MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1fa34b5dfb8f50388ac6387aa6ad8672e333b0d5dfa3e725f2ef0308091a10b8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 1fa34b5dfb8f50388ac6387aa6ad8672e333b0d5dfa3e725f2ef0308091a10b8
SHA3-384 hash: 748e05f61818dde32bcad6cde883578ea4f86471a747d27d362c327047a14df3930b369ba94ba58740209861624ca9ed
SHA1 hash: a4d446a37f85b52c162ba5535f7bea90efce44a9
MD5 hash: 22b9c3d02a4db16e4beb15251bda9069
humanhash: queen-washington-asparagus-pasta
File name:w.sh
Download: download sample
Signature Mirai
File size:948 bytes
First seen:2025-03-05 22:06:35 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:8MlctHcWAb/cWA3mcJlcWgcD1cWVgcZTcn20tlcrcy8:8MlcpcHb/cH3mcJlcWgcBcRc9cnZtlcM
TLSH T1AC11BCCF12A5F21048ACCD183066C418B669CBCDA8591F88DACC95F2F7C4D08B936F49
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.140.135/drea4b7a8882a502098f8b51aa06b9c215be250307c4e355f6f7073819d2562f23741 Miraielf mirai
http://176.65.140.135/vejfa55ebfaa628075bc3731fb8901e570c63163df5cbdf211ef452d0aeda6877247a8 Miraielf mirai
http://176.65.140.135/efea611c0436f0741bb589a1498e00793e89c2b1736bda1d576c12eb07fb2bf916383 Miraielf mirai
http://176.65.140.135/efefa7b15eca8497ee7c754ae99626c1b50afc2777afb0178f4b052aa7c75136c28c20 Miraielf mirai
http://176.65.140.135/eehah4e07bdb3a4a02e3678c2cf9e95e42526aa6833f916f9ba5a02f7f6e9b87b7a589 Miraielf mirai
http://176.65.140.135/rjfe686f327ab37d2c795344b9ece6b06744d3ec0b2fb0bffa4f3001c36080c1f1f2189 Miraielf mirai
http://176.65.140.135/vjwe68k80852be512eca4d9373bc31291353467c465b4ec941397289b8484aafe303ebd Miraielf mirai
http://176.65.140.135/efjepc533e7a32f1b2080de97659a6df20a672a988bd0c6e13988ea85c5f1a254a19f8 Miraielf mirai
http://176.65.140.135/jfeeps00937209bfc651fb263deaec059ea7eb0b40c3c224c66648d606946aab58723f Miraielf mirai
http://176.65.140.135/weje6491d2c341f6489f94dfa001ef9151e56fa6f8331b218733a8b6f4152f3685fe2a Miraielf mirai
http://176.65.140.135/rrrdsl5b6a3ddaea69d6a2b4bde62a543fefb22c055e6f3b0165d415d00e12c62bdb64 Miraielf mirai
http://176.65.140.135/bejv86c247239e9373395f8f485f350d1d38c78656d72c6dcf6bf61551fb32100aad0e Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
bash lolbin mirai remote
Threat name:
Document-HTML.Trojan.Vigorf
Status:
Malicious
First seen:
2025-03-05 22:07:12 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1fa34b5dfb8f50388ac6387aa6ad8672e333b0d5dfa3e725f2ef0308091a10b8

(this sample)

  
Delivery method
Distributed via web download

Comments