MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 14530afafda9a3011a70235f700da28bc7ac962da63fb752215ff01106a4d96d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 14530afafda9a3011a70235f700da28bc7ac962da63fb752215ff01106a4d96d
SHA3-384 hash: 1814b7b827bebd94642fd076ae8cfe8945c222a5f3d71ba8028b93d45b1175a526fba0821522547ff545673013c6c532
SHA1 hash: fa29e3c99f84ff8648c419a9c59091e1a82b8347
MD5 hash: 0f21cae740a41b420c85598ed83a8197
humanhash: failed-fanta-paris-michigan
File name:c.sh
Download: download sample
Signature Mirai
File size:778 bytes
First seen:2025-05-11 16:57:14 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:3J3jKawK6LlKoNI7vKoKwKI+K89K+UK7MKutBzKtKSzGKS9HR:JKawK8lKtvKoVKI+KMK+UKQKIzKtK3K6
TLSH T13F019B8E27B996CA9F0C8E1CB0AA898C764592C1F870EE15F81CD8F578D9605305CB7F
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://161.248.238.64/arm2f00e4fb95309d91ab81dc08851ccfd6680ef23469986904a31749c6d78e8559 Miraielf mirai
http://161.248.238.64/arm557aee870589a2560b3674f6038b69b19e6653d96cb97ed06291ca361868f3ef5 Miraielf mirai
http://161.248.238.64/arm69f53039e036b76911846e9da33ee5239f7123a6e7a845854e385a45532611354 Miraielf mirai
http://161.248.238.64/arm787a4f596f7843ab69e4cc37fcdbeb6f049adb36d90f3f8cef361897bca47ba58 Miraielf mirai
http://161.248.238.64/m68k08d599c98659bbf14d79de79202561ec33c2d39927461c796633949ba4c34d10 Miraielf mirai
http://161.248.238.64/mips46229e24b48ba7c1f238b66acb508be355544a303a93a3348adc8b80d819af59 Miraielf mirai
http://161.248.238.64/mpsl757e960e32d068988534c366cc408939e22e9081e657ccff7780aba90dc21649 Miraielf mirai
http://161.248.238.64/ppcafb123ebe8623dc644deceb092f170a3e4689a94f97323e94c2fbe28613ece9a Miraielf mirai
http://161.248.238.64/sh4a69dcd95a865f1af32e87bd70e4cf237a0ca249f0296fda1d407c5af690f7c5d Miraielf mirai
http://161.248.238.64/spcn/an/an/a
http://161.248.238.64/x86b099b8efafeef0b5d17747c9b2ab8813b40fa89b3d7db63d04fc253c7b7027b0 Miraielf mirai
http://161.248.238.64/x86_6437166e1ed7557cb7dbc2521f38f0e2f6e818f3025e4803cbb7503f591a84ad2f Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
mirai agent virus hype
Threat name:
Linux.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-05-11 16:58:10 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 14530afafda9a3011a70235f700da28bc7ac962da63fb752215ff01106a4d96d

(this sample)

  
Delivery method
Distributed via web download

Comments