MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1373f5b97ca92c777762fbc6638e75a21a2bfd0887d959e7bd8c6e37ff980568. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 1373f5b97ca92c777762fbc6638e75a21a2bfd0887d959e7bd8c6e37ff980568
SHA3-384 hash: a688608b6edcc9fb0fffba217ce0e394252bda2ea58bd6d9297c40f69ca36768a049ee9542aeb98d72633544b6b548b5
SHA1 hash: f4fdb2f0b2842c8a94a8f2757c40e11dadedaaca
MD5 hash: 208a150f8005f432991ea28dbe642896
humanhash: ohio-batman-ceiling-illinois
File name:bins.sh
Download: download sample
Signature Mirai
File size:10'830 bytes
First seen:2024-11-28 02:31:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:Yxp3B557pypKpjSucLnmLlF1Ln7cLVtVtVudp3E2EmEmxFz/TThZjRXrTLB5ULFb:cYAjSu1Fc9jTmxF1QySjTmxFjYAjSuQ
TLSH T1BE22E2C6229814125CB1CE1D2A682DE066587DC05CCD8D6F98CC299FC94DFFB749BEE8
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Threat name:
Linux.Downloader.Dwnlodr
Status:
Malicious
First seen:
2024-11-28 02:32:05 UTC
File Type:
Text (Shell)
AV detection:
16 of 38 (42.11%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalatio
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Creates/modifies Cron job
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Renames itself
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1373f5b97ca92c777762fbc6638e75a21a2bfd0887d959e7bd8c6e37ff980568

(this sample)

  
Delivery method
Distributed via web download

Comments