MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c0dfdacb0cd75b71c9ad81cb6cb9228798e8788910cc9f98a1e524824fc3f288. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: c0dfdacb0cd75b71c9ad81cb6cb9228798e8788910cc9f98a1e524824fc3f288
SHA3-384 hash: f27db0b6668335f03d782ad921052032c78457e1bdfb286e2b3acb86219c0db6778a5161127ced05873e6802ab2839bf
SHA1 hash: 2acffbfe4fe4a874c9026c1acb52427c73f51648
MD5 hash: 763563fc4063ddf07c9857e9322d6d78
humanhash: zulu-hot-harry-berlin
File name:wget.sh
Download: download sample
Signature Mirai
File size:1'965 bytes
First seen:2025-09-14 12:23:25 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:etpm6CpRbLp4IwpmqpqppdR+p1n4pDBWkpm6vpEU1peyapZNRvpEQ:etpm6CpRbLp4Iwpmqpqppz+p1n4pDBt2
TLSH T1B941F1E625DA628DDA8F0C2D50453EF9158FF64A3B1F4D68C28A207B78C6D016058DCB
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.armb420bd3eb08be7a46bda86980ce236e01f0e4f537ee66c893eebaa37741bfa6f Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.arm51fdd082f335e9e532f1039faee3748fb6d60315512158aa82a7f9635f5d00cd6 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.arm6a97ca61c136538ec7ddbe8c5d997b024ead03e2de794b43e14ffbcb82eeb0bc2 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.arm79a83ad82689920ca739d3788a5af2c528f9e505936fbe4c219d07b405ebd4b9f Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.sh46bfb2a7b07e99847de1cfb1549d92097a4e8ef3293de9f5951e66af12d86a076 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.ppc8bb4df0aa4feb63db8be0bafa8c55c9604f4b3e208494c8908c8211c35212e77 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.mips792382b8c6c7bb3e464ebb6e04dc0c5288372076d1160294843bb405ca6e983e Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.mpsld4d89cf3cded538c69ce6d967f1f9dabbac7e712793b63363f67b00448c3aa84 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.spcd82bfbab2112ba7bfe20a67c4601647244480344814a4963a4a6005a69cc790d Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.x86b720ebdf7af675e22755b23a9c43d200958d3ae7da661fb85c427ad8f06aeaf3 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.x86_647348d7becd55ee6c4ad7ecb605a8ae9f4c3470d8f083250b72819845c695b181 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.i586n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
ps1
First seen:
2025-08-20T21:22:00Z UTC
Last seen:
2025-08-20T21:22:00Z UTC
Hits:
~10
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2025-09-14 13:03:34 UTC
File Type:
Text
AV detection:
13 of 24 (54.17%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c0dfdacb0cd75b71c9ad81cb6cb9228798e8788910cc9f98a1e524824fc3f288

(this sample)

  
Delivery method
Distributed via web download

Comments