MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c3252c2dfa3ffbb915ad59f1b620d7273caf598392360697b923114991f318d1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: c3252c2dfa3ffbb915ad59f1b620d7273caf598392360697b923114991f318d1
SHA3-384 hash: 8207c819ca37ec09328d08083bc421a57fbec4504242237bf96a24ba8d1b6ed4a37d1f17a630719158f2febd9bf9191a
SHA1 hash: 03c301aec7065f566d3056485c222685a169653e
MD5 hash: 70ca85b14477842b5ffe035160ab49e6
humanhash: hydrogen-lamp-london-jersey
File name:c.sh
Download: download sample
Signature Mirai
File size:861 bytes
First seen:2025-03-06 09:46:42 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:3J3DMTtVWAbNWA3eJTW4DDWV4ZJn20tThyuA:VMTPHbNH3eJTW4nXLnZtThyf
TLSH T1B5113C8E52A5F2415D6CCD1D7067C10DBB61D2CEF86D5E40F29CA9F0EAC41047878FA6
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.140.135/drea4b7a8882a502098f8b51aa06b9c215be250307c4e355f6f7073819d2562f23741 Miraielf mirai
http://176.65.140.135/vejfa55ebfaa628075bc3731fb8901e570c63163df5cbdf211ef452d0aeda6877247a8 Miraielf mirai
http://176.65.140.135/efea611c0436f0741bb589a1498e00793e89c2b1736bda1d576c12eb07fb2bf916383 Miraielf mirai
http://176.65.140.135/efefa7b15eca8497ee7c754ae99626c1b50afc2777afb0178f4b052aa7c75136c28c20 Miraielf mirai
http://176.65.140.135/eehah4e07bdb3a4a02e3678c2cf9e95e42526aa6833f916f9ba5a02f7f6e9b87b7a589 Miraielf mirai
http://176.65.140.135/rjfe686f327ab37d2c795344b9ece6b06744d3ec0b2fb0bffa4f3001c36080c1f1f2189 Miraielf mirai
http://176.65.140.135/vjwe68k80852be512eca4d9373bc31291353467c465b4ec941397289b8484aafe303ebd Miraielf mirai
http://176.65.140.135/efjepc533e7a32f1b2080de97659a6df20a672a988bd0c6e13988ea85c5f1a254a19f8 Miraielf mirai
http://176.65.140.135/jfeeps00937209bfc651fb263deaec059ea7eb0b40c3c224c66648d606946aab58723f Miraielf mirai
http://176.65.140.135/weje6491d2c341f6489f94dfa001ef9151e56fa6f8331b218733a8b6f4152f3685fe2a Miraielf mirai
http://176.65.140.135/rrrdsl5b6a3ddaea69d6a2b4bde62a543fefb22c055e6f3b0165d415d00e12c62bdb64 Miraielf mirai
http://176.65.140.135/bejv86c247239e9373395f8f485f350d1d38c78656d72c6dcf6bf61551fb32100aad0e Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
134
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-03-06 09:47:18 UTC
File Type:
Text (Makefile)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c3252c2dfa3ffbb915ad59f1b620d7273caf598392360697b923114991f318d1

(this sample)

  
Delivery method
Distributed via web download

Comments