MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fb4244859bda903361e41fbc226810e43e3278f9e8322ea69eec2e7e306d8ddb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: fb4244859bda903361e41fbc226810e43e3278f9e8322ea69eec2e7e306d8ddb
SHA3-384 hash: 2e8cfdf413b13ec542f5a798b5661d36d4d122b0e19c50d9e01568ee84a1590d6cfa211d80104c014b76f2cf9232cbb7
SHA1 hash: f34c495294be8b1ae663e11b2050770143dbaac0
MD5 hash: d28af637a9c236ec496de9e15290b294
humanhash: nevada-neptune-three-cold
File name:tbk
Download: download sample
Signature Mirai
File size:124 bytes
First seen:2025-09-13 06:37:52 UTC
Last seen:2025-09-13 09:30:33 UTC
File type: sh
MIME type:text/plain
ssdeep 3:GRFe6qLXzkWRGy1NRGNN3zSGNRGBT+K/RGrE42L:SXq8Wwy1Nwf1wl+K/w+L
TLSH T178B09299C01B5C0230E8CDA0D8BD42B0668AACB482C89AA4470F3E2D774CB103CBA150
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://109.205.213.5/kvariant.arm795c84d2cb01247b415f57c19c291ff83f7f2e5da207db1fe775ae6df6f8414fe Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=d78a0336-1600-0000-692c-e42fdf0b0000 pid=3039 /usr/bin/sudo guuid=24adf038-1600-0000-692c-e42fe80b0000 pid=3048 /tmp/sample.bin guuid=d78a0336-1600-0000-692c-e42fdf0b0000 pid=3039->guuid=24adf038-1600-0000-692c-e42fe80b0000 pid=3048 execve guuid=56124439-1600-0000-692c-e42fea0b0000 pid=3050 /usr/bin/wget net send-data write-file guuid=24adf038-1600-0000-692c-e42fe80b0000 pid=3048->guuid=56124439-1600-0000-692c-e42fea0b0000 pid=3050 execve guuid=f9dbe854-1600-0000-692c-e42f1c0c0000 pid=3100 /usr/bin/chmod guuid=24adf038-1600-0000-692c-e42fe80b0000 pid=3048->guuid=f9dbe854-1600-0000-692c-e42f1c0c0000 pid=3100 execve guuid=6bca2c55-1600-0000-692c-e42f1e0c0000 pid=3102 /usr/bin/dash guuid=24adf038-1600-0000-692c-e42fe80b0000 pid=3048->guuid=6bca2c55-1600-0000-692c-e42f1e0c0000 pid=3102 clone 9df19bce-d755-5940-91ff-d0e847757959 109.205.213.5:80 guuid=56124439-1600-0000-692c-e42fea0b0000 pid=3050->9df19bce-d755-5940-91ff-d0e847757959 send: 141B
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fb4244859bda903361e41fbc226810e43e3278f9e8322ea69eec2e7e306d8ddb

(this sample)

  
Delivery method
Distributed via web download

Comments