MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2c95ce1c6140c8c2db66382fbc0b832367891d03789b31bfef60f1e34b9250a5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 2c95ce1c6140c8c2db66382fbc0b832367891d03789b31bfef60f1e34b9250a5
SHA3-384 hash: 4b0e84634745aa503ce6aeb33d615cc41c00ad3e60d4a67b27f1e9889c2fa163f9e78f709b344568e847d3ec715ac09e
SHA1 hash: fde809f81c26db59c148255c0b60176c8971bc0c
MD5 hash: d7aac5b39f096043750096172ee9a84f
humanhash: equal-rugby-nitrogen-pluto
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'940 bytes
First seen:2024-12-17 11:17:35 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vp27E27N7hp2L26Gp2gj2zPp272KWp2t2oUp27t27o7Up2fa23bp2U29Rp2B2cgZ:vp27E27N7hp2L26Gp2gj2zPp272KWp2y
TLSH T1BC51E6C562444E382DA7AB17F7B6616C30C2D09219FA6F96D9C8BFF0865ED247140BA3
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
bashlite gafgyt mirai
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Mirai
Status:
Malicious
First seen:
2024-12-17 11:18:04 UTC
File Type:
Text (Shell)
AV detection:
18 of 24 (75.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Unexpected DNS network traffic destination
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2c95ce1c6140c8c2db66382fbc0b832367891d03789b31bfef60f1e34b9250a5

(this sample)

  
Delivery method
Distributed via web download

Comments