MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 08c65eebf3c102885be33adb98df1c3b131c853227fdc98da8b5945901174c82. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 08c65eebf3c102885be33adb98df1c3b131c853227fdc98da8b5945901174c82
SHA3-384 hash: ff52a1f56d431f096244b777ae2ea73b8d4e5e52522180b13dd9b3430753fe1a163c8e27b681c9202f452a978dea0c19
SHA1 hash: db6717b5b69794ccd68de7a55dafc27ff82cc923
MD5 hash: eb50bef4cc3050b444955cc22dc96dd1
humanhash: seventeen-echo-chicken-arizona
File name:jaws
Download: download sample
Signature Mirai
File size:462 bytes
First seen:2026-05-31 13:57:22 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:yEdEqdwq4XmaZVgzd3/FFscll7qxObK4aF:ucHH7qx5F
TLSH T103F068921B90002B0FB548C4F0FDC714210523B65F24422C7D8EC92077C42D7F77386A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-28T02:55:00Z UTC
Last seen:
2026-05-31T12:43:00Z UTC
Hits:
~10
Detections:
Trojan-Downloader.Shell.Agent.bi
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-05-28 06:46:28 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Creates/modifies Cron job
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (2002721) amount of remote hosts
Creates a large amount of network flows
Family: Mirai
Malware Config
C2 Extraction:
terrabot.qzz.io
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 08c65eebf3c102885be33adb98df1c3b131c853227fdc98da8b5945901174c82

(this sample)

  
Delivery method
Distributed via web download

Comments