🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 768aadcb776b4adb4869d8a795f78187b2b43c2a8ccc148548b313a76259f13d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 768aadcb776b4adb4869d8a795f78187b2b43c2a8ccc148548b313a76259f13d
SHA3-384 hash: 4a78b4890a30dd4b7a5d59cf709680db7135b826051fb2fbeceaacb1e740762fd976e68eab1db0fbb74f675a614d3c64
SHA1 hash: 4eddfcdbc63d7370193c7e9484100deb4ced803c
MD5 hash: 5df392cfa823695575a9e9a43989df3d
humanhash: blossom-edward-september-red
File name:xx.sh
Download: download sample
Signature Mirai
File size:457 bytes
First seen:2025-02-20 17:32:03 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:oHT2LcHsyHTLJ62yHTu8HsyHTZEZsyHfhbg2yHfmFhV8O0:y2LcMyzLE2yzu8MyzZby/hry/qV8j
TLSH T184F0E58E1434B230590E4E91BBF29706B28FB2D16D280B3F980A44F78CAD74CB019F89
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.224.0.236/am.nn68e1ee3e1b5e0d16f4d54798d2173857ac570240dbe77cd79a67eab64b7a51ad Miraicensys elf mirai ua-wget
http://185.224.0.236/am5.nnad366b5ea62f2db18e78ce894b7ed5e3c6d2cddc79da2180ea003c15a0f9cceb Miraicensys elf mirai ua-wget
http://185.224.0.236/am6.nn9d0b5f1906e031ac9c1444132dcfb793f0a8d6708e491996677dbd8daeed7f2c Miraicensys elf mirai ua-wget
http://185.224.0.236/am7.nn84ec0609acd424357c718e41b21c632400c619f011a78567c953fb545b99ab9f Miraicensys elf mirai ua-wget
http://185.224.0.236/mis.nnn/an/an/a
http://185.224.0.236/mpsl.nn0fb77e7212fb7874d8f8cc7e52eb74b454bbb9df8e789b7fc6a69a8548370a4d Miraicensys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
lolbin mirai remote
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-02-20 17:32:20 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet defense_evasion linux
Behaviour
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
nnmmab.0u8n.com
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 768aadcb776b4adb4869d8a795f78187b2b43c2a8ccc148548b313a76259f13d

(this sample)

  
Delivery method
Distributed via web download

Comments