MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8de8ec0aabdd853bcfe8c3c47ab4e72ae025e023a9ac9ec6e2c47159382d6920. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8de8ec0aabdd853bcfe8c3c47ab4e72ae025e023a9ac9ec6e2c47159382d6920
SHA3-384 hash: a7544162c83c6eb0b72b2f9db3ab9fe5ab75cdf8d566e0d841090b09c9cf876ce9bd1796e2ede5aebc96d5471396f32d
SHA1 hash: 2911e7f941662aa172033cdff24151729436ff64
MD5 hash: 1ebcb63ef77a4034694b30102979f3f4
humanhash: football-cat-hawaii-gee
File name:c.sh
Download: download sample
Signature Mirai
File size:768 bytes
First seen:2025-02-26 21:08:38 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3VEjxVSqxVKNIl5zAxV30LKjxVxeTtaKAxVu7nxVqCxVGxV4B6jxVitfAxVsAt:3J3q6XNI79K5ytBHOPsUn
TLSH T166011EDC627062A71F2C9E2AF36FA6089542DBD0B3700D10E86418B2DCEC643F058F67
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.32.162.27/arm779f8bd17f5d0e3bfe934ff0e1d88170fb132bfc95f08df0d7cb596d6e4de5cf Miraibash curl elf mirai wget
http://193.32.162.27/arm56b7d5e51c586f28a78bbdfa463eb7ae2ac3d6986a9ee510e284b39aff9b53c9c Miraielf mirai
http://193.32.162.27/arm63bfa09b37b7c4d211a6d7e007c1f461fbc13f9bee6a1fd8dece92a2d6418bba0 Miraielf mirai
http://193.32.162.27/arm7e993c4b0c2014b2ddfa7225eae86ff92ec27b85704e032bc42dbd1568747a236 Miraielf mirai
http://193.32.162.27/sh40b1ae0d6db25ceccef1b8df07e541d80f88fdb34be77f48c91b2e93d986f0711 Miraielf mirai
http://193.32.162.27/arc0b1ae0d6db25ceccef1b8df07e541d80f88fdb34be77f48c91b2e93d986f0711 Miraibash curl elf mirai wget
http://193.32.162.27/mips4718246775cb5b4eae3ff9b6ed336b36b4df8ee67a899e75d09b973add656ed4 Mirai32-bit elf mirai
http://193.32.162.27/mipsel4718246775cb5b4eae3ff9b6ed336b36b4df8ee67a899e75d09b973add656ed4 Miraibash curl elf mirai wget
http://193.32.162.27/sparc4718246775cb5b4eae3ff9b6ed336b36b4df8ee67a899e75d09b973add656ed4 Miraibash curl elf mirai wget
http://193.32.162.27/x86_64779f8bd17f5d0e3bfe934ff0e1d88170fb132bfc95f08df0d7cb596d6e4de5cf Miraielf mirai
http://193.32.162.27/i686779f8bd17f5d0e3bfe934ff0e1d88170fb132bfc95f08df0d7cb596d6e4de5cf Miraibash curl elf mirai wget
http://193.32.162.27/i586779f8bd17f5d0e3bfe934ff0e1d88170fb132bfc95f08df0d7cb596d6e4de5cf Miraibash curl elf mirai wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Result
Verdict:
UNKNOWN
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-02-26 21:09:17 UTC
File Type:
Text
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8de8ec0aabdd853bcfe8c3c47ab4e72ae025e023a9ac9ec6e2c47159382d6920

(this sample)

  
Delivery method
Distributed via web download

Comments