MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1021d4629b5d66de532149303fc06281d118c87bc8a473a2ca98e3c87e07d6d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 1021d4629b5d66de532149303fc06281d118c87bc8a473a2ca98e3c87e07d6d3
SHA3-384 hash: a42dfd32f6c4dffe842f55189357c4c29b0f03d7667769a83f0c5f103339da6b5db7d8f74e4658bdec70674c7574aecd
SHA1 hash: f6949bce88472075e00a0d9c26e877959cd714d3
MD5 hash: 654cdddf04ee6be3efc808ae761c4559
humanhash: wolfram-blossom-sink-angel
File name:f.sh
Download: download sample
Signature Mirai
File size:375 bytes
First seen:2025-05-16 09:38:40 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:ebgfr3w5/KjUAFjbKTVpJjFIcMW8MIcMW8NsIV8aCTIcMGMIcMGNsIAaQu:3rWKIw+3JjecMl7cMleIea5cMG7cMGN9
TLSH T165E09BC502B0D93550495EE3B22455375BC5C9C99DC00E5875CA14B3D50DC14BD95F65
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.149.29.68/fmips079cff90b478d9516e612f4faa88dba0b809443c1b2ef030f9a19898a66b96b5 Miraicensys elf mirai ua-wget
http://103.149.29.68/fmpsl6f65ad8a1b85c698a402b8e7f489abaf067d23ee823474848bc178be67463802 Miraicensys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1021d4629b5d66de532149303fc06281d118c87bc8a473a2ca98e3c87e07d6d3

(this sample)

  
Delivery method
Distributed via web download

Comments