MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 00cae2bf4d705018eaae458331caf0afbc13bd3ca6949b1bd039b8d8f5e62ac9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 00cae2bf4d705018eaae458331caf0afbc13bd3ca6949b1bd039b8d8f5e62ac9
SHA3-384 hash: 54c5cacd7fca776befe810fd91efe2642c77ace76b5152b28fb7e64a2133d39b7ef667539ad392dc9c0fbc69f339c598
SHA1 hash: fb8def951bfc2071d9e3ab78ad2489c73aba4736
MD5 hash: 873852594908ebecd40ab6c47e55525d
humanhash: twelve-chicken-nineteen-lima
File name:ssh.sh
Download: download sample
Signature Mirai
File size:703 bytes
First seen:2025-01-06 11:01:28 UTC
Last seen:2025-01-21 13:17:03 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:KGAkNZADziYyA7u/4AM8QpAd8YM6iAswIMRNItAwDwCBhAOUwn/6AswU:KXo+DeYTq/NsuzM2/IMRNIyxCQIn/r/U
TLSH T1DB0196CE2DA136464804DEC4256188409D07FEEEE5978B4EF4C8CE3A96C8A447126F8B
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://79.124.60.186/bins/res.x862d8fea0d43cdd0c083cf4d94267390fb91e82fc95af76865051f6d1d1214424e Mirai32-bit elf mirai x86-32
http://79.124.60.186/bins/res.sh483f662eb487b31559891eeaea6dd0c1ffa41cb0aa95aef6c202cc64c7e4ee7d8 Miraielf mirai opendir
http://79.124.60.186/bins/res.ppc3fea98738e49ec2c4ef82d2db62643550f83cd7728146db4365a74f8f64e91c7 Miraielf mirai opendir
http://79.124.60.186/bins/res.mpslee2fa2c8dd0670fca4e137cbb60675dcdc6148f799644667377273bb1e7d1ab4 Miraielf mirai opendir
http://79.124.60.186/bins/res.mips35a176fd312afaacdf56f8f53a2a4e4ecc83d737278744d0d0a9c057ddd602bc Miraielf mirai opendir
http://79.124.60.186/bins/res.arm7c74dde32c0a93bb5ec5cc8457d88e9d3d4d4eeb83343c573e7d6b3669d695621 Miraielf mirai opendir
http://79.124.60.186/bins/res.arm6eff81e483d964da558eb9214e743b85ea4b4cd8f0c24f4c0c1638f8f6bb557bc Miraielf mirai opendir
http://79.124.60.186/bins/res.arm5b893ec14f82f0111a82adb81c4ff326af075a594f9ed4443eb0de2346ef03aaf Miraielf mirai opendir
http://79.124.60.186/bins/res.arm368d9c9d203dc9e6047e7f00c6c92cfdbb845348bc7516dfd0569ed3cda16f1c Miraielf mirai opendir

Intelligence


File Origin
# of uploads :
2
# of downloads :
96
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug
Result
Verdict:
UNKNOWN
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2025-01-06 11:02:04 UTC
File Type:
Text (Shell)
AV detection:
10 of 38 (26.32%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 00cae2bf4d705018eaae458331caf0afbc13bd3ca6949b1bd039b8d8f5e62ac9

(this sample)

  
Delivery method
Distributed via web download

Comments