MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e44fb8d77d6164400491e59cd7597484bfa73ae766b6da40b8b7c9bdfb2efd09. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: e44fb8d77d6164400491e59cd7597484bfa73ae766b6da40b8b7c9bdfb2efd09
SHA3-384 hash: 984fd7a23d933136f1ffd1db77c77f5068df4b236b437d35ed57cc9eb3a038c7743e6533406e1e2915c0c1d8342304c1
SHA1 hash: 1d10b32b3912f5ea6d268f7b4032685a915aa571
MD5 hash: 36e4ec757e73bcf2e3db965289dce646
humanhash: yankee-montana-mobile-harry
File name:e44fb8d77d6164400491e59cd7597484bfa73ae766b6da40b8b7c9bdfb2efd09
Download: download sample
Signature Mirai
File size:1'739 bytes
First seen:2026-06-28 19:18:06 UTC
Last seen:2026-06-29 13:33:43 UTC
File type: sh
MIME type:text/plain
ssdeep 24:oq5hrq23Prg1NIjaDFFsgklueWGjPVwFhGDo:oq5hrq23PrtaDFFsbupGjPVehGDo
TLSH T1AD31FDDD02119B01D61EEF99AB7EC998D036F8B29FC1CF5AEDC4847DCC886D97164A80
Magika txt
Reporter c2hunter
Tags:mirai sh wraith
URLMalware sample (SHA256 hash)SignatureTags
http://143.20.185.89/bins/px86428b93455b3493b726412fee9af76ff7d9d94853b99278f9aeda67014a19ce2b Miraimirai wraith
http://143.20.185.89/bins/px86_64n/an/aelf ua-wget
http://143.20.185.89/bins/parm7b00ef255f0cb798d40028afe2979f574808418e96351f6629a5e237c90233db5 Miraimirai wraith
http://143.20.185.89/bins/parm6c37a77a63582b02f69f1ea71d810d9aab433af52c37ec973650e82cecf7ba6ae Miraimirai wraith
http://143.20.185.89/bins/parm5a02da5e32c12a004632ef7adebc48188d9b57432f56fd453277dee5daf7e31a9 Miraielf mirai ua-wget
http://143.20.185.89/bins/parm4n/an/aelf ua-wget
http://143.20.185.89/bins/pmipsfcdba82f542e9da59bae98a4a4b10af7b92d2c866ce488e27444e28cb7f7b42c Miraielf mirai ua-wget
http://143.20.185.89/bins/pmipseln/an/aelf ua-wget
http://143.20.185.89/bins/psh4331633e511552d0e2bdb744f929bf678f3870cc21740380c104a4044b132a735 Miraielf mirai ua-wget
http://143.20.185.89/bins/pmpslba8434f48cde1b17f64eda516e3264d2651e6a622d3421078085e17c7d1becd0 Miraielf mirai ua-wget
http://143.20.185.89/bins/pppc4761538b84739ab042de484749e359402a9115faf3a4ffbf564d969095edd4eb Miraielf mirai ua-wget
http://143.20.185.89/bins/pm68k0998a444bd04a05fb3229e7a2eb0cc6baecd3373f666f0d44883261c41437159 Miraielf mirai ua-wget
http://143.20.185.89/bins/pi686n/an/aelf ua-wget
http://143.20.185.89/bins/pspcb326f6700c07600a0d1664eaf2a757b0bcea7b993114360e04d6f7f02a97c9dc Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
7
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
downloader mirai
Verdict:
Malicious
File Type:
text
First seen:
2026-06-28T18:04:00Z UTC
Last seen:
2026-06-29T12:58:00Z UTC
Hits:
~10
Gathering data
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-06-28 22:04:27 UTC
File Type:
Text (Shell)
AV detection:
13 of 36 (36.11%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh e44fb8d77d6164400491e59cd7597484bfa73ae766b6da40b8b7c9bdfb2efd09

(this sample)

Comments