MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9e52c51d2d3cd11be1efe60406e5a3ff06495acc84eb11adefc947a849238f72. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 9e52c51d2d3cd11be1efe60406e5a3ff06495acc84eb11adefc947a849238f72
SHA3-384 hash: ac304d1827def11ffbd9c31d392eb76d821bde7901cbd1bae1c771af01f8587ec0e4fb43be795e232b38fa8382a2d02c
SHA1 hash: b4f4fa776af5bafa33ffb867ed0e91570ff3ec5f
MD5 hash: 3e24cd0d06cd1a6e5e461958ef74603e
humanhash: south-georgia-artist-hot
File name:w.sh
Download: download sample
Signature Mirai
File size:3'887 bytes
First seen:2025-06-09 10:34:50 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:nAeN9YGYv9MT9jG9Yx9hI9BI919wp9je9K9V91xO9aQrOdMg9c9DDAskU91nd9pn:MpWWrytDAsk09
TLSH T19F8191CB6550ECB30DB3EF076B13B7B451C4FA970DA7D668C0C85A5C8895994328FB86
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://178.62.82.167/static/ciubuc_x86f4acf9dbb7f288725b7aa17877fc927c6017152786d0f749b6317b02b93445b6 Miraielf mirai ua-wget
http://178.62.82.167/static/ciubuc_aarch646779ecfe357e9d44c8213b1dce3dee0a325e304a1c6404700f5ae9a8dc8bfaaa Miraielf mirai ua-wget
http://178.62.82.167/static/ciubuc_arma61ab1e350c7bab7b3a318bd7d44cd07840350f21d5cb4a25b6d9348962998bb Miraielf mirai ua-wget
http://178.62.82.167/static/ciubuc_arm506d5466f12126e3e2512471bd66759c4ed817c34ef78f8c9f7298964e2321026 Miraielf mirai ua-wget
http://178.62.82.167/static/ciubuc_arm6cea8f78291bf79cdaa7610bcffefa71167b5c559c03f41319b306ff82fc87de3 Miraielf mirai ua-wget
http://178.62.82.167/static/ciubuc_arm7da9e923ead4ab0693adb3a72e41b1c8fcdd483015b13144e06ed3ac692b3794f Miraielf mirai ua-wget
http://178.62.82.167/static/ciubuc_i486n/an/aelf ua-wget
http://178.62.82.167/static/ciubuc_i586n/an/aelf ua-wget
http://178.62.82.167/static/ciubuc_i686n/an/aelf ua-wget
http://178.62.82.167/static/ciubuc_m68k87f14d1f5d107a77b634f5cf79761b827a4088c373ce7cab4966569bf1e14bc8 Miraielf mirai ua-wget
http://178.62.82.167/static/ciubuc_mipsa92087a514477e8e1aa47efe53ab16088a00572625290336073ee2c502a7b362 Miraielf mirai ua-wget
http://178.62.82.167/static/ciubuc_mips6491a91e18ae521ad11fca0f083348394bc88288297222b039a88c12fd4826dd93 Miraielf mirai ua-wget
http://178.62.82.167/static/ciubuc_mpsl04abd5367789751db0e4f0bd207c905d6efbda98816127d35c375d3e6e4e5d68 Miraielf mirai ua-wget
http://178.62.82.167/static/ciubuc_ppce68fdd628193df4d146bd9c4fc46706db65b93b1d113b037831d7ee5f4db9a88 Miraielf mirai ua-wget
http://178.62.82.167/static/ciubuc_sh444e65ab0db99731f1b422c1c6a47b43c55b4b263333681d1ae7b97be2389360c Miraielf mirai ua-wget
http://178.62.82.167/static/ciubuc_spcn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
shellcode agent hype
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-06-09 10:37:14 UTC
File Type:
Text (Shell)
AV detection:
10 of 23 (43.48%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Mirai
Mirai family
Malware Config
C2 Extraction:
hotel.wildhorsehotel.net
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 9e52c51d2d3cd11be1efe60406e5a3ff06495acc84eb11adefc947a849238f72

(this sample)

  
Delivery method
Distributed via web download

Comments