MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a00385d1e4618586712709fc8d3ea8002b8e01dc3cdf9de1145d2d7faacd7eb7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: a00385d1e4618586712709fc8d3ea8002b8e01dc3cdf9de1145d2d7faacd7eb7
SHA3-384 hash: 67c6efcfbd84b5396ba4e5a945c815d53c332c05b7634cab02bd606b7b520dcefc243b9afee7cf60e3d40f4a207c0e68
SHA1 hash: 1e6431ad01e4df91380a61847273a8ccefead150
MD5 hash: 88911776f3bf72c59f99aa8343ac899e
humanhash: kilo-red-uniform-quebec
File name:w.sh
Download: download sample
Signature Mirai
File size:891 bytes
First seen:2025-04-26 13:07:27 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:NRgtD7tFNI75tNKgtBtBlt7UtRDt4tbwgttltbtqA:NRgtD7tw5tNLtJlt7UtFt4t0gttltbtj
TLSH T11911C6CF215696610E4E4E58F22A5BA8EA46EFD230504F68944C44F37AA8D14B629F0A
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.77.240.231/arm8901880a311752e5fbd35d4b4d49b3688c7ac11b8d1daac136ce521442aa43bd Miraielf mirai
http://103.77.240.231/arm5f75e2ca9f1df6579aad4dffc021ea152ad18d7a85225035f12a7acba4e3ffec2 Miraielf mirai
http://103.77.240.231/arm6d4513eec03a905618779d8b8c3a64fb74c64fb5b482e2f7753c8028dc3411163 Miraielf mirai
http://103.77.240.231/arm7ad5545dd5d11b840a9283904da705708f4af037e5830d9357a033bce08f172b3 Miraielf mirai
http://103.77.240.231/sh49a3a6949bfc0682dc83a4e62493490cc1da075b437cd3683ed62d2485334e9c7 Miraielf mirai
http://103.77.240.231/arcn/an/an/a
http://103.77.240.231/mips4a1d31ec9168bde507f91d1c0c027ef551b1c75c07b52435605a53d65e21df22 Miraielf mirai
http://103.77.240.231/mipseln/an/an/a
http://103.77.240.231/sparcn/an/an/a
http://103.77.240.231/x86_64bd0a87a41d34faa2ac1ac95d2da225c14cd1f13c87d610ff76142edb87ee19d0 Miraielf mirai
http://103.77.240.231/i686n/an/an/a
http://103.77.240.231/i586n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
trojan mirai virus html
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-04-26 13:08:15 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh a00385d1e4618586712709fc8d3ea8002b8e01dc3cdf9de1145d2d7faacd7eb7

(this sample)

  
Delivery method
Distributed via web download

Comments