MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5b59cc0c7dce41f23553fdd2b7590f4657d7013c0cac3686007845e08eb9a840. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 5b59cc0c7dce41f23553fdd2b7590f4657d7013c0cac3686007845e08eb9a840
SHA3-384 hash: 3b1b9fe7749322ac3029d095b107626f6d2d4af3ee256d4bcfa45dc3a673fddd8909ea952b24a11fa861ff00734396c2
SHA1 hash: e685829aeb863e9ea27c723b0b4b3c7c07f62dd9
MD5 hash: 657e8a250879a48524b9ff9ac371828f
humanhash: seven-video-pasta-alanine
File name:k.sh
Download: download sample
Signature Mirai
File size:512 bytes
First seen:2025-03-15 00:18:39 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:od8VLLF955dFRLLF955drLLF955dlI3LLF955dc7LLF955d8LLF9k:oKVLx5lLx5xLx57qLx5O7Lx5qLc
TLSH T144F012DA3C1159098D03D5842537D911B215C1DCA580871679A73539D0786B47D11B88
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.120.253.44/re.bot.mipsac61fe040ab4b5679119b4bb6292fe940170c4511f1da3e780292bbac1a044f6 Miraiddos elf mirai
http://87.120.253.44/re.bot.mpslc08cddb3d6804838132d55afddce2bfdb6d0870977dad7eb99bdd3f73f75ba4e Miraiddos elf mirai
http://87.120.253.44/re.bot.armn/an/addos elf mirai
http://87.120.253.44/re.bot.arm5n/an/addos elf mirai
http://87.120.253.44/re.bot.arm707ef12e0741251ae867210ed7db52419181baefa7981075d41afcbd7567bd3d2 Miraiddos elf mirai
http://87.120.253.44/re.bot.aarch64n/an/addos elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
downloader mirai agent virus
Result
Verdict:
MALICIOUS
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-03-15 00:20:21 UTC
File Type:
Text (Shell)
AV detection:
11 of 36 (30.56%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5b59cc0c7dce41f23553fdd2b7590f4657d7013c0cac3686007845e08eb9a840

(this sample)

  
Delivery method
Distributed via web download

Comments