MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6ca393164a1afa47eb12d005dafdf1bdcb0fd8203c636fe47862bf39b152c955. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 6ca393164a1afa47eb12d005dafdf1bdcb0fd8203c636fe47862bf39b152c955
SHA3-384 hash: 455de3d9caa997cc7cee858f51789ac1012d4014e5b82f2180b04333cc0528879c3d7332658606f393f73b19768e33bc
SHA1 hash: 148d28d5826be16afcf9488b4dcbfa52b2fc28cd
MD5 hash: 9a7751723fb4834749556d173aca3aaf
humanhash: oregon-five-uranus-twenty
File name:wget.sh
Download: download sample
Signature Mirai
File size:1'062 bytes
First seen:2025-04-26 20:09:31 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:qYft9IfY33I9YwSIwYxNIejIxYKLK/IVfY19IfYysIOYmwIaYiAfIkTY9lInY7nf:qYftyfY349YwHwYDkxYKLJVfY1yfYy1L
TLSH T12311F28EC3ACBC0550A9CF103059961456459AD1A5FD9FE9ED98CB2398DB530B258F0F
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.138.123/boatnet.mpsl4d7ea8f3d886eeb896892320c19e7258fe64b26109f90deafed39b394c724a60 Miraielf mirai
http://176.65.138.123/boatnet.arm4698ae7c36abaee38a3bc76cfdd7035d9144667b9af8ea1f46b053e11be7e0ce Miraielf mirai
http://176.65.138.123/boatnet.arm5d31c4e3bea8d4045df980114a5eec61e8fcbb16d8e2dd9e2224d8b2ade7a25c0 Miraielf mirai
http://176.65.138.123/boatnet.arm67fa3effea55a7e3c22e2caabbf9c5bfa4523ab7124ac5e9ef8fc5ebb8aa1157d Miraielf mirai
http://176.65.138.123/boatnet.arm78d0408083d088b4ce9d6caeb00c2656253cf470ad49001e27da4238f1e337fe8 Miraielf mirai
http://176.65.138.123/boatnet.m68k43b47bdb26dc63d4a7689fa1f53be7956110c14eccaa43e54c3deac0954f8a8a Miraielf mirai
http://176.65.138.123/boatnet.mipsf27dc83a57f5a7f400577171a9b2cb9144281bc3de55dc899794a12b96cbdadf Miraielf mirai
http://176.65.138.123/boatnet.ppcededa601443290dfa368ed1d83f067a29771fdaeb3bb7607d7b7a05d948d47a9 Miraielf mirai
http://176.65.138.123/boatnet.sh4dd07ce822c300e825e83c298d27e61b6d78fa94c824aa4b3ecb8b7d62f9cb77f Miraielf mirai
http://176.65.138.123/boatnet.spccaa3c15416a21c927447ffeceea9b3bb19573f262a758fc198536dea3388dd67 Miraielf mirai
http://176.65.138.123/boatnet.x860d646f1ece2189e6682a6f5783da2cc4d71172dc3d97840d9ef1bb2fa91dbc4f Miraielf mirai
http://176.65.138.123/boatnet.x86_64bd6a237d1af27f27452ccfa51843746910c79410baf30a2970375aa19bfd3bec Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
93
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
downloader trojan agent
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
lolbin remote
Threat name:
Document-HTML.Trojan.Vigorf
Status:
Malicious
First seen:
2025-04-26 20:02:10 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6ca393164a1afa47eb12d005dafdf1bdcb0fd8203c636fe47862bf39b152c955

(this sample)

  
Delivery method
Distributed via web download

Comments