MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ab0f5764f11fea3c42aa70524bebb47d1e561f1f6214313550a024fdddf6549c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: ab0f5764f11fea3c42aa70524bebb47d1e561f1f6214313550a024fdddf6549c
SHA3-384 hash: 494d005e1638644645f13f134304ee0c630e5d20dfd4260579b6735a82f54c13c47656738893784b468d535151b37f2f
SHA1 hash: f7b13b756621777dd18c5269783bae81615956fc
MD5 hash: 2b92b2a887b11b94b68cd235c809b617
humanhash: pip-oklahoma-edward-skylark
File name:wget.sh
Download: download sample
Signature Mirai
File size:899 bytes
First seen:2025-12-13 08:43:26 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:yw378YhAUlk39NIl5dvCa0LKNuNgOFx2JMJUO7tjQpSOZ74Nt28JDf2G9kMftL:cwlWNI78KZIwM5GlGNtfNO0BfZ
TLSH T1E81194DF26921FF289689F0CFD730464900682C5F4631E786A87583A8CE6705BA25BD6
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.156.152.6/bins/armfcde6f5c944b25a7a99e71303163f96337522e75dd3ae4063266f638642971ae Miraielf mirai ua-wget
http://94.156.152.6/bins/arm5f05b323569eea22a77466ad81b2269a088c65afef9dcd3aae7694d1082956c44 Miraielf mirai ua-wget
http://94.156.152.6/bins/arm62ab741a76d21bf01542e22bfa650e4aef178aa0c60ea101e6c71e8b72224afb0 Miraielf mirai ua-wget
http://94.156.152.6/bins/arm7c31fcc01f0f596380a39690803dc56937cf44e444e9343a6acc0bb9ea400ad96 Miraielf mirai ua-wget
http://94.156.152.6/bins/m68k0c59e69f26fb1625f225e51a5cd7e4b5a01df562278c358f91bfce6f6ca2bc63 Miraielf mirai ua-wget
http://94.156.152.6/bins/mips5bb6555cfd3e08d19dfe8e568e6115e3d44b756a92a643ce09299c0b3bf80f3c Mirai32-bit elf mirai Mozi
http://94.156.152.6/bins/mpsln/an/aelf ua-wget
http://94.156.152.6/bins/ppc0d24ee35cf06c1519b2b075ccaf2bf491635639b8756223d3b93c8a3a6afe7b9 Miraielf mirai ua-wget
http://94.156.152.6/bins/sh4f9f248474004bdcb9dd077f59e01df30250af3df79caf217aee330cb8b6c8618 Miraielf mirai ua-wget
http://94.156.152.6/bins/spcc7f7ccd1145ae14e5dc9000fd88a59bbc08f12d70f9ba34c3df631162dc54894 Miraielf mirai ua-wget
http://94.156.152.6/bins/x86290d4ed63719a0ed2362bf726abe742e0bdc5bf0d75d4644996e063928b471bf Mirai32-bit elf mirai Mozi
http://94.156.152.6/bins/x86_64f40e7ac020e9810f49a0c4ae156de58ced9ee1e65c8cb1d6e2cf39db9de2c77d Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-13T05:54:00Z UTC
Last seen:
2025-12-14T12:08:00Z UTC
Hits:
~10
Threat name:
Document-HTML.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-13 08:39:15 UTC
File Type:
Text (Shell)
AV detection:
17 of 38 (44.74%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ab0f5764f11fea3c42aa70524bebb47d1e561f1f6214313550a024fdddf6549c

(this sample)

  
Delivery method
Distributed via web download

Comments