MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8b98474a02a14a4ec364b66a958123d8712a2b5057d2415ad53e0369d67c0337. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8b98474a02a14a4ec364b66a958123d8712a2b5057d2415ad53e0369d67c0337
SHA3-384 hash: 1faf0311ea1f575d921fca3f382e55c329f25cbacfefb41bd78d54f642ca2e1fe4df7df4b87f1bb8748b8e1ca1e51690
SHA1 hash: 6db841b20ae0eb999970facf2bcd86d7e34bd231
MD5 hash: 97827d18c12ae1495c196b14906a1250
humanhash: river-mountain-sad-carbon
File name:cn
Download: download sample
Signature Mirai
File size:546 bytes
First seen:2025-03-07 00:46:40 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:afWmTKYfWjIhtfWiHRfWxufW1NIbtvtfWmYI:eWmTK8WjIh1WiHBWxaW1NIbtv1WfI
TLSH T1CBF0F9CD9863398245ACFD1E72B7A6CEB951838C140F1B8EBCC5187DD89CA94F069BD4
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.134.5/mipsef931d8ba4966260112b7ed31a1e0b5cd4423becc0397e8eeaee345de903a1ab Mirai403 dosbot Micheal mirai Mirai.TBOT skids Supplys ua-wget
http://176.65.134.5/mpsl9cf41e60807702cd85a42ffcabb10f2798193200a381b47f3adbebe65f8360aa Mirai403 dosbot Micheal mirai Mirai.TBOT skids Supplys ua-wget
http://176.65.134.5/armc4fd68b20997f3c8a60dbadf177b3309d465f0a8bb0ad9b33b4c70ee74dc3a90 Mirai403 dosbot Micheal mirai Mirai.TBOT skids Supplys ua-wget
http://176.65.134.5/arm57568e9e64ac1105cdcae20095154214ee943b2edc6c01e6d4b4eb0b7e06255a3 Mirai403 dosbot Micheal mirai Mirai.TBOT skids Supplys ua-wget
http://176.65.134.5/arm641342a887d2be09cf0165913b43a5916492e677d20429068d4829a090453ccbb Mirai403 dosbot Micheal mirai Mirai.TBOT skids Supplys ua-wget
http://176.65.134.5/arm7fe4e8d464b7849a5483782d0c47e53deaf199e284badad12ed98ca79e47a79d9 Mirai403 dosbot Micheal mirai Mirai.TBOT skids Supplys ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
129
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
mirai agent virus shell
Result
Verdict:
UNKNOWN
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-03-07 05:48:20 UTC
File Type:
Text (Shell)
AV detection:
15 of 38 (39.47%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8b98474a02a14a4ec364b66a958123d8712a2b5057d2415ad53e0369d67c0337

(this sample)

  
Delivery method
Distributed via web download

Comments