MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c4740e23441ee28ea7661f8cab09e66a4e87bd28da2fa5ca19865505b825677e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: c4740e23441ee28ea7661f8cab09e66a4e87bd28da2fa5ca19865505b825677e
SHA3-384 hash: d625b01385dd12133bf7e9704c02c76a182067580bd07676a420589d090894225d719523ed9f632506b600edeabedd3a
SHA1 hash: 06de3f99d2a5ddd957969f0b6350ad6c9bad0ce8
MD5 hash: 502c3b6a6965a947d2f77ae9cf5e40f3
humanhash: papa-london-single-football
File name:w.sh
Download: download sample
Signature Mirai
File size:2'029 bytes
First seen:2025-09-14 12:26:11 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:EtpmwCpRhLp4OwpmqXppaU4pDfWkpmw+p1FqppdvvpEq1peYxNp:EtpmwCpRhLp4OwpmqXppaU4pDftpmw+a
TLSH T13141FFE625DA738DCE8E0C2D50456EB9148AFA8A3B0F4DACC28E207775C6D11A054EDB
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.armb420bd3eb08be7a46bda86980ce236e01f0e4f537ee66c893eebaa37741bfa6f Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.arm51fdd082f335e9e532f1039faee3748fb6d60315512158aa82a7f9635f5d00cd6 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.arm6a97ca61c136538ec7ddbe8c5d997b024ead03e2de794b43e14ffbcb82eeb0bc2 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.arm79a83ad82689920ca739d3788a5af2c528f9e505936fbe4c219d07b405ebd4b9f Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.m68k980313e319a6901fc1a0e56e2a8646311ffc185feb29676a6c00c841317c7de8 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.mips792382b8c6c7bb3e464ebb6e04dc0c5288372076d1160294843bb405ca6e983e Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.mpsld4d89cf3cded538c69ce6d967f1f9dabbac7e712793b63363f67b00448c3aa84 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.ppc8bb4df0aa4feb63db8be0bafa8c55c9604f4b3e208494c8908c8211c35212e77 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.sh46bfb2a7b07e99847de1cfb1549d92097a4e8ef3293de9f5951e66af12d86a076 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.spcd82bfbab2112ba7bfe20a67c4601647244480344814a4963a4a6005a69cc790d Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.x86b720ebdf7af675e22755b23a9c43d200958d3ae7da661fb85c427ad8f06aeaf3 Miraimirai opendir
http://160.187.246.158/nwfaiehg4ewijfgriehgirehaughrarg.x86_647348d7becd55ee6c4ad7ecb605a8ae9f4c3470d8f083250b72819845c695b181 Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
ps1
First seen:
2025-09-14T09:36:00Z UTC
Last seen:
2025-09-14T09:36:00Z UTC
Hits:
~10
Threat name:
Linux.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-09-14 13:04:31 UTC
File Type:
Text
AV detection:
15 of 38 (39.47%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c4740e23441ee28ea7661f8cab09e66a4e87bd28da2fa5ca19865505b825677e

(this sample)

  
Delivery method
Distributed via web download

Comments