MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 432b33fdddfe4ebea5ff02ac28337c745c8ca5c66791fb26be68d1011016179d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 432b33fdddfe4ebea5ff02ac28337c745c8ca5c66791fb26be68d1011016179d
SHA3-384 hash: 8a6be93de6a81011d624ec5878306ad11754e8ca2b1a7daefa21439a2ab549b7d0eea140e751f096f9eb951edf0af635
SHA1 hash: 6983fef27c416a9ceb7980917eaefed25774c4bb
MD5 hash: 292bba2add1d328b97bc27ef9052fd05
humanhash: lake-uniform-neptune-mike
File name:c.sh
Download: download sample
Signature Mirai
File size:540 bytes
First seen:2025-04-17 19:39:35 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3H+jgHxjgYnHCjxNIl5BH7jna0LKOH8WjV/HNWjfKHR8jp95:3J3q8gYWxNI7hBKQVlCfmgH5
TLSH T1F5F05EBC2497AB472A05EF49F47AD6CDA03BE6EF5071CE61F05D3C3465A81107431B69
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.24/arm66183a14c02a02d7429597cdcf5f911a295f31d9ba4589abca84a6e794e10905 Gafgytelf ua-wget
http://213.209.143.24/arm56d04d6cc458082f1dd5233ac5b8b048c7d67c6a2a431e4750cf2b4366a0bdb74 Miraielf mirai
http://213.209.143.24/arm63b50d951810dc7e8bb7b9cf9d95d33ffaf55e50ca4ff15dded98a4198ecdef4e Miraielf mirai
http://213.209.143.24/arm75d11b9be5daa65fe010cc7900d5d5eead7f62a7885e862a5971a005856ae9878 Miraielf mirai
http://213.209.143.24/mips01453889de074520278d104c051ba80147706206ac12ccb4da2f07dc660872bb Miraielf mirai
http://213.209.143.24/mpslc081dbcab79688429efe181b099a18cd061bf0fd33da3d9f8b6bddf82bb99032 Miraielf mirai
http://213.209.143.24/x864a113a9f858520ad3dfa772fd30838a2a19855041941b35326a750d4c887089a Miraielf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
93.3%
Tags:
vmdetect agent hype sage
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Threat name:
Document-HTML.Trojan.Heuristic
Status:
Malicious
First seen:
2025-04-17 19:40:38 UTC
File Type:
Text
AV detection:
9 of 24 (37.50%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 432b33fdddfe4ebea5ff02ac28337c745c8ca5c66791fb26be68d1011016179d

(this sample)

  
Delivery method
Distributed via web download

Comments