MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8e147a2359c7460cd756ea1904560277446fcd0861d3ab4dc44021cf2a15cfbe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8e147a2359c7460cd756ea1904560277446fcd0861d3ab4dc44021cf2a15cfbe
SHA3-384 hash: 3efb0d00b9a78e6327f2a50eb88cea452e1db7b914f9ff4f3f5354a2f9543eda8510c3063c76ebf21ce37d5789e1dae3
SHA1 hash: 86cd9a2f46af877ead50924c0ad2e326c6aad540
MD5 hash: a66ba4a95ec057571de8afcde9944fcd
humanhash: blossom-golf-robert-ceiling
File name:w.sh
Download: download sample
Signature Mirai
File size:864 bytes
First seen:2025-02-26 21:08:32 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:kEjMSqMKNIl5zAM30LKjMxeTtaKAMu7nMqCMGM4B6jMitfAMsAMnAUn:lz8NI7aK2ytB8Nt9yn
TLSH T15811FADE617073B5084C9E29F36FAA08944A9FD0B2600E58D88C18F3AFA8D51F159F5A
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.32.162.27/arm53651a5084dd4a452154b579e35482c2578c910f3afd2a2f0fc32e272c9acd63 Miraibash curl elf mirai wget
http://193.32.162.27/arm56b7d5e51c586f28a78bbdfa463eb7ae2ac3d6986a9ee510e284b39aff9b53c9c Miraielf mirai
http://193.32.162.27/arm63bfa09b37b7c4d211a6d7e007c1f461fbc13f9bee6a1fd8dece92a2d6418bba0 Miraielf mirai
http://193.32.162.27/arm7e993c4b0c2014b2ddfa7225eae86ff92ec27b85704e032bc42dbd1568747a236 Miraielf mirai
http://193.32.162.27/sh40b1ae0d6db25ceccef1b8df07e541d80f88fdb34be77f48c91b2e93d986f0711 Miraielf mirai
http://193.32.162.27/arc0b1ae0d6db25ceccef1b8df07e541d80f88fdb34be77f48c91b2e93d986f0711 Miraibash curl elf mirai wget
http://193.32.162.27/mips4718246775cb5b4eae3ff9b6ed336b36b4df8ee67a899e75d09b973add656ed4 Mirai32-bit elf mirai
http://193.32.162.27/mipsel4718246775cb5b4eae3ff9b6ed336b36b4df8ee67a899e75d09b973add656ed4 Miraibash curl elf mirai wget
http://193.32.162.27/sparc4718246775cb5b4eae3ff9b6ed336b36b4df8ee67a899e75d09b973add656ed4 Miraibash curl elf mirai wget
http://193.32.162.27/x86_64779f8bd17f5d0e3bfe934ff0e1d88170fb132bfc95f08df0d7cb596d6e4de5cf Miraielf mirai
http://193.32.162.27/i686779f8bd17f5d0e3bfe934ff0e1d88170fb132bfc95f08df0d7cb596d6e4de5cf Miraibash curl elf mirai wget
http://193.32.162.27/i586779f8bd17f5d0e3bfe934ff0e1d88170fb132bfc95f08df0d7cb596d6e4de5cf Miraibash curl elf mirai wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Result
Verdict:
UNKNOWN
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2025-02-26 21:09:14 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8e147a2359c7460cd756ea1904560277446fcd0861d3ab4dc44021cf2a15cfbe

(this sample)

  
Delivery method
Distributed via web download

Comments