MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aff538d6b5b0c58f881f11de50f67baed41ccbdca3d4ba73b94c9300f343d900. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: aff538d6b5b0c58f881f11de50f67baed41ccbdca3d4ba73b94c9300f343d900
SHA3-384 hash: 5df619623a681ab201e9e72cb2d0c91869a6b058af2ce9220fedc8b4f0d5a84a6a312b96407cdb74fe0bc9208b014cc5
SHA1 hash: c2ccbf8a8aa97324efc1794ab5e82ecc89950fa8
MD5 hash: 2d7ab9da08f0022d323186c76ebfc718
humanhash: xray-comet-idaho-avocado
File name:bash
Download: download sample
Signature Mirai
File size:2'070 bytes
First seen:2025-04-11 19:27:29 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:0CBCocBcNIwiX5xQKiS2/oBMyByxrnrHYFOLLaK2DH14w/8KES0:9DCEVrHYFoLsH1vE
TLSH T12D41DBDD307A249723F2C4B76A12A14F103890B6925FBBEDACF8017D95F8744761BB94
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
DE DE
Vendor Threat Intelligence
Threat name:
Script-Shell.Trojan.MiraiA
Status:
Malicious
First seen:
2025-04-11 18:44:02 UTC
File Type:
Text (Shell)
AV detection:
7 of 38 (18.42%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
newageofkifirempire.camdvr.org
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh aff538d6b5b0c58f881f11de50f67baed41ccbdca3d4ba73b94c9300f343d900

(this sample)

  
Delivery method
Distributed via web download

Comments