MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3851eee22e73e59e60d2d0e5bb46227538a26e24f4fc47312543f0a755c875a6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 3851eee22e73e59e60d2d0e5bb46227538a26e24f4fc47312543f0a755c875a6
SHA3-384 hash: 5b65caa1d598a9b39dc924d74436729877fbecaab8058ab42c51a68767c853e2dd3c9c7e0b9f834acf9ebefb8e9a938d
SHA1 hash: 179708c110adb5252a51f8d51cadbbdde4bde7fa
MD5 hash: c8d547e66f4a643aaeae42c6c9e8f1b0
humanhash: fifteen-crazy-pennsylvania-magazine
File name:weed
Download: download sample
Signature Mirai
File size:4'670 bytes
First seen:2024-12-22 12:35:46 UTC
Last seen:2025-01-18 19:10:50 UTC
File type: sh
MIME type:text/plain
ssdeep 96:1xelxBLfJcJKk5KN99z7NgF2/h19W+LTFv:GN3k5KN99z7KF2/hHW+LTFv
TLSH T191A102DC3A214B360C52DF99F263C662704ED4C60EE14F9965AD30BCAAFED88B120597
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.188.82.218/mips3609f8f3d45d41da70c11fc558eb7e37b6cae17d88c0179a4473d9991dad23cc Miraiddos elf HailBot mirai
http://103.188.82.218/mpsl647723492da9410480ea3337ea11c5e39d360305dea6a09eb661cce35b9a8b7e Gafgytddos elf gafgyt HailBot mirai
http://103.188.82.218/x86bbbd8da54939b309d5355cb37e5e526d0fd504634fe8e17d5b6a79635a951028 Gafgytddos elf gafgyt mirai
http://103.188.82.218/arm4a32a04f697a396c4d3008947a605c70b6a139d738fc4665e69457b219de59922 Miraiddos elf mirai
http://103.188.82.218/arm5f641c646b09a47bce17d7c55b7323bb67bf16c151269d125f9615455955ab201 Miraiddos elf HailBot mirai
http://103.188.82.218/arm61200075da17d87d7748d66dde17eceb0f75fb2a2a491da622db0cdd3a61077a1 Miraiddos elf HailBot mirai
http://103.188.82.218/arm71473bb781c7add63f1a618d9a1a3ae5ab9fc8e58d3c734fd0eea422ff7436b70 Miraiddos elf HailBot mirai

Intelligence


File Origin
# of uploads :
5
# of downloads :
113
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug busybox expand lolbin remote
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2024-12-22 12:41:07 UTC
File Type:
Text (Shell)
AV detection:
11 of 23 (47.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 3851eee22e73e59e60d2d0e5bb46227538a26e24f4fc47312543f0a755c875a6

(this sample)

  
Delivery method
Distributed via web download

Comments