MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 787f256a1c3c37fc9f17326edbeb1359aea1fb1ac831b761b05583997aa8dc71. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 787f256a1c3c37fc9f17326edbeb1359aea1fb1ac831b761b05583997aa8dc71
SHA3-384 hash: cc2695ec4e896f84ba10e0076c4a35fb37bb55457d454f2a9c15f84747b109dea4c617b81e39fd3035ca336bbcf58d0f
SHA1 hash: adbe8218a8ba786d3f4ca7452e235e320edc14fd
MD5 hash: 5f41e3e3d337462f0e27e5b62c6ce709
humanhash: oklahoma-pennsylvania-september-magnesium
File name:wget.sh
Download: download sample
Signature Mirai
File size:835 bytes
First seen:2025-12-02 04:54:52 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:KSs6wZFYmFYQNyHe0fFYRswJGSYeJB/JvpLFrynFI:KSKZFJN6NMsnedpBryFI
TLSH T1F201E9CE41902B754DC8E90FB5938E1C104946CA0B8A17CA7EDC5837ABD4ADEF004E58
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://23.132.164.18/arma3d5e3c3e422d72ef0e095e164f2706e250839eaf52e24dd7624f6e3e250f8da Mirai32-bit elf mirai Mozi
http://23.132.164.18/arm5788e47fcc1f7e85da5b575ddeb98980fafc9cab532c378855556d679da2a59be Miraielf mirai ua-wget
http://23.132.164.18/arm7547d1e75421bbbfe0492e2191417ad070d3e1e40db837e9aa4737c7946cd67b7 Miraielf mirai ua-wget
http://23.132.164.18/mips67df849f3252e566ca8f73336ab31eb7b5ddb277c91f90a9dac885c9d9de3837 Mirai32-bit elf mirai Mozi
http://23.132.164.18/mpsl449e30caaa96c2833e4f381071095addc874ad4bab41e21225acf6356145c0ed Miraielf mirai ua-wget
http://23.132.164.18/arc40340e3a77486c1369e0c0983e376950720970a61d9645ecccdc68e6a10337f5 Miraielf mirai ua-wget
http://23.132.164.18/aarch647cf1b7da477075d7c365bd1fb986b170fac4e9c5b32252ad7e53940e24495f86 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox expand lolbin
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-02T03:08:00Z UTC
Last seen:
2025-12-02T23:15:00Z UTC
Hits:
~10
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-12-02 04:46:05 UTC
AV detection:
8 of 36 (22.22%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
antivm credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads process memory
Creates a large amount of network flows
Deletes log files
Enumerates running processes
File and Directory Permissions Modification
Deletes system logs
Executes dropped EXE
Renames itself
Unexpected DNS network traffic destination
Contacts a large (14306) amount of remote hosts
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 787f256a1c3c37fc9f17326edbeb1359aea1fb1ac831b761b05583997aa8dc71

(this sample)

  
Delivery method
Distributed via web download

Comments