MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 00f24eec43a1cdd502029173150e1553de4a552a77a1e719fd0232948b888dc3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 00f24eec43a1cdd502029173150e1553de4a552a77a1e719fd0232948b888dc3
SHA3-384 hash: ae14860fab170e97dbb9f9c2f5e987f9741890c34309eb2841a8109f3e14a285ec313fe79f082d86683cb4af0f571fab
SHA1 hash: 2f2fff71239a41ac4a2133215085e44e750520b2
MD5 hash: f17b69fa5b2c1e3fa96ae5bf4b86f6b3
humanhash: oxygen-salami-seventeen-berlin
File name:pop
Download: download sample
Signature Mirai
File size:1'038 bytes
First seen:2025-12-22 16:40:57 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:k7uSa7M5QSa7iSa7/Sa7V+Sa7PSa70Sa7bSa7XSa7kSa7beSh:knawHajaOaxa2axaaaGaZarh
TLSH T13D11845F01459D90C08CD43A37D2850DB4D44FCA187B0AA69EA600BE10F46CE7738E55
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/splarmef08459125a017651d2e87b64f1cdc320e46a496126b2b110e8b48b2a3d7f494 Miraielf mirai ua-wget
http://130.12.180.64/splarm5c418417d14f1d28b8ead43b923e549e0f795013c37abcc9ccf0a71467cc994ca Miraielf mirai ua-wget
http://130.12.180.64/splarm67acbab1fa1aa1ea342e5594a41423a529d656fd3aaf933fdaf8d687d1099146b Miraielf mirai ua-wget
http://130.12.180.64/splarm7bb53c80e89c03c910ee91eaa9a6a69b7834b835ee05c290cad9c86af29a821a9 Miraielf mirai ua-wget
http://130.12.180.64/splm68k42b0734f7c690a634bfa4c879517b455c51bf28616d532eeb89227b7f2a735fd Miraielf mirai ua-wget
http://130.12.180.64/splmips5827ab22c27a3de7ae37378f9fc1af2e2216b5b68787f2523a850f8b267f9989 Miraielf mirai ua-wget
http://130.12.180.64/splmpsl0b3a84e6b9026a574bf56df57ad63f769a28b7650b44cd589eea2cce8c681e85 Miraielf mirai ua-wget
http://130.12.180.64/splppcbfe80fbbec57ae28444d17b39641ecd3670d30e35afffafa088aead3346e645f Miraielf mirai ua-wget
http://130.12.180.64/splsh4c0e5e329988731ca2a595ca0a63e768f99c53dd7e6c9d078d01748479d31237c Miraielf mirai ua-wget
http://130.12.180.64/splspc1e53146545b3c903fc5ca0f5d7be95a2b241ca672f388a1e0aded9407d945768 Miraielf mirai ua-wget
http://130.12.180.64/splx861701951703ef39c28bc9b122408fe4f3db58dfd47a9086b055dc1f7a14139274 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-22T14:07:00Z UTC
Last seen:
2025-12-24T01:01:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=12466373-1900-0000-7d2f-10232d080000 pid=2093 /usr/bin/sudo guuid=39c99875-1900-0000-7d2f-102332080000 pid=2098 /tmp/sample.bin guuid=12466373-1900-0000-7d2f-10232d080000 pid=2093->guuid=39c99875-1900-0000-7d2f-102332080000 pid=2098 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-12-22 16:37:52 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 00f24eec43a1cdd502029173150e1553de4a552a77a1e719fd0232948b888dc3

(this sample)

  
Delivery method
Distributed via web download

Comments