MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 39fcdc01acbbd57c12ddff3f2f70f5841543e0cf1cbeca13584a0185accacd89. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 39fcdc01acbbd57c12ddff3f2f70f5841543e0cf1cbeca13584a0185accacd89
SHA3-384 hash: e8c181e5614abe73c69a887dfb1fc2df462475ba1ed0b2e914a5e186206b0d0fd33923e21b20fccd15ec22a7f64344bb
SHA1 hash: 38ae5ff4327e568d0c66e49981fb9cedc03121e7
MD5 hash: 206214f9ca5ff85f80b18fd8f59c5efe
humanhash: oranges-carolina-alanine-purple
File name:massload
Download: download sample
Signature Mirai
File size:1'756 bytes
First seen:2025-04-27 01:44:45 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:QvZi4w8+ifJNnABw4RHfWCn1BxZ2k3nBbFnXuYhqJ:AZi7ihNABw4RHuC1BdFnXucqJ
TLSH T18931B498BE92DFE26F8ADF48F133D646F043DA9320508A156CA9207DCCBD9483035E4B
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://62.60.232.26/mips75d23e5b4962e274ea70858ceaf99e2ed221f064a76db13e36e0ea6a148cbe4a Miraicensys elf mirai ua-wget
http://62.60.232.26/mpsl44e90309c2c81241972ca9165f45c2216c39ce19ebc61046ee32cd6a581442e4 Miraicensys elf mirai ua-wget
http://62.60.232.26/arm4bbab0ec65b20410697236c7c408aeffe2cb61dde61cef633c8f77e50440a56be Miraicensys elf mirai ua-wget
http://62.60.232.26/arm5d4e1ad57d13ec2d8a908dc7cad39cc2cbe1e8c5f852e6d10e9ccdb20e98e1183 Miraicensys elf mirai ua-wget
http://62.60.232.26/arm7694a293cbe11bae17ae38512fa5aa78e7300fce10966c5c89e3e64daabda3672 Miraicensys elf mirai ua-wget
http://62.60.232.26/ppc7c6e99f2ec8b7baaccc7dacc5bfa6c8a93085a3374bea1e74dc41e58b2fc6b75 Miraicensys elf mirai ua-wget
http://62.60.232.26/sh43ef58015ea244b1a45e26b222b3aaa1f05441270e1c73f61f73712331221e0de Miraicensys elf mirai ua-wget
ftp://2.60.232.26:8021/mipsn/an/an/a
ftp://2.60.232.26:8021/mpsln/an/an/a
ftp://2.60.232.26:8021/arm4n/an/an/a
ftp://2.60.232.26:8021/arm5n/an/an/a
ftp://2.60.232.26:8021/arm7n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
101
Origin country :
DE DE
Vendor Threat Intelligence
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-04-27 07:10:30 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 39fcdc01acbbd57c12ddff3f2f70f5841543e0cf1cbeca13584a0185accacd89

(this sample)

  
Delivery method
Distributed via web download

Comments