MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53171bbb629eee5595e5b1e17a718545974df736f50a224d2272aba81b004ce1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 53171bbb629eee5595e5b1e17a718545974df736f50a224d2272aba81b004ce1
SHA3-384 hash: ee2a40245b9c3d3736eade2479774b13923b5a0551bbff00a52f424294e85d9e50ca67106f83ef413d6e79c8445c72af
SHA1 hash: 587926b6f2d3f22b756de2576200af2b38eaf428
MD5 hash: 372b5eda599e5dc9964575d90e79576e
humanhash: oklahoma-venus-minnesota-uncle
File name:w
Download: download sample
Signature Mirai
File size:893 bytes
First seen:2025-12-21 15:13:50 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:0im4Y/mnI/mn/mm/GERC/z/z8L/bL/j/3IL/niL:zNY/AI/K/L/vRC/z/gL/bL/j/3Y/niL
TLSH T1B211AE5F1200796040CDE46536D1CA0874888BCDEA760E246FF152B944F86CD377CF2B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/zerarm179cfdbd65f960c0b9fb37197d7c140151289d9fe1e0672b23bc0ad426338748 Miraielf gafgyt mirai ua-wget
http://130.12.180.64/zerarm5c69f89332f107754f5c5e63b50dd23a67f5a6e4c8815d1e08f1343bc374f43fb Miraielf gafgyt mirai ua-wget
http://130.12.180.64/zerarm67be74146ce1ff5c722bd8c19959e748bbf631a026de7bc5052906c926999688f Miraielf mirai ua-wget
http://130.12.180.64/zerarm73f200a3f58080153144d9de9fc6793935953d69b0cab3ad0f3e53b7a28c0606f Miraielf mirai ua-wget
http://130.12.180.64/zerm68k7cc4369130d23cc86f1f4fec5fd83b360bf53f6e5e5ed486fbf0f2c1e90549f0 Miraielf mirai ua-wget
http://130.12.180.64/zermips1db8393738f9732c74bd79fe6b05588b0e70c484015d4511b75a0a9648b29779 Miraielf mirai ua-wget
http://130.12.180.64/zermpslc27bd5d6ac8115410b857aef6615746145506482f8418bf5e8c3882dc7207db8 Miraielf mirai ua-wget
http://130.12.180.64/zerppc9e8b9ade3a80abdb7033dbdd1127ae712eb586e0e3d4e2f907a416a2572574e9 Miraielf mirai ua-wget
http://130.12.180.64/zersh4066bce416db0f320e1745ffc6c3e382ffae95f6ddfbf8498fa9c9f2622366906 Miraielf mirai ua-wget
http://130.12.180.64/zerspcc0f4e3dac179613297cd7898ad6bef9f17b83b7bd8e257c82e6b64d2ddeaad7b Miraielf mirai ua-wget
http://130.12.180.64/zerx861e08428a405fcbe010f206ec2cfe36203b7b5f9b83cf6129e2a511622b77df2f Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-21T12:33:00Z UTC
Last seen:
2025-12-22T23:44:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=359e0a6b-1900-0000-6fc1-b926660a0000 pid=2662 /usr/bin/sudo guuid=724e066d-1900-0000-6fc1-b9266e0a0000 pid=2670 /tmp/sample.bin guuid=359e0a6b-1900-0000-6fc1-b926660a0000 pid=2662->guuid=724e066d-1900-0000-6fc1-b9266e0a0000 pid=2670 execve
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-21 15:32:20 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 53171bbb629eee5595e5b1e17a718545974df736f50a224d2272aba81b004ce1

(this sample)

  
Delivery method
Distributed via web download

Comments