MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b6441119603c0adc33902485fdd6d3cbfd9eae6d6d85642466044c3d7ff9e181. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: b6441119603c0adc33902485fdd6d3cbfd9eae6d6d85642466044c3d7ff9e181
SHA3-384 hash: 256d8742ec459ecb7ad96a87d2d8be7c76f99ab970885fd304c7a234db5681eaaa0874f7c63a045a4c860ff571ecd318
SHA1 hash: 04af9c5ac022c07364c67eaa11e52a90702251c4
MD5 hash: 2a9bc1428380d34ed64f6af5210be9f9
humanhash: kentucky-delaware-arizona-william
File name:hidden.sh
Download: download sample
Signature Mirai
File size:2'653 bytes
First seen:2025-01-19 12:01:48 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vltx/52EL8ofl5Z5PicLflJJ7047gA3vPVdXHXOu78qBjHk:v1BvlVVLNZZFVZ5S
TLSH T15B51D3CA359142323DE268F3B1F9849462D6C5EDC2C64EB497F534A8E48DF28B68C791
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.143.1.66/nA0diE1/pecga.x86fc139908a4cc0fa85ab1415b23e985863b4deb45b8cae876ac4583b58265660c Miraielf mirai opendir
http://193.143.1.66/nA0diE1/pecga.mipsdbc242b30bd1a02528949d6159b36b0487d3cc60a53fd2f1d407c25e2a80c508 Miraielf mirai opendir
http://193.143.1.66/nA0diE1/pecga.mpsl3d5754f374ebf513f7f4f9628121b4dbd2ece485eb40c6e8ac72acb2813bed79 Miraielf mirai opendir
http://193.143.1.66/nA0diE1/pecga.arm22ba65ade0c5700d09f2309de4d41ba7942f462ac06e3cc3026f2d0483e4ddb0 Miraielf mirai opendir
http://193.143.1.66/nA0diE1/pecga.arm530482b8f60b505ad06cab6af1715dbd63f896de0b91e054cc08f3f8130a7c280 Miraielf mirai opendir
http://193.143.1.66/nA0diE1/pecga.arm64f717dfd2a079f475a71771194d4538a841d4826ef27d0b18b5b3ae4cc18e269 Miraielf mirai opendir
http://193.143.1.66/nA0diE1/pecga.arm74e64cc3e81967c1b53542f1565097c315fb288621762aaf4b754f4a5ddd03678 Miraielf mirai opendir
http://193.143.1.66/nA0diE1/pecga.ppcb8fb124043b6406a2810bbd85b43f8af96d2e55e4c01a9d574ae9508eb3de9f6 Miraielf mirai opendir
http://193.143.1.66/nA0diE1/pecga.m68k1e862bdb67f1e9545edc9c43c69855ab2b974d27653ea8b91fead08b33ab1709 Miraielf mirai opendir
http://193.143.1.66/nA0diE1/pecga.spc03d0cc1607db3d49d7658c9f00e097a2f03b5d3ba682f0454777acc7f5e189d1 Miraielf mirai opendir
http://193.143.1.66/nA0diE1/pecga.i68603d0cc1607db3d49d7658c9f00e097a2f03b5d3ba682f0454777acc7f5e189d1 Miraielf opendir
http://193.143.1.66/nA0diE1/pecga.sh449c99a5dc72acb985d59341471ac50cf09d80fb75a8adfe1d358e185c8407270 Miraielf mirai opendir
http://193.143.1.66/nA0diE1/pecga.arc66e4960eb68af43115d0db277b6694616375749b41e6cfdab4ceaccb2853678f Miraielf mirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-01-19 12:02:04 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b6441119603c0adc33902485fdd6d3cbfd9eae6d6d85642466044c3d7ff9e181

(this sample)

  
Delivery method
Distributed via web download

Comments