MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6dd36ae06f8ade5299fdb81d072d735d17d15dd4447ab7d1b2b71bf66e0b2b1a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 6dd36ae06f8ade5299fdb81d072d735d17d15dd4447ab7d1b2b71bf66e0b2b1a
SHA3-384 hash: ffc592206c31056bbd8a2df5efd0d267500fa7b9f29c69cc385302307e32aaebf3cb47e234ab76d2c363abff78552768
SHA1 hash: fced6e9a98cb1fd8b568f7698dbf1b4e1e4231d5
MD5 hash: c46ce91068e77aa58bd2127bec2ee6c3
humanhash: high-sierra-blossom-romeo
File name:sh.sh
Download: download sample
Signature Mirai
File size:1'633 bytes
First seen:2025-03-07 02:26:46 UTC
Last seen:2025-03-07 14:41:36 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vp4BppXzp3OumpaMeLpZno4pQBpp/qGpToypODpnu:vMRuGLHo4ap4GHyg
TLSH T195316FC911A225B96DFBD82272B9C8C871C0548B94EA3F0DFADD3CB499CDE0461647C3
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.134.5/jklx86fb1458decd00d0895af791f8fe6a8cbb5cc2a89e99e8c1aa7e4d5bda4cb87d0b Miraielf mirai
http://176.65.134.5/jklmipsef931d8ba4966260112b7ed31a1e0b5cd4423becc0397e8eeaee345de903a1ab Mirai403 dosbot Micheal mirai Mirai.TBOT skids Supplys ua-wget
http://176.65.134.5/jklmpsl9cf41e60807702cd85a42ffcabb10f2798193200a381b47f3adbebe65f8360aa Mirai403 dosbot Micheal mirai Mirai.TBOT skids Supplys ua-wget
http://176.65.134.5/jklarm49cf41e60807702cd85a42ffcabb10f2798193200a381b47f3adbebe65f8360aa Miraielf
http://176.65.134.5/jklarm57568e9e64ac1105cdcae20095154214ee943b2edc6c01e6d4b4eb0b7e06255a3 Mirai403 dosbot Micheal mirai Mirai.TBOT skids Supplys ua-wget
http://176.65.134.5/jklarm641342a887d2be09cf0165913b43a5916492e677d20429068d4829a090453ccbb Mirai403 dosbot Micheal mirai Mirai.TBOT skids Supplys ua-wget
http://176.65.134.5/jklarm7fe4e8d464b7849a5483782d0c47e53deaf199e284badad12ed98ca79e47a79d9 Mirai403 dosbot Micheal mirai Mirai.TBOT skids Supplys ua-wget
http://176.65.134.5/jklppc5573fc70c149f6676e1bae8e8a07d916b1690aeb06320689e17a54651c2c7133 Miraielf mirai
http://176.65.134.5/jklm68k2866188e4567599fab76b51f822d9a402bc85af7f74dd1927f6ea1af1632a3f2 Miraielf mirai
http://176.65.134.5/jklsh4b31d22cb1050faa0328fe4f05f03f450bbaccdc4a983d85f058cee4296890280 Miraielf mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
125
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
shellcode phishing agent overt
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Mirai
Status:
Malicious
First seen:
2025-03-07 02:27:21 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:botnet antivm botnet credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Renames itself
Unexpected DNS network traffic destination
Contacts a large (166189) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6dd36ae06f8ade5299fdb81d072d735d17d15dd4447ab7d1b2b71bf66e0b2b1a

(this sample)

  
Delivery method
Distributed via web download

Comments