MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fbe254681cab293ab4ce8ff3cf19c7debc8f9c4edb48e52f01fd0ddc714aff7a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: fbe254681cab293ab4ce8ff3cf19c7debc8f9c4edb48e52f01fd0ddc714aff7a
SHA3-384 hash: e9c36f2951378f2dc83f7fc5ad05f5d5cb78eb46676169960590e9370a172657bbc5e5dc604ff622a7faea99af4ef56c
SHA1 hash: e740d17d91ad61091c127026cbd21f090535ebcc
MD5 hash: 28f97008b6fd9aa71d92cd2f91abe7c4
humanhash: maine-sixteen-red-moon
File name:li.sh
Download: download sample
Signature Mirai
File size:498 bytes
First seen:2025-12-05 18:23:56 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:St5/ebTZ6WY+x8t5/oaKZjXI+x8t5/+LzPEixx8t5/+sNELx8t5/+6NIF+KZEBF5:AhyT6hfJDh+Lsh+sZh+6NIbMDh+HG
TLSH T128F090B8E05E3E56420DAD4BF266080EA07783CE402BCF9AFC94B039619C5803076F84
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.64/mipsbd9c65cc309aa6ef706f8c9681de4cc39c32aa4291072722519b6baab55f349b Miraielf HailBot mirai ua-wget
http://213.209.143.64/mpsl3931c3450bcb95fb433d775ab37d3bb3cd3e610ae0a762c30711db8c1822b61f Miraielf mirai ua-wget
http://213.209.143.64/arm7effcd4169edfb6ee63f1ee384950a19fe8b3187e07a5e8849ef9e921dabb413 Miraielf mirai ua-wget
http://213.209.143.64/arm5c1a704fbb0fb0a441537da2e3571b21f697bc3cc371c985af7789737e3f3ef70 Miraielf mirai ua-wget
http://213.209.143.64/arm6d093e3e8633a4b992141153ba4a9189a0bcae6422e96141f6caeacf27dcd0655 Miraielf mirai ua-wget
http://213.209.143.64/arm7f6a697c5b3d4fd4a10ac00d2c1d95d5a42860aca0cd027f2c161c0a6a1103f0a Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-05T16:46:00Z UTC
Last seen:
2025-12-06T02:00:00Z UTC
Hits:
~10
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-12-05 18:29:21 UTC
File Type:
Text (Shell)
AV detection:
10 of 38 (26.32%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fbe254681cab293ab4ce8ff3cf19c7debc8f9c4edb48e52f01fd0ddc714aff7a

(this sample)

  
Delivery method
Distributed via web download

Comments