MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2dbdae2cf27308d8dd73a031576c7ca1bdc45053f38e0054ef050be8236467af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2dbdae2cf27308d8dd73a031576c7ca1bdc45053f38e0054ef050be8236467af
SHA3-384 hash: 07359084b647f713b27450c77550d2b29c8cabba4b3179b4748838282c25aba9765b4b4244a10706d3f8a067e083568d
SHA1 hash: 060be82f17864c224b4635f4a774f4bb117f4833
MD5 hash: 233498cc485f3d9323470e0d74e313cd
humanhash: fifteen-tango-georgia-massachusetts
File name:mass.sh
Download: download sample
Signature Mirai
File size:3'520 bytes
First seen:2025-04-07 06:42:36 UTC
Last seen:2025-04-08 04:50:37 UTC
File type: sh
MIME type:text/plain
ssdeep 48:olpWxnNa8MFPMB3AQNrq20YENeRmAoENr4TmCFv:oKnN6PXQNAzfSS3Fv
TLSH T17271A9F87C716F3ECA8EDF40912188656C3BD4D129A18B05E47E24BAE6FCE05A47174B
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.39.207.117/nimips5b339544ba55c78bff25dbd5e737cd854d6c61d5ed3b1866d6d5fe110a8a9d7e Miraiddos elf mirai
http://185.39.207.117/mpsl77adfd58c50986b6d252a69e969fc4155ae57c9e5a7fe4e90e93526755a4ccde Gafgytddos elf gafgyt mirai
http://185.39.207.117/arm8856683950f423745d59b13c343024508084de08361fda0d42cdf9129e556d18 Miraiddos elf mirai
http://185.39.207.117/arm53a5c86a7631f29a6f599ef74a218dfcc9291aa525cd36fd06d2650364dd1b8d2 Gafgytddos elf gafgyt mirai
http://185.39.207.117/arm65f42803eab74d911c451ba243f92fa339781b0abb7c2cd77fe7840d087ce84f2 Gafgytgafgyt mirai ua-wget
http://185.39.207.117/arm74609c07c381e508ccdaf2ade1709ded444c168ca7333144d5cf91784b77b1b6b Miraimirai ua-wget
http://185.39.207.117/ppc053d6e52a3713feb0843e37934e9e516aeba14aa19d4de64d9c2bd3422ea586a Miraigafgyt mirai ua-wget
http://185.39.207.117/sh41e27d80628ff82735b1efb58c7ac743f7ecf533b6de2074d4cc5a2bdc5276ab8 Gafgytgafgyt mirai ua-wget
ftp://5.39.207.117:8021/nimipsn/an/an/a
ftp://5.39.207.117:8021/mpsln/an/an/a
ftp://5.39.207.117:8021/armn/an/an/a
ftp://5.39.207.117:8021/arm5n/an/an/a
ftp://5.39.207.117:8021/arm7n/an/an/a
ftp://5.39.207.117:8021/ppcn/an/an/a
ftp://5.39.207.117:8021/sh4n/an/an/a
ftp://5.39.207.117:8021/arm6n/an/an/a

Intelligence


File Origin
# of uploads :
11
# of downloads :
66
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Threat name:
Script-Shell.Downloader.MiraiA
Status:
Malicious
First seen:
2025-04-07 06:43:09 UTC
File Type:
Text
AV detection:
10 of 24 (41.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2dbdae2cf27308d8dd73a031576c7ca1bdc45053f38e0054ef050be8236467af

(this sample)

  
Delivery method
Distributed via web download

Comments