MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 94e5bd8ea9fe4e85b890e59c2d266d922a0f2f05a6f5616d29c2d8e6be45b43c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 94e5bd8ea9fe4e85b890e59c2d266d922a0f2f05a6f5616d29c2d8e6be45b43c
SHA3-384 hash: c7a7b82a295be4775a9d9d1c6ede2bc7e4e4bc4b82ec30e1894b51f22aa3c5455087b62ac291270b58ca006f13484ac9
SHA1 hash: 1a6c7dba6e40d18a6d629e000edf4fa04aad1e84
MD5 hash: 5ede13fe3d552a6ab34b710ddd62b8c5
humanhash: thirteen-orange-friend-oranges
File name:c.sh
Download: download sample
Signature Mirai
File size:862 bytes
First seen:2025-05-11 17:07:29 UTC
Last seen:2025-05-11 18:02:45 UTC
File type: sh
MIME type:text/plain
ssdeep 12:3J3m0jQmiqQm6NIl5zAQmH0LKjQGMDOsQtCQn/QNuSEQdtaKAQPjQFJiAQFTfAUR:3J39YXNI71KSDux72tBIoHR
TLSH T1E711BECD335DD3D2AE4C8E64B1AE858C66A0F1C0F6F54F19F31588709899501389DB76
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.187.146.122/where/arm509963081d6c799251cbbf25526066a9be9b3448413c3abc7a4073577918f97b Miraielf mirai ua-wget
http://160.187.146.122/where/arm5c498c8a2be3901318c907d3348cfb56c24538113c4c1a0980d2e9154e02057f7 Miraielf mirai ua-wget
http://160.187.146.122/where/arm674b60fe779fa3f19d7b2c0e6538a296d65866d0cacad099ff2910a3eed80800b Miraielf mirai ua-wget
http://160.187.146.122/where/arm7n/an/aelf ua-wget
http://160.187.146.122/where/m68kb843187727c7023e81b4f46b44cd134b22a42e6fa142ced3a93e56789ebba039 Miraielf mirai ua-wget
http://160.187.146.122/where/mips99d556204d617458f4ab06e4e185387b18cd8d7d5f8c598ee3da29ec0bfde62d Miraielf mirai ua-wget
http://160.187.146.122/where/mpsl328877ceed439e27d8d0f637934bce0d0dd90aee64ec3ff913a20da699c83b59 Miraielf mirai ua-wget
http://160.187.146.122/where/ppc22fc95742f664d7480d568dcabc244ba0742d9883368751ea4c4cbeb15295ec3 Miraielf mirai ua-wget
http://160.187.146.122/where/sh4803729263e687b0518815441c596dcd3caa099215bc2cd08a7e950a79f2feb90 Miraielf mirai ua-wget
http://160.187.146.122/where/spc97d98e0af2b45bcc08d3bc3f486d769e3f897fc28e88e085f64588b37a6937f2 Miraielf mirai ua-wget
http://160.187.146.122/where/x86504cd68bd61c5e1007368a17f4a34ae03b0763d2ed9e5a38de1c48522cf4b383 Miraielf mirai ua-wget
http://160.187.146.122/where/x86_64n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
121
Origin country :
DE DE
Vendor Threat Intelligence
Threat name:
Linux.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-05-11 17:08:18 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 94e5bd8ea9fe4e85b890e59c2d266d922a0f2f05a6f5616d29c2d8e6be45b43c

(this sample)

  
Delivery method
Distributed via web download

Comments