MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0f241b8952e3eee26badf4a1aec93744ac6faa26759f7cf87a3c58a2079109c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 0f241b8952e3eee26badf4a1aec93744ac6faa26759f7cf87a3c58a2079109c0
SHA3-384 hash: 77242ec68f1b97cb85ecff7340b65534104a3c85bbfd3d84f21d504d8e11be09071ff122f3151a13e8ab2a433b4c149b
SHA1 hash: 06fbfa9f4b37ea8824aa29863f96d080c0e82690
MD5 hash: 24672c0c32b9ea6bd60ca89e9f97686e
humanhash: alpha-may-carolina-twenty
File name:8UsA.sh
Download: download sample
Signature Mirai
File size:2'610 bytes
First seen:2025-04-26 13:53:28 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:yCiRMecCiRMTcCiRM6cCiRMZ9cCiRM9vcCiRMOcCiRMLCcCiRMDcCiRM9cCiRMsZ:JAr0b9fQLc7FsINFVgpT
TLSH T149518F84B3EB4518D9C95106E3B9C0D673DFF04B28A3DEA6C1A728F79478D8437886D6
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://156.253.227.62/8mips89909130bafd82ebfa359da02df7921cef4a56938dbaa655275bc5c27b6032ed7 Miraicensys elf gafgyt ua-wget
http://156.253.227.62/8mpsl8710c915f9801ecdf779d08feb73068f105d59984449f9f67560d2ab133f22407 Miraicensys elf mirai ua-wget
http://156.253.227.62/8sh48823c38c9e4b20afbb589f5019d43890096fa19f751a302998dc765fdc68e2f83 Gafgytcensys elf gafgyt ua-wget
http://156.253.227.62/8x868e1ea837b498ed596be48ac6f192305bb80dc48c154b42e40e154299c837e9c7c Miraicensys elf mirai ua-wget
http://156.253.227.62/8arm685fb8bd41a49f00e2ca9177b3142a3eb9a6f9cca5c577e7598ca99de56ee112a9 Miraicensys elf mirai ua-wget
http://156.253.227.62/8i6898a2d71b278c5a53608e0dbd3acc37625c2de754f273b703d2c54de7afaaa050 Miraicensys elf mirai ua-wget
http://156.253.227.62/8ppc8296c8daa54ebbc3be0fa2232dcb997a852efc825930b3ffcec132a65050e87e1 Gafgytcensys elf gafgyt ua-wget
http://156.253.227.62/8m68k8480ea65d5b48fd90b5ed6c93071812ba87fc5d68d88cf795396cb0ddb4a2df06 Gafgytcensys elf gafgyt ua-wget
http://156.253.227.62/8spc82347b9fde358e0d3a05c8cd98a422153c4792d8f3d206a3da86fec8825fc3772 Gafgytcensys elf gafgyt ua-wget
http://156.253.227.62/8arm48678db44c8f76ea1207e5f14235c6ec0700caca324ba9751581d0ca7fb6c0a0e0 Miraicensys elf mirai ua-wget
http://156.253.227.62/8arm58cd3e2e4fd40d987fd551ec0f6dcb2523beac652bc1e15322b3c2cc1b1d5b7bc4 Miraicensys elf gafgyt ua-wget
http://156.253.227.62/8arm785253c1d263e3690f26f0615fcbfc39c3945f00ad0b418996ca3a1ab79fde4d3c Miraicensys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
lolbin remote
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-04-26 13:54:28 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
UPX packed file
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0f241b8952e3eee26badf4a1aec93744ac6faa26759f7cf87a3c58a2079109c0

(this sample)

  
Delivery method
Distributed via web download

Comments