MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9af69589bf24c39e7c22ff1b994f86b4fe95d7b104169665ba247a38fcdc99de. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 9af69589bf24c39e7c22ff1b994f86b4fe95d7b104169665ba247a38fcdc99de
SHA3-384 hash: 693e535ec907f802de6cdb0db81957fac945b6e0324f506a33e710248c0c4c2c0489b52eedb24c72953e00a3396515a5
SHA1 hash: 4de7a321dfba41127139189dfa79f25702de65f9
MD5 hash: 9c5c436711fcfd29bfff4f4c38a7a20a
humanhash: queen-hot-vermont-robin
File name:w.sh
Download: download sample
Signature Mirai
File size:1'066 bytes
First seen:2025-08-20 16:16:03 UTC
Last seen:2025-08-20 17:47:44 UTC
File type: sh
MIME type:text/plain
ssdeep 12:XiVUMxCWEUyNI9kxwAU/ySKxWHUzyFUePCUskVUwjvUwxRI4qKAU9JeUpx7+cAU8:ymW5yNIqcfKxzLKs1aMA1xlHvig0HR
TLSH T1241169DF21A46280045ECDC53A9A4C085F89CEE1E89CDB29ADFC4FF651D6A287549F08
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://74.201.28.102/bins/bot.armn/an/an/a
http://74.201.28.102/bins/bot.arm5n/an/an/a
http://74.201.28.102/bins/bot.arm6n/an/an/a
http://74.201.28.102/bins/bot.arm7n/an/an/a
http://74.201.28.102/bins/bot.m68kn/an/an/a
http://74.201.28.102/bins/bot.mipsn/an/an/a
http://74.201.28.102/bins/bot.mpsln/an/an/a
http://74.201.28.102/bins/bot.ppcn/an/aelf
http://74.201.28.102/bins/bot.sh4n/an/aelf
http://74.201.28.102/bins/bot.spcn/an/an/a
http://74.201.28.102/bins/bot.x86n/an/an/a
http://74.201.28.102/bins/bot.x86_64n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=a5e0d75f-1a00-0000-edb8-261d960b0000 pid=2966 /usr/bin/sudo guuid=3924d862-1a00-0000-edb8-261d980b0000 pid=2968 /tmp/sample.bin guuid=a5e0d75f-1a00-0000-edb8-261d960b0000 pid=2966->guuid=3924d862-1a00-0000-edb8-261d980b0000 pid=2968 execve guuid=dca33563-1a00-0000-edb8-261d990b0000 pid=2969 /usr/bin/busybox guuid=3924d862-1a00-0000-edb8-261d980b0000 pid=2968->guuid=dca33563-1a00-0000-edb8-261d990b0000 pid=2969 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-08-20 16:09:52 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 9af69589bf24c39e7c22ff1b994f86b4fe95d7b104169665ba247a38fcdc99de

(this sample)

32d0aa3ced98ba184a5fc383c7e74b39895fc45abfb6738935b370c2cc88e486

  
Delivery method
Distributed via web download
  
Dropping
MD5 4902cfad4497fac4083e1c80012c2f6e
  
Dropping
SHA256 32d0aa3ced98ba184a5fc383c7e74b39895fc45abfb6738935b370c2cc88e486

Comments