MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc897284eea230580b9b187457b3a293433a7dc3ea378d85fbd351fe4f179ce5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: bc897284eea230580b9b187457b3a293433a7dc3ea378d85fbd351fe4f179ce5
SHA3-384 hash: 1f4fc68aeba8144d423242cd17172af357094c040cf7ae9ce072ce347f8e467e0407a0be76d377fd7d01c4c842024039
SHA1 hash: 74fcdeefdb0b3f61f8c8fcffc41bcd29f39f503a
MD5 hash: 4cd37cc3524151d97fd940a9045e5ad7
humanhash: uniform-cold-batman-oranges
File name:calix
Download: download sample
Signature Mirai
File size:1'009 bytes
First seen:2025-12-21 15:13:35 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:+7XYa7M5tYa7bYa7iYa7VHYa7SYa7hYa7uYa7KYa7xYa7bnY7:+caw8a4aRa+aZa+ataJaGaA7
TLSH T15D11215F4201AED0858CD43A7783C10CB4844BD919BB06E45E96057E14F42CE7338E59
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/splarmd967f32dac513d1ea8f02c8137174c784fff987c887dff1bf0a2b8178e1624bc Miraielf mirai ua-wget
http://130.12.180.64/splarm557672f91464676b6b331c8ed2dd675eb63d46e42c5e21358eb1ef1bccb5bba68 Miraielf mirai ua-wget
http://130.12.180.64/splarm6b12c8efcac2af8b598c7075aeb2df78e8d373fd27c15013046a4ead6289a5f49 Miraielf mirai ua-wget
http://130.12.180.64/splarm7ccb58d3643e5813f781813ab9e5348702f68b146a93ec3cfb0c35879f0837f17 Miraielf mirai ua-wget
http://130.12.180.64/splm68kb800b350f64f189597936304c1b4bf2132f14c60cd0d21f9915914f1a6e016ca Miraielf mirai ua-wget
http://130.12.180.64/splmips99119aaf01d3b317ca0e6cf7a8912f4980b6071211483242336795337cfe17e0 Miraielf mirai ua-wget
http://130.12.180.64/splmpsl5a11b3bc9145663f668b8124d193fa6035534206318a29b53071c807bfceb2e0 Miraielf mirai ua-wget
http://130.12.180.64/splppcc2d899639364442f75c9b58dc718184312c1fc1401154f587b1a4aca3c7f72a9 Miraielf mirai ua-wget
http://130.12.180.64/splsh4406278399a23fd8ef8d4c9e17a4d3245a5aea266287559641aadde419ac69421 Miraielf mirai ua-wget
http://130.12.180.64/splspccf4eb1234011f39b0893d13f4825c78420608402621551ff8814a50ad2ba6fa3 Miraielf mirai ua-wget
http://130.12.180.64/splx860a8d25eb0ba2300c1419dbe3ccf13e01b32659293ad75e90ef9945a7e0ef78a6 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-21T12:39:00Z UTC
Last seen:
2025-12-21T14:59:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=87dadf16-1a00-0000-8b7a-6d919f0a0000 pid=2719 /usr/bin/sudo guuid=fe900619-1a00-0000-8b7a-6d91a70a0000 pid=2727 /tmp/sample.bin guuid=87dadf16-1a00-0000-8b7a-6d919f0a0000 pid=2719->guuid=fe900619-1a00-0000-8b7a-6d91a70a0000 pid=2727 execve
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-21 15:30:40 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh bc897284eea230580b9b187457b3a293433a7dc3ea378d85fbd351fe4f179ce5

(this sample)

  
Delivery method
Distributed via web download

Comments