf5460cd87eb39e2391e Miraielf geofenced mips mirai ua-wget USA
http://87.248.150.68:84/mipsel10042c1b8692a8bf567a8be9a20f52b333aaeb79f5a60fb8ae9dc9a1a32bf323 Miraielf geofenced mips mirai ua-wget USA
http://87.248.150.68:84/powerpcc8393ef6fa63cb5e8df05f72037b6505bf7f5591fee32881a84c5fa639fc3da5 Miraielf geofenced mirai ua-wget USA
http://87.248.150.68:84/sparcb8e1835879b4aeb84fcaf19d9775adb28848bc031e0634df5f092cc27136fa5e Miraielf geofenced mirai ua-wget USA
http://87.248.150.68:84/sh4805f7622938b17b78660339b7c353edfb470ab1df42274c17a5b9a758a58fce6 Miraielf geofenced mirai ua-wget USA
http://87.248.150.68:84/arc20c7fe63ea801e2b60bd06e6568dfa1afb8f5a10950d06ce84269737d2e9e867 Miraielf geofenced mirai ua-wget USA
http://87.248.150.68:84/i486a7c7a4e2f42040cd94d2dc2104a93c86b2c5a83b7f113861a1184eda2752073f Miraielf geofenced mirai ua-wget USA
http://87.248.150.68:84/armv4l6f435eb2236d179a36333f714817b0e83c536600faf3a5559af200d25304df4f Miraielf gafgyt geofenced mirai ua-wget USA
http://87.248.150.68:84/armv5l6b895dd5abe5372171cb9571f6afb129c678559602d17730762cb86797a559a7 Miraielf gafgyt geofenced mirai ua-wget USA
http://87.248.150.68:84/armv6l06dfacf4bb22758e1743be816e982b9af64da11c4889ecf68009469a5e5b1b67 Miraielf geofenced mirai ua-wget USA
http://87.248.150.68:84/armv7l40b70454a2e34804db7ee8e6eed43bcf55f1bab7b6473bce7e1b0e6ae3a5aab7 Miraielf geofenced mirai ua-wget USA

Intelligence


File Origin
# of uploads :
2
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-08-30T11:10:00Z UTC
Last seen:
2025-08-30T11:10:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=9054f9b8-1900-0000-75a2-1e2bb70c0000 pid=3255 /usr/bin/sudo guuid=a4f4bdba-1900-0000-75a2-1e2bbd0c0000 pid=3261 /tmp/sample.bin guuid=9054f9b8-1900-0000-75a2-1e2bb70c0000 pid=3255->guuid=a4f4bdba-1900-0000-75a2-1e2bbd0c0000 pid=3261 execve guuid=c57d3cc1-1900-0000-75a2-1e2bcf0c0000 pid=3279 /usr/bin/wget guuid=a4f4bdba-1900-0000-75a2-1e2bbd0c0000 pid=3261->guuid=c57d3cc1-1900-0000-75a2-1e2bcf0c0000 pid=3279 execve
Verdict:
Malicious
Threat:
Script-Shell.Downloader.Heuristic
Threat name:
Document-HTML.Trojan.Heuristic
Status:
Malicious
First seen:
2025-08-30 13:56:38 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
credential_access discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Reads process memory
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh e3bbe8226e888e117cdee910260b056036ee5029969d5f6a7946ce739a0e03a5

(this sample)

Comments