MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4812e217f4ff45508ea28cafa918964c49e24795b8b5052aa55bf64644e828c8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 4812e217f4ff45508ea28cafa918964c49e24795b8b5052aa55bf64644e828c8
SHA3-384 hash: 3c58fe6caa21397e7bae168e609c7812b6a4a0773d1e505cb4e9482b9cf45edbbb724af5622313dc11d7939eb085774a
SHA1 hash: eaa7aebc694c028eeca7b68f48b5bf67d0e161ad
MD5 hash: ad1d122e44a30ebe0962e519ffa9667e
humanhash: pluto-indigo-hawaii-alanine
File name:b
Download: download sample
Signature Mirai
File size:311 bytes
First seen:2025-12-06 16:30:47 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:h9OnFflE0FJ60hMwXJfLFNfZ5B6Ea5XKbF8dvwtMs:d0FJ73JDhy7COs
TLSH T145E086D9A4720071B84CBE2AA56D47586051F795A9C4272444DBBD91D81CD453446A27
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://bpy.is/f1d4d24c9fc8553770036239bc2be91e1865a5ec6ec8316cb0380117a42380329 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-06T14:35:00Z UTC
Last seen:
2025-12-07T01:41:00Z UTC
Hits:
~10
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-06 16:12:57 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4812e217f4ff45508ea28cafa918964c49e24795b8b5052aa55bf64644e828c8

(this sample)

  
Delivery method
Distributed via web download

Comments