MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0df55cf208409ad731139351cea1ca22a003fbad4092d9ba514529206f2642b2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0df55cf208409ad731139351cea1ca22a003fbad4092d9ba514529206f2642b2
SHA3-384 hash: ac7174c09e164f1e385f03dc0b5884de758e5ea833254bc6a7522d1359b0bd8be2269d230a0523681475edb426b072d9
SHA1 hash: b9a380eac46b4ae33d879bccd1041cd86ade5aa4
MD5 hash: 556f03dacbca79a48a68d9ac2c1264d0
humanhash: georgia-island-fillet-one
File name:c.sh
Download: download sample
Signature Mirai
File size:793 bytes
First seen:2025-04-24 11:07:52 UTC
Last seen:2025-04-24 11:22:50 UTC
File type: sh
MIME type:text/plain
ssdeep 24:3J34RhDKFNI7MNKhBtBo71RyZbwhtoqqR:WRhDKwMNaJo71IZ0htoqq
TLSH T15201E1CE2166D6C21F0E8E1CF26A979CEA42EAC271708F21F01598F668EC5006568F77
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.77.240.231/arm8901880a311752e5fbd35d4b4d49b3688c7ac11b8d1daac136ce521442aa43bd Miraielf mirai
http://103.77.240.231/arm5f75e2ca9f1df6579aad4dffc021ea152ad18d7a85225035f12a7acba4e3ffec2 Miraielf mirai
http://103.77.240.231/arm6d4513eec03a905618779d8b8c3a64fb74c64fb5b482e2f7753c8028dc3411163 Miraielf mirai
http://103.77.240.231/arm7ad5545dd5d11b840a9283904da705708f4af037e5830d9357a033bce08f172b3 Miraielf mirai
http://103.77.240.231/sh49a3a6949bfc0682dc83a4e62493490cc1da075b437cd3683ed62d2485334e9c7 Miraielf mirai
http://103.77.240.231/arcn/an/an/a
http://103.77.240.231/mips4a1d31ec9168bde507f91d1c0c027ef551b1c75c07b52435605a53d65e21df22 Miraielf mirai
http://103.77.240.231/mipseln/an/an/a
http://103.77.240.231/sparcn/an/an/a
http://103.77.240.231/x86_64bd0a87a41d34faa2ac1ac95d2da225c14cd1f13c87d610ff76142edb87ee19d0 Miraielf mirai
http://103.77.240.231/i686n/an/an/a
http://103.77.240.231/i586n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
93
Origin country :
DE DE
Vendor Threat Intelligence
Threat name:
Linux.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-04-24 11:08:16 UTC
File Type:
Text
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0df55cf208409ad731139351cea1ca22a003fbad4092d9ba514529206f2642b2

(this sample)

  
Delivery method
Distributed via web download

Comments