MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae5a1d7672b52b420e37cf9b44a901d81850b77e7c581752a7b3507f45984483. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: ae5a1d7672b52b420e37cf9b44a901d81850b77e7c581752a7b3507f45984483
SHA3-384 hash: 5b902875203e431f5206acd3c60d76ade91e3bb14d99885701c95a9fa97242a6b265cf22479b5fe689571af76c5da7d5
SHA1 hash: 896113de1c3583c9e70b97b96fc025ee6c9c4771
MD5 hash: d08d89061e84206aaa3beb912ffc6052
humanhash: delaware-happy-timing-carolina
File name:weed
Download: download sample
Signature Mirai
File size:3'530 bytes
First seen:2025-03-21 10:22:44 UTC
Last seen:2025-03-22 08:30:13 UTC
File type: sh
MIME type:text/plain
ssdeep 48:1tD90/FN80WTRa5lmKNJawewEs3rMLE13qJXFv:1tUFNIRFKNm9s4I1qXFv
TLSH T1C4715CD87E516EB2CB0EDF84E1218C94B5A3D8E30551CB11597F45B8C9F8A093634AAF
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://156.253.230.23/nimips5b339544ba55c78bff25dbd5e737cd854d6c61d5ed3b1866d6d5fe110a8a9d7e Miraimirai ua-wget
http://156.253.230.23/mpsla15bf9dd4d0aad9778ab4380feb71ca2cf314765a78f8dbb5275f1343a9f5b8e Miraimirai ua-wget
http://156.253.230.23/arm33ffeb7f9d5e17ad498d9ca9843e31844d7421e04917b3a9a1475c53c177c05b Miraimirai ua-wget
http://156.253.230.23/arm5c2d51bc86e52742a4d5bfc9541667690c516aaf1d7a4f971f4eee77d79c89076 Miraimirai ua-wget
http://156.253.230.23/arm63a23ff501ce58ec816fa09f77f8b8e9b79934199688f6f8aaf2d8e32caad1435 Miraielf geofenced mirai ua-wget
http://156.253.230.23/arm7091b84349ab71754a9f74f93525a054a64b98f17799013df02f2dfb42ce918da Miraielf mirai ua-wget
http://156.253.230.23/ppc41d7eb8d26f4db1c4efaa16ee1c230d3f4760a4c5a4c334c037d4efb1c5fc6a3 Miraielf mirai ua-wget
http://156.253.230.23/sh43dc6298bbf1922c1d5c6d34f9a45fa0ce297c5438ec63fdfdcd562b1732ac6ac Miraimirai ua-wget
ftp://6.253.230.23:8021/nimipsn/an/an/a
ftp://6.253.230.23:8021/mpsln/an/an/a
ftp://6.253.230.23:8021/armn/an/an/a
ftp://6.253.230.23:8021/arm5n/an/an/a
ftp://6.253.230.23:8021/arm7n/an/an/a
ftp://6.253.230.23:8021/ppcn/an/an/a
ftp://6.253.230.23:8021/sh4n/an/an/a
ftp://6.253.230.23:8021/arm6n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
76
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
93.3%
Tags:
trojan botnet agent
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
expand lolbin remote
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Mirai
Status:
Malicious
First seen:
2025-03-21 11:59:49 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ae5a1d7672b52b420e37cf9b44a901d81850b77e7c581752a7b3507f45984483

(this sample)

  
Delivery method
Distributed via web download

Comments