MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 942fcee6e6ee3ac530608079fbaa88c9e654cea683386e45323f3db695714385. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 942fcee6e6ee3ac530608079fbaa88c9e654cea683386e45323f3db695714385
SHA3-384 hash: 0358a26779d7680ed0d9d16e0d07aab1254220c0d4ae484b578593e39932c1b7b1f476a744ae6717d9d01fc73a9beb12
SHA1 hash: 65d34d67e69dd2eb5ac9ca43fa0a03f9ab575c9d
MD5 hash: 0a53b1eb820f426ed6497addf1a9a7c3
humanhash: indigo-river-florida-one
File name:check.sh
Download: download sample
Signature Mirai
File size:1'473 bytes
First seen:2026-02-26 04:47:18 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:VUeYj+H1geDMK9CFdYhEnHQ6Yl60mOD+nl72tZ9Hg9I5M5GR2QZaZl1cSRs/:VUeYj+H1geDMK9CnYhEK0U3lgl5YjjSu
TLSH T19531BF8253227E3C3CC565DEA1AA4495A146922F05BF2F7474C5AEF66B0C440F368F71
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://64.120.95.129/check.sh942fcee6e6ee3ac530608079fbaa88c9e654cea683386e45323f3db695714385 Miraimirai sh ua-wget
http://64.120.95.129/syst3mddcf343df280816c4856ee164b9b4b14906a09b1fd4bfab604ee9370529ed61d1 Miraielf miner mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
99
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
bash lolbin
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.cw
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-02-20 00:10:09 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Command and Scripting Interpreter: Unix Shell
Enumerates kernel/hardware configuration
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Deletes log files
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Indicator Removal: Clear Command History
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 942fcee6e6ee3ac530608079fbaa88c9e654cea683386e45323f3db695714385

(this sample)

  
Delivery method
Distributed via web download

Comments