MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 29d23ce570c0a01a779615a73d3c2f1887816cd7ad54f80815abec15e56b55d4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 29d23ce570c0a01a779615a73d3c2f1887816cd7ad54f80815abec15e56b55d4
SHA3-384 hash: 46607e05e8b6ec04ccef550f60af3b02269e4237489b0d87cc37bc0e8068d7a0fb5b0058ec3074222d8fbfe0381d6859
SHA1 hash: b31f3c5c4ffaf17b42fa2c8cbe8b74fa75882752
MD5 hash: 1e22af2cfd226674c24cff450d5d9acd
humanhash: cola-ink-purple-fix
File name:weed
Download: download sample
Signature Mirai
File size:1'028 bytes
First seen:2025-12-21 15:14:40 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:k7zJOa7M5tJOa7nJOa7EJOa7VDJOa7UJOa7BJOa7wJOa7sJOa7xJOa7bjJOf:kEawkagaTa6a7a6avaLaiaof
TLSH T1251151DE0201ED90888CD43977D1800DB4C18FDA59BB0BB82E9601BE14F06CE7338E2A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/splarme3c748cae6c49c536fb41220772ca2c9e8d15afb34de9ccf9d63e3becdcb037f Miraielf gafgyt mirai ua-wget
http://130.12.180.64/splarm54877b50dae39c0d329442cf951aa544c99c3735bd2e04a43d639a35e108a8b6c Miraielf gafgyt mirai ua-wget
http://130.12.180.64/splarm69f3c038722a236bae610bcd2010d210d07be594cbabccb3529d89359e3f696ca Miraielf mirai ua-wget
http://130.12.180.64/splarm757ad94f6a0019ae8852bac6530147b717e2bfaed768600c658c44346357c4554 Miraielf mirai ua-wget
http://130.12.180.64/splm68k5a1d924f81f15da4e3b1e7bc1f350c3b25697babf91bc509479197cb524d727d Miraielf mirai ua-wget
http://130.12.180.64/splmips4a3b75e3f968337924dfc92ac11b62ec56ce5fd449e0e0d3e3dfd50273c9d3d6 Miraielf mirai ua-wget
http://130.12.180.64/splmpsl5a8d30683a937ecf56f6e06cf1f9eb7c9de187e68b4ba1d214eae22a5f1e5bec Miraielf mirai ua-wget
http://130.12.180.64/splppc35a66a7d28203ad8c60f54be62d6dd64259908d8739a2dde01c17ff5e40f4409 Miraielf mirai ua-wget
http://130.12.180.64/splsh47bafb063fde2bdf45b581d7e9c5aa70c560cacc9f4bda83d50efd0e26dbc808a Miraielf mirai ua-wget
http://130.12.180.64/splspc6b0d6def84c8ba20fc7e2bc65c2daefc1b6d5cfe2e9873e1f78171bbaa405d72 Miraielf mirai ua-wget
http://130.12.180.64/splx86b9506abc4e3cb1470df2036977c93f5c220b198a37e1a84a6a04a1ea736dda8b Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-21T12:31:00Z UTC
Last seen:
2025-12-23T12:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=7b757d0c-1f00-0000-4844-8f410e0c0000 pid=3086 /usr/bin/sudo guuid=987a1b0f-1f00-0000-4844-8f41140c0000 pid=3092 /tmp/sample.bin guuid=7b757d0c-1f00-0000-4844-8f410e0c0000 pid=3086->guuid=987a1b0f-1f00-0000-4844-8f41140c0000 pid=3092 execve
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-21 15:38:19 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 29d23ce570c0a01a779615a73d3c2f1887816cd7ad54f80815abec15e56b55d4

(this sample)

  
Delivery method
Distributed via web download

Comments