MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a6cda9aaf6fba825d8188d5ccf561efbd5d2e8128fe46e7be24af6e12b7267c8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: a6cda9aaf6fba825d8188d5ccf561efbd5d2e8128fe46e7be24af6e12b7267c8
SHA3-384 hash: 1efe497d58863ea7de2cbde48bfe2e886135b9c2e272fc7c2501a7c662d7e57253cc36c53e1a257363fa16a28597effd
SHA1 hash: 34f3385070ad1ea4d606038baf6e8f7971f0cc3b
MD5 hash: bb33d7749a07d2d7e792736a47729507
humanhash: uranus-july-march-floor
File name:wget.sh
Download: download sample
Signature Mirai
File size:842 bytes
First seen:2025-12-13 08:55:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:KSs6wZjYTjYtXNyHe0fjYcswjNSYeJB/jKpLjYbynj9:KSKZjgKX67LsUteLKpHuyj9
TLSH T12501C6CD135477BD868CCE0FF6934F6824444ACE4E8A1BCD3ECC54269684ED5F824E58
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.146.122.62/arm45168bc663329c3b1d883b83a59fe84f08b6e01895c37144ddfa9156bea3eaee Mirai32-bit elf mirai Mozi
http://103.146.122.62/arm5c081b0cb0bf6317b1c5a57c3c6c821afc9656185960865bece92b13f5da8817a Miraielf mirai ua-wget
http://103.146.122.62/arm725d009b54cc805f0e3f69e011da81239bfb6422877c1574d62e0fbc988eab49a Miraielf mirai ua-wget
http://103.146.122.62/mipsa04ede576aa16c227ad500289a8c66fdd19fdbff2697ece9a24705418b42b9e0 Mirai32-bit elf mirai Mozi
http://103.146.122.62/mpsl25f528c64b08f744661e0a347d6f8152fa9b76e2f62f42c2351539186cc1dcde Gafgytelf gafgyt mirai ua-wget
http://103.146.122.62/arcb6ee760b9fbfe272a0013850886a8e4e0b4fd824fb44b2a038ce187e8126dece Miraielf mirai ua-wget
http://103.146.122.62/aarch6469008b5e7815c51d3b6d26bb29ebdd82057ee1c853b0368111bd47a3f145ba5f Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-05T03:22:00Z UTC
Last seen:
2025-12-14T17:43:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-02 22:02:16 UTC
File Type:
Text (Shell)
AV detection:
17 of 38 (44.74%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
antivm credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads process memory
Deletes log files
Enumerates running processes
File and Directory Permissions Modification
Deletes system logs
Executes dropped EXE
Renames itself
Unexpected DNS network traffic destination
Contacts a large (33119) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh a6cda9aaf6fba825d8188d5ccf561efbd5d2e8128fe46e7be24af6e12b7267c8

(this sample)

  
Delivery method
Distributed via web download

Comments