MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0cbc063cbb926110df491c8c0a9c10b73668592c05c37a59f50b8063ad2a9738. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0cbc063cbb926110df491c8c0a9c10b73668592c05c37a59f50b8063ad2a9738
SHA3-384 hash: f94b388f850e13c834e3478efd34b18848b3432ba6700890e1b96321baa5bce0f826130549ca9dbe6133a3498abd7dec
SHA1 hash: 8cbe30497b681298805d5a000fdd27fce9ef6704
MD5 hash: 96af444eee358de34edaee4a4817c414
humanhash: spring-earth-solar-double
File name:wget.sh
Download: download sample
Signature Mirai
File size:4'670 bytes
First seen:2024-12-11 07:06:19 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:1tLiBLymLFRdLOGLuYqLZDLOxXKr5mNuUpRhi0CYgVHCzjtRFWYtnQHEehbgQG5B:1xENFLrFcVOY505pzHBgRCtR9u2/TFv
TLSH T19CA1C19A39612F328D11EF15F373C5697092A0C504B08F39A6AD70BCE9BED58FE10667
Magika shell
Reporter abuse_ch
Tags:Hailbot HailCock HailCockBotnet mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug busybox expand lolbin remote
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2024-12-11 07:07:10 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0cbc063cbb926110df491c8c0a9c10b73668592c05c37a59f50b8063ad2a9738

(this sample)

  
Delivery method
Distributed via web download

Comments