MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 47123066fa8948fe17fe994ba445ad68d9ee388f54c04fddabd2a393ba7dd56f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 47123066fa8948fe17fe994ba445ad68d9ee388f54c04fddabd2a393ba7dd56f
SHA3-384 hash: d56420f5ecf273b44b9c63534fca39e566aefed5e2170f68276ac87f51b169ff49f26c0c7e2d203cad7a25b9065e1e76
SHA1 hash: 5c8b44ed0f9d58671a405a0b47f0ff28d6f0a51a
MD5 hash: 3ae55187d8b0344036e6b0590530703c
humanhash: single-carbon-massachusetts-don
File name:h.sh
Download: download sample
Signature Mirai
File size:647 bytes
First seen:2025-12-05 18:22:20 UTC
Last seen:2025-12-06 08:35:25 UTC
File type: sh
MIME type:text/plain
ssdeep 12:3J3Hh+0jQHh+sLqQHh+6NIl5zAQHh+H0LKjQHhFtaKAQHh++7nQHhVCQHhPFEQHS:3J3B+0k+sLL+6NI7t+SKkFtBR+owVz9G
TLSH T12AF0ECBD269E92E71E0C8E19F46E844C766787D6B071CA01B028B86475982103063F7A
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.64/arm7effcd4169edfb6ee63f1ee384950a19fe8b3187e07a5e8849ef9e921dabb413 Miraielf mirai ua-wget
http://213.209.143.64/arm5c1a704fbb0fb0a441537da2e3571b21f697bc3cc371c985af7789737e3f3ef70 Miraielf mirai ua-wget
http://213.209.143.64/arm6d093e3e8633a4b992141153ba4a9189a0bcae6422e96141f6caeacf27dcd0655 Miraielf mirai ua-wget
http://213.209.143.64/arm7f6a697c5b3d4fd4a10ac00d2c1d95d5a42860aca0cd027f2c161c0a6a1103f0a Miraielf mirai ua-wget
http://213.209.143.64/sh41bde6e79df9ba33e31a7065024ae290361ff274a321cb28ca202b387000a1d47 Miraielf mirai ua-wget
http://213.209.143.64/arcn/an/aelf ua-wget
http://213.209.143.64/mipsbd9c65cc309aa6ef706f8c9681de4cc39c32aa4291072722519b6baab55f349b Miraielf HailBot mirai ua-wget
http://213.209.143.64/mipsln/an/aelf ua-wget
http://213.209.143.64/sparcn/an/aelf ua-wget
http://213.209.143.64/x86ce527b630754a440a5e2bb447e34100818291bbc78513533429e148e580eac91 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
56
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-05T20:58:00Z UTC
Last seen:
2025-12-06T02:00:00Z UTC
Hits:
~10
Threat name:
Linux.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-12-05 18:25:51 UTC
File Type:
Text (Shell)
AV detection:
14 of 38 (36.84%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 47123066fa8948fe17fe994ba445ad68d9ee388f54c04fddabd2a393ba7dd56f

(this sample)

  
Delivery method
Distributed via web download

Comments