MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54f17039d5076d09e26b85e4f16ee9b05aad57b26e27425481294fc1105fc12f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 54f17039d5076d09e26b85e4f16ee9b05aad57b26e27425481294fc1105fc12f
SHA3-384 hash: 7f1646e8356845b3c08a2ba0abe240fbbd9b94a7375e81f1f1c7d22321c2740bdee9b839eb3fac9151af0dd09c9ca806
SHA1 hash: 815b127d25833b32e1a407085002e1abcf206000
MD5 hash: 5ccef8f938724fc16f2192fd0049c02b
humanhash: harry-cup-fourteen-may
File name:tot
Download: download sample
Signature Mirai
File size:985 bytes
First seen:2025-12-21 15:14:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:E43Z43M5343l43643Vp43K43T43O43y43D43bJh:Ey3tMvufCR14ah
TLSH T17011519E15107DB1445CD6A57B928108B5809BC918F70E685FE9063A4DFA28C3328E29
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/splarm58437e27972eaa1c41a3979eb2702a162859de6989ec13c2320c8167646154fe Miraielf gafgyt mirai ua-wget
http://130.12.180.64/splarm57e00f77027719cb9765deb9277c19d8b40c88b46615260ad93d0afb886823108 Miraielf gafgyt mirai ua-wget
http://130.12.180.64/splarm69d2d570444ed159fe100228afbb3adeb12ebf28255d592ce8f1e0ccdeca6af0a Miraielf mirai ua-wget
http://130.12.180.64/splarm7ea147f75569a79b6594801335977ac607b790ab362f6c43b8f64b8157abff727 Miraielf mirai ua-wget
http://130.12.180.64/splm68k88e63dfeca5efe7db364bce1b8b5b75701e7ffb2deba8f6fca954894cc98a91f Miraielf mirai ua-wget
http://130.12.180.64/splmips32215d5ef9898986309b2c83ca8d9a40cef938953cd8e9936038e6d81be99139 Miraielf mirai ua-wget
http://130.12.180.64/splmpsl31fbd5a4cb53048cb780455fc0973eaa37baef2cb874c3f51298298c2be7d273 Miraielf mirai ua-wget
http://130.12.180.64/splppcae11c290aaf522f11e91b9c05f022d6e7bf31b5cc2b6406c60a7618584db22a2 Miraielf mirai ua-wget
http://130.12.180.64/splsh49ae60e993b5915b716b8685a04821d55ba1d16b4727c1644fe83a0c97a833ade Miraielf mirai ua-wget
http://130.12.180.64/splspc7256bbee58a1fec663e4343b6faa8eb36aa486ea28fc380d4ab358227b06d8ee Miraielf mirai ua-wget
http://130.12.180.64/splx869ca7eaf7a185704e633ee776bd789d5c8a81446027d0424bb19b0fbf8e77406a Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-21T12:34:00Z UTC
Last seen:
2025-12-23T12:48:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-21 15:37:13 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 54f17039d5076d09e26b85e4f16ee9b05aad57b26e27425481294fc1105fc12f

(this sample)

  
Delivery method
Distributed via web download

Comments