MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 04b4f7018286e89d329a7dfb6c6fefcd3810aa19e003ca6d2b9fe1bd1974cd32. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 04b4f7018286e89d329a7dfb6c6fefcd3810aa19e003ca6d2b9fe1bd1974cd32
SHA3-384 hash: f8c88dba7b5dcc6b2eddfa7d111126b3e1368a80847ecb6b99beef178fa5efa9a0fae077435a8caeecd6729cf146cd3e
SHA1 hash: 92844d5165d97e657427d6f4b1f5f4fa923f2243
MD5 hash: c1bd4feb699f92db0207a26ffd62a45f
humanhash: earth-avocado-three-lion
File name:massload
Download: download sample
Signature Mirai
File size:598 bytes
First seen:2026-06-06 15:47:39 UTC
Last seen:2026-06-07 07:20:57 UTC
File type: sh
MIME type:text/plain
ssdeep 12:7duyXP0LKXjduyX1YEduyXicduyXcnduyXW5duyXVSf:7duTKXjduqYEdubcdu1nduZ5dum6
TLSH T19DF0F9DD986047720418EE1D2D3F9C26F1A0C2F9A2870B589DFC557EC8ED9747021A46
Magika html
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://vitacocoyougoloco.potassium.st/arm7e0ee4736e94b5f548312a48602b57f0e6cb9bd3867c31f0596873ae830c80c24 Miraiarm elf mirai ua-wget
http://vitacocoyougoloco.potassium.st/arm597ccd285196504320eeb5d398667c459fc9422567e9b68725490a21bf9234f51 Miraiarm elf mirai ua-wget
http://vitacocoyougoloco.potassium.st/mipsbe5053449eec9855acc145c2c268f177c035e6bc3066003ad37c472572f2bbd1 Miraielf mips mirai ua-wget
http://vitacocoyougoloco.potassium.st/mpslba8a21f445070d5ff3e03f88f22c8be7ba5fb76f2c5c07a1b83905722cd9b130 Miraielf mips mirai ua-wget
http://vitacocoyougoloco.potassium.st/x867b15e02eb1012a75718bdbb7e4eb296337f7ddab152a72caf81f4440abf101b5 Miraielf mirai ua-wget x86
http://vitacocoyougoloco.potassium.st/ppcd0e29f38e0a32fe5e2a054e431a5326e45f3f4424bd1a0a4e8b7b7f37e807335 Miraielf mirai PowerPC ua-wget

Intelligence


File Origin
# of uploads :
554
# of downloads :
5
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-06-06T14:24:00Z UTC
Last seen:
2026-06-06T14:45:00Z UTC
Hits:
~10
Gathering data
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-06-06 16:51:39 UTC
File Type:
Text (Shell)
AV detection:
15 of 36 (41.67%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 04b4f7018286e89d329a7dfb6c6fefcd3810aa19e003ca6d2b9fe1bd1974cd32

(this sample)

  
Delivery method
Distributed via web download

Comments