MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 42f08d40a951bf5198ed4252d3fbf95842806d130e8e29aa9d1548148c9f06ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 42f08d40a951bf5198ed4252d3fbf95842806d130e8e29aa9d1548148c9f06ed
SHA3-384 hash: ca8838e16f3a88792c45b405a52349a037bad5f43129392f3306e2292372b8edd1696ded244d62fb97b23b8f72655600
SHA1 hash: 69f3ebd74a2348ffa08310b847c3aaa14c9b5bc5
MD5 hash: 1f12fcad7b3ba62cbecd853c568c4879
humanhash: jersey-vermont-salami-connecticut
File name:y
Download: download sample
File size:280 bytes
First seen:2026-01-24 06:16:46 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:/VJ+pUKUFAmVYKXhyqiYPEIAF+3FYKo1KXGVKhOXqIN3Ikr1IEx1IQ:/VJ+3mpQvYCKo1fghs3rN
TLSH T1B1D02B5CFC824C7AF0B848B8F6872547D10FD3181E8610CE6141111BB8F4D60A450C27
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=7b4600b9-1800-0000-fa54-8575f8090000 pid=2552 /usr/bin/sudo guuid=83fdd2ba-1800-0000-fa54-8575ff090000 pid=2559 /tmp/sample.bin guuid=7b4600b9-1800-0000-fa54-8575f8090000 pid=2552->guuid=83fdd2ba-1800-0000-fa54-8575ff090000 pid=2559 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.MiraiB
Status:
Malicious
First seen:
2026-01-18 05:26:25 UTC
File Type:
Text (Shell)
AV detection:
17 of 36 (47.22%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 42f08d40a951bf5198ed4252d3fbf95842806d130e8e29aa9d1548148c9f06ed

(this sample)

  
Delivery method
Distributed via web download

Comments