MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2aa36ffb8713cbd1abaef6651638902ac329a666b114e46bd767224747a8ef92. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2aa36ffb8713cbd1abaef6651638902ac329a666b114e46bd767224747a8ef92
SHA3-384 hash: 72079db3363bec450ad75b11957a9a10d14e6ac9f8a1ea5b47f95db88827c7d02aa54c42e74c084eaafaf4997c338c6e
SHA1 hash: 5cf2530dd1488e8d150d9031e3bca3e16a95c96a
MD5 hash: a1ec83fa8f7c13a8d72e6e626dd37bc0
humanhash: moon-alanine-ack-five
File name:w.sh
Download: download sample
Signature Mirai
File size:1'126 bytes
First seen:2025-12-09 06:53:26 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:8IvLc9c3NIZcAKHcCcTSWcZPIcncplcccFgc3HR:8IvLc9c0cA8cCcTSWcZAcncplcccWc3x
TLSH T1FA219ACA32B1A10074ED8D44729BE40CE1759AF1E9F51E19FCCDBC79EAC5A19B209F08
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.149.4/bins/Demon.armn/an/aelf ua-wget
http://176.65.149.4/bins/Demon.arm52df8a7ceba4b1648f689d6fcee1ee41d0ca9d7bdc611a65c6c3d80c17ca89cf0 Miraiarm elf geofenced mirai ua-wget USA
http://176.65.149.4/bins/Demon.arm6432420c135f443d59d76544b0d73e8eb530d9eae7648f7e838015fc706b1eb85 Miraiarm elf geofenced mirai ua-wget USA
http://176.65.149.4/bins/Demon.arm7997433271601e11425f3111cedeaf929a79b978d76fb6f5f399a0a03585aa40c Miraiarm elf geofenced mirai ua-wget USA
http://176.65.149.4/bins/Demon.m68kebee38f02beecf097992c4ea94e6b3dcf860349c4ba6b336bdc9c34f9dce7fd9 Gafgytelf gafgyt geofenced m68k mirai ua-wget USA
http://176.65.149.4/bins/Demon.mipsf60e4dfdc819a1ff12064faabbfd14a1ddf90ff5af5d9098718e5e611f0c8066 Miraielf geofenced mips mirai ua-wget USA
http://176.65.149.4/bins/Demon.mpsldfb90637ed3fa4e0d49aa81b02d16858a43c61a1541cd359f22b76dc06c97540 Miraielf geofenced mips mirai ua-wget USA
http://176.65.149.4/bins/Demon.ppc0dad2706685517f94f0c628f83fad5da211a30ea0621a032a467c958bd2efb66 Gafgytelf gafgyt geofenced mirai PowerPC ua-wget USA
http://176.65.149.4/bins/Demon.sh4b3af2b24fce06e94f7484946a35ee51944676105381934eb74681958ed0b03d2 Gafgytelf gafgyt geofenced mirai SuperH ua-wget USA
http://176.65.149.4/bins/Demon.spcn/an/aelf ua-wget
http://176.65.149.4/bins/Demon.x8687512d3762057f799ed76d9310d94c8ae3798623259cff636a68001958b7ed47 Miraielf geofenced mirai ua-wget USA x86
http://176.65.149.4/bins/Demon.x86_64n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-09T01:12:00Z UTC
Last seen:
2025-12-09T01:41:00Z UTC
Hits:
~10
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-09 03:21:59 UTC
File Type:
Text (Shell)
AV detection:
15 of 38 (39.47%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2aa36ffb8713cbd1abaef6651638902ac329a666b114e46bd767224747a8ef92

(this sample)

  
Delivery method
Distributed via web download

Comments