MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a6d61bbd1f776ce0fdef1b0651a8bb216aef1638b212fa020e3b92c9e6e26989. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: a6d61bbd1f776ce0fdef1b0651a8bb216aef1638b212fa020e3b92c9e6e26989
SHA3-384 hash: f2e500d96062da181f8d47e6d2f4e5369b2bd4af7a0bde73464f37107d745e56023dc76ba1f57b9038aa820b96442feb
SHA1 hash: 574b365e0b92514b536bea2eb9efb501f34e95a8
MD5 hash: 6dfcadbff7da56326f71b4c24c14afb6
humanhash: delta-juliet-whiskey-mike
File name:li
Download: download sample
Signature Mirai
File size:994 bytes
First seen:2026-01-11 19:04:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:HO75Va7M5fVa7tVa7+Va7VpVa7uVa7DVa7qVa7WVa7TVa7bJVT:uVVaw1VapVaaVa/VaiVa/VauVayVanVI
TLSH T1B011335E0101ADA4848CD53937C2D10CB8C04FDD19BB1BA45EA7017E54F12CF7338E29
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/splarmbd715871ed31ff6163a4f854c5ffa1f8f68e6800d2f6018ee03f19b89b597e3e Miraielf mirai ua-wget
http://130.12.180.64/splarm5d50efedc59af498b7f0cf79f2e0ee2cc2c87f3bde528d47393b4f1006a84f11a Miraielf mirai ua-wget
http://130.12.180.64/splarm67719b420e339519ffc00f758578e213f565f8c0c431b09928926f74083f950dc Miraielf mirai ua-wget
http://130.12.180.64/splarm74123da745435d01d5d48ba3545542adb1e9b5ff39ca967526c4b084103d2386b Miraielf mirai ua-wget
http://130.12.180.64/splm68k8b4d48627caebf4b1c68616a70e098146a7b19fe5d7ae58efbc7f57a835d2768 Miraielf mirai ua-wget
http://130.12.180.64/splmipsfc618fd78ecaf993b3b831901cc96d780a502cfd49426ab3dfab83fae75c0197 Miraielf mirai ua-wget
http://130.12.180.64/splmpsl4e57f33b9e542352340b5e29f489d0b4dc22f0e371b8920d730d631a7c4bef4d Miraielf mirai ua-wget
http://130.12.180.64/splppc5ea361dd0b5af5accd4ba2a384d8312f92dbcec47418ccb20745f808446af1d7 Miraielf mirai ua-wget
http://130.12.180.64/splsh45c73e5adc065b5193ab562bed697ceb00bce8ea4232ea405a8cd280920030bf0 Miraielf mirai ua-wget
http://130.12.180.64/splspc7f6e3b8b63ac7df59ee54c2a0376cb878a3f6fe3ead4ac8dc0801c1476111ddf Miraielf mirai ua-wget
http://130.12.180.64/splx86a6dc9997b1063107643a95e17d73d1ee2843386808f36b599b3a2541ca209ff3 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-11T16:48:00Z UTC
Last seen:
2026-01-11T18:53:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=5f645ff8-1900-0000-4861-1118470c0000 pid=3143 /usr/bin/sudo guuid=be9a70fa-1900-0000-4861-11184e0c0000 pid=3150 /tmp/sample.bin guuid=5f645ff8-1900-0000-4861-1118470c0000 pid=3143->guuid=be9a70fa-1900-0000-4861-11184e0c0000 pid=3150 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-01-11 19:10:08 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh a6d61bbd1f776ce0fdef1b0651a8bb216aef1638b212fa020e3b92c9e6e26989

(this sample)

  
Delivery method
Distributed via web download

Comments