MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f6fe24cc25d8f6361f34a27102c04755729510bd5b74d5f03b0899180f8c5dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 8f6fe24cc25d8f6361f34a27102c04755729510bd5b74d5f03b0899180f8c5dd
SHA3-384 hash: da08f92ea1c776b53f7f52a4c8065276bbd09c3c7637f2bf13084a7355c9d54039e758e169112d7589191da0ef5b15d2
SHA1 hash: a0cceac199b8a05ae1d85bb44430f6248f7832f9
MD5 hash: a7707df38f86c75a7f360bef9f9f43a8
humanhash: eleven-potato-glucose-snake
File name:f
Download: download sample
Signature Mirai
File size:997 bytes
First seen:2026-01-13 00:54:28 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:X7NvVa7AfVa7hVa7SVa7vRpVa7qVa7gSVa7bSVa7aVa73vVa7nJVT:X5VaIVatVa+VabvVauVaDVaqVaWVaLve
TLSH T10911215E1201ADA4858DD47A37D2C30CB8C04FDD297B16556DA341B954E16CE737892A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/zerarm6e1eb38ceacb9b22d4feca47c5599c5327102fa22614c5cbe4dbb6dfe653a091 Miraielf gafgyt mirai ua-wget
http://130.12.180.64/zerarm5de82bd365213a87054f09be19c1f67ac8672b4924719ca900911448c5974ea68 Miraielf gafgyt mirai ua-wget
http://130.12.180.64/zerarm615328497efb82492607b67225a59d1d73d8d8334cba2f90f7acf1cbc85ef3cf7 Miraielf mirai ua-wget
http://130.12.180.64/zerarm74d68ee855dfd77cdf365e4af3a99a10412fe38f0c9d27f43ee2e16c306d42b4b Miraielf mirai ua-wget
http://130.12.180.64/zerm68kdbd962339ad6d9573d4a2ab32a8374dfc4759a2ed25e1c11bcf0fb15c38a783e Miraielf mirai ua-wget
http://130.12.180.64/zermipsdf87a7a75fbcb3907cd9a50599541a524827b421a1d37961cea908f5bd20fba1 Miraielf mirai ua-wget
http://130.12.180.64/zermpsld964a7a68c53a69a082064984e6779bf20d0b00f3e5eb6c729cf745650f7f595 Miraielf mirai ua-wget
http://130.12.180.64/zerppc30094855f734e99f964d9f3b8118d4b4ab2539fb277a71c1f80f41493648afae Miraielf mirai ua-wget
http://130.12.180.64/zersh459f07506dfea2ee3dfa47d07a28eaa8660c5290a50a5db6b21f6256e9c10ded2 Miraielf mirai ua-wget
http://130.12.180.64/zerspc318df882e7a506d224b9762fbdb5b82eed5cf3aedf80e8f674db6883189eb51c Miraielf mirai ua-wget
http://130.12.180.64/zerx8666dafc3cb09abe2c44e7042c4eeb384c077ecd8fb93641d766a95223e2748e2e Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
140
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-13T00:02:00Z UTC
Last seen:
2026-01-13T00:34:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=d9612535-1a00-0000-c832-86666d0c0000 pid=3181 /usr/bin/sudo guuid=bd655e38-1a00-0000-c832-8666740c0000 pid=3188 /tmp/sample.bin guuid=d9612535-1a00-0000-c832-86666d0c0000 pid=3181->guuid=bd655e38-1a00-0000-c832-8666740c0000 pid=3188 execve
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-01-13 01:19:13 UTC
File Type:
Text (Shell)
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8f6fe24cc25d8f6361f34a27102c04755729510bd5b74d5f03b0899180f8c5dd

(this sample)

  
Delivery method
Distributed via web download

Comments