MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 64da36cca835693f6125a3022974309ae6fb3cfedcb0efc642bccedbdbd0e98d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 64da36cca835693f6125a3022974309ae6fb3cfedcb0efc642bccedbdbd0e98d
SHA3-384 hash: 8a7e808252b0292677abf300861718bd5d1bcb0144372eed261371c4468a1fe4a9f284e9f6304a379212c127e02a8223
SHA1 hash: 4d8c67d8ccdc679e4335cc4fda853202d67d7304
MD5 hash: af11b5d7d17ce5e8b94c71d8a52d4b16
humanhash: mobile-batman-nevada-mars
File name:irn
Download: download sample
Signature Mirai
File size:654 bytes
First seen:2025-02-11 18:26:26 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:KSHTvxZ82nqNgQSjz1YnhM6p2n+5MaDFnINNI1MTUtZT1YnB6MbUznN:KmTvr8bN3Sjz1PqrKaDWNNIeTmZT1Obo
TLSH T19EF0DE961812750E8C1CBE7B72B118AEA312CE89959B8FFDEDC7183D8954940B434998
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.143.1.32/jklmips6cb427e528d9d6e68e43e97ff0f81ddd5768458159561d0fafdb5dffd0b6f7b2 Miraielf mirai ua-wget
http://193.143.1.32/jklmpsl86c056be36634614be66908d7f0972d73bb765bad533391385adf9656ac0151e Miraielf mirai ua-wget
http://193.143.1.32/jklarm06cd477d71445530f3bb6ec717e553569719b20cdaac7243640a275f051af2d8 Miraielf mirai ua-wget
http://193.143.1.32/jklarm555bb1f8005d2fa8d651b660d4244c862511ad4a087fc11e9f431bd46133a9557 Miraielf mirai ua-wget
http://193.143.1.32/jklarm68e97f80775e8068982c685ca7f316fe380199675311ba3edc6c289acf32762ee Miraielf mirai ua-wget
http://193.143.1.32/jklarm717bf13198278d1613f8fc3d44d0c2b307dedcb6b8d1b269c00f5d361ffa43ee9 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
mirai agent hype sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Result
Verdict:
UNKNOWN
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-02-11 18:22:47 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 64da36cca835693f6125a3022974309ae6fb3cfedcb0efc642bccedbdbd0e98d

(this sample)

  
Delivery method
Distributed via web download

Comments