MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc4fb3c4d30d89cb8054f4ce5fff017d276f740fe84a0ef2718d61367f061bae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: fc4fb3c4d30d89cb8054f4ce5fff017d276f740fe84a0ef2718d61367f061bae
SHA3-384 hash: 31440ec9eb6494e198ed82f154531af8e55c40bcae860d9d8020a797182f4749bdc73b4a85969a5337f88fb8c0dc2da2
SHA1 hash: 391f2689aaff507ee196c277a3d5ef406cbdbbe8
MD5 hash: bfb659f06f6c4e142de7766862bc28cc
humanhash: hamper-delta-july-island
File name:c.sh
Download: download sample
Signature Mirai
File size:317 bytes
First seen:2026-08-26 05:38:43 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:3J3Qq9XTE823fKMBQQq9Xk5E8kWQBQQq9XjGNI1E8j+PAMBQQq9XH6E84KPGxBUA:3J3QAE8lAQQ15E8kFQQtNI1E86YAQQeP
TLSH T132E08CEA323066D337880E08B09BC104A5A1D1F26878C204FA2DC42B35B12C8EF18BB7
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://43.228.157.102/jah.arm431eb2f39e196a49b650a6e22a36c32c2fdad59987c2a356296ef4a08e7428c13 Miraielf ua-wget
http://43.228.157.102/jah.arm53fd8a35f03e8e8bd652539d4a86555c8e51eaae1509cf40871a15f4ce20ba508 Miraielf ua-wget
http://43.228.157.102/jah.arm64bf6e6698b385e763b231b278e3700f9c5cf4cc188f3edafd272af1c10cdb1e4 Miraielf mirai ua-wget
http://43.228.157.102/jah.arm73390ac845e39190004d9c34d799b8fb3ad09696c0dc4dc5c24190f60a001f474 Miraielf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
ps1
First seen:
2026-08-26T03:00:00Z UTC
Last seen:
2026-08-26T18:56:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=6722e0fb-1b00-0000-15d5-c5da1d0b0000 pid=2845 /usr/bin/sudo guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850 /tmp/sample.bin guuid=6722e0fb-1b00-0000-15d5-c5da1d0b0000 pid=2845->guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850 execve guuid=9468bffd-1b00-0000-15d5-c5da230b0000 pid=2851 /usr/bin/curl net send-data guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=9468bffd-1b00-0000-15d5-c5da230b0000 pid=2851 execve guuid=c81a5107-1c00-0000-15d5-c5da3d0b0000 pid=2877 /usr/bin/chmod guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=c81a5107-1c00-0000-15d5-c5da3d0b0000 pid=2877 execve guuid=7aafc507-1c00-0000-15d5-c5da400b0000 pid=2880 /usr/bin/dash guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=7aafc507-1c00-0000-15d5-c5da400b0000 pid=2880 clone guuid=61c0e307-1c00-0000-15d5-c5da410b0000 pid=2881 /usr/bin/curl net send-data guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=61c0e307-1c00-0000-15d5-c5da410b0000 pid=2881 execve guuid=cbdd240f-1c00-0000-15d5-c5da510b0000 pid=2897 /usr/bin/chmod guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=cbdd240f-1c00-0000-15d5-c5da510b0000 pid=2897 execve guuid=16abce0f-1c00-0000-15d5-c5da530b0000 pid=2899 /usr/bin/dash guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=16abce0f-1c00-0000-15d5-c5da530b0000 pid=2899 clone guuid=9d56ea0f-1c00-0000-15d5-c5da540b0000 pid=2900 /usr/bin/curl net send-data guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=9d56ea0f-1c00-0000-15d5-c5da540b0000 pid=2900 execve guuid=1ee62d16-1c00-0000-15d5-c5da640b0000 pid=2916 /usr/bin/chmod guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=1ee62d16-1c00-0000-15d5-c5da640b0000 pid=2916 execve guuid=37bb9416-1c00-0000-15d5-c5da650b0000 pid=2917 /usr/bin/dash guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=37bb9416-1c00-0000-15d5-c5da650b0000 pid=2917 clone guuid=e7b4b716-1c00-0000-15d5-c5da670b0000 pid=2919 /usr/bin/curl net send-data guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=e7b4b716-1c00-0000-15d5-c5da670b0000 pid=2919 execve guuid=4147a51e-1c00-0000-15d5-c5da780b0000 pid=2936 /usr/bin/chmod guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=4147a51e-1c00-0000-15d5-c5da780b0000 pid=2936 execve guuid=c3c4191f-1c00-0000-15d5-c5da7a0b0000 pid=2938 /usr/bin/dash guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=c3c4191f-1c00-0000-15d5-c5da7a0b0000 pid=2938 clone guuid=5f9b391f-1c00-0000-15d5-c5da7b0b0000 pid=2939 /usr/bin/rm guuid=8be68cfd-1b00-0000-15d5-c5da220b0000 pid=2850->guuid=5f9b391f-1c00-0000-15d5-c5da7b0b0000 pid=2939 execve e1f4c081-f54b-5379-9425-f2f4035ce6d7 43.228.157.102:80 guuid=9468bffd-1b00-0000-15d5-c5da230b0000 pid=2851->e1f4c081-f54b-5379-9425-f2f4035ce6d7 send: 86B guuid=61c0e307-1c00-0000-15d5-c5da410b0000 pid=2881->e1f4c081-f54b-5379-9425-f2f4035ce6d7 send: 86B guuid=9d56ea0f-1c00-0000-15d5-c5da540b0000 pid=2900->e1f4c081-f54b-5379-9425-f2f4035ce6d7 send: 86B guuid=e7b4b716-1c00-0000-15d5-c5da670b0000 pid=2919->e1f4c081-f54b-5379-9425-f2f4035ce6d7 send: 86B
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2026-08-26 05:39:35 UTC
File Type:
Text (Shell)
AV detection:
5 of 36 (13.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fc4fb3c4d30d89cb8054f4ce5fff017d276f740fe84a0ef2718d61367f061bae

(this sample)

  
Delivery method
Distributed via web download

Comments