MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8639977fbb7f8a242889744c8ce08e3b02d208a7a7d55a00e23deffb842871cb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8639977fbb7f8a242889744c8ce08e3b02d208a7a7d55a00e23deffb842871cb
SHA3-384 hash: 3f464f96f3553a4a630ba96e0b28db02460db975bb69067e1f9ac3019bfe9fcffa93118eeb3f1dd94897d0304e2ec1fa
SHA1 hash: 32bf01dbd412abdacfa59d120cb1e7707b220a9c
MD5 hash: 1cc72f9690e3abdfe86ba009a24a8da4
humanhash: eleven-equal-grey-texas
File name:w.sh
Download: download sample
Signature Mirai
File size:886 bytes
First seen:2025-03-29 15:22:10 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:GjU4qUMNIl5zAUt0LKjUN+OsU4CUi/U3SEUKtaKAUgjUQiAUFyfAUR:Gg47MNI75UKgsi4Di83EKtBl3QaFMHR
TLSH T13A11A0CE325893D1DC8C8FA071AA88986558F7C076558F4DEB4C88B2A9C4D197999F3C
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.187.146.122/armc8b221b3f1fe50842ac45a52fc7217ecdf671d3bfaca51be78c9076923165341 Miraielf mirai
http://160.187.146.122/arm5fbadf8857d11880dd756c01c12d2997dd41d56a87b48b90eab9b336b8d54732e Miraielf mirai
http://160.187.146.122/arm6422204b0ec9f3e4143d99ea39589cf57c796b20c0303004c6288807b0c5b5b35 Miraielf mirai
http://160.187.146.122/arm7n/an/an/a
http://160.187.146.122/m68k87fc4abaf843ed6606550555c0defb2c0a0d4fdceff3575c249a8e58a959d359 Moobotelf mirai moobot
http://160.187.146.122/mips28f26f2cfee85c12784adff883084aba4e33d0847f2f41e452fbc2982f8a4a81 Miraielf mirai
http://160.187.146.122/mpsl357ec744a44dc3e96b96e9ed41fec9a5824f265b61b7487543bfd7edceb5264e Miraielf mirai
http://160.187.146.122/ppc513075d1fb167b1d277ddae6a18679661946657a741c85c939397b1de7f4545b Miraielf mirai
http://160.187.146.122/sh47dd6e0655b381a0beab5551df632145cf6534869f88e04be8e2254167da0bf57 Miraielf mirai
http://160.187.146.122/spc78724c0c385692f039e6731dbc9b317173957ba57ba43ae9921733a581fb470b Miraielf mirai
http://160.187.146.122/x86d72eb9a4d384022aec3c46b783ae63d99ec8c25dacf476bdd7b2b4249c4a7022 Miraielf mirai
http://160.187.146.122/x86_64n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
backdoor trojan hype
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Threat name:
Script-Shell.Downloader.Mirai
Status:
Malicious
First seen:
2025-03-29 15:23:13 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8639977fbb7f8a242889744c8ce08e3b02d208a7a7d55a00e23deffb842871cb

(this sample)

  
Delivery method
Distributed via web download

Comments