MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c84b0aa49c19799f9019444fee7e488eac73fe0af1997d4d1c60879dd38e8e80. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: c84b0aa49c19799f9019444fee7e488eac73fe0af1997d4d1c60879dd38e8e80
SHA3-384 hash: 4b1b123a3c5bc2812a6d65c0d299071b412248a73ba242db046d7527690a7586ad0d0699d6c7ac2a0c517a75b3d71254
SHA1 hash: 2560b7ca5e799522b67bc7eeec9ea9f709515791
MD5 hash: adc333e7164f3e0ea94e9ea715473356
humanhash: foxtrot-steak-kitten-double
File name:esf
Download: download sample
Signature Mirai
File size:1'027 bytes
First seen:2025-12-21 15:13:32 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:HO7fsa7M5tsa7Dsa7Asa7Vvsa7Qsa7Bsa7Msa74sa7xsa7bPse:uAawgaEaPamaHamaja3aea8e
TLSH T11E11215E1101EE90948CD4393781920CF4804FD929BB0AA85EDA017E58F06CE7338F29
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/splarm8f6a29ee517a7bb5d9c3db16b8363420c732d8a9d7993da16006a05a6b80c836 Miraielf mirai ua-wget
http://130.12.180.64/splarm599126f681aa44a7d9b99678bdc492133341e2de0ca22c50b014a1e43b8ae2d91 Miraielf mirai ua-wget
http://130.12.180.64/splarm6fa62bcbb4cff0013ab416aaa10c8fe9b2c3beb731db15f27eafba9f81d761343 Miraielf mirai ua-wget
http://130.12.180.64/splarm77cc0c7d015dfef9d1917318d0ec9b7cb9d1bb80d8b2b0bff615814bc2a0726eb Miraielf mirai ua-wget
http://130.12.180.64/splm68kc437b3ebe72cd0ec30b6adc633a002b1203d94eb95bc4e452ecaa4af4d0f2f67 Miraielf mirai ua-wget
http://130.12.180.64/splmipsdcb690747a11527c5ad9919521ffd27a29563f24c19df3d7f9218fdea6e88622 Miraielf mirai ua-wget
http://130.12.180.64/splmpsl0cffd5f3473dde6aecb03030cb95efa81c7e1a1bc218528dc318348af422c8cc Miraielf mirai ua-wget
http://130.12.180.64/splppc619c3fc25ff1f4fbca7aaff8426fe85b5134ad836c12ee7c779d232011576e64 Miraielf mirai ua-wget
http://130.12.180.64/splsh4677dd974a94d8f27bcbf2d487d0c7f1609324d7fc5c0a9ec7d96500e31e7bccb Miraielf mirai ua-wget
http://130.12.180.64/splspce40a515af36d187ea6a3ab5462061306f9ce49fd8a19943a2045d600d2b45760 Miraielf mirai ua-wget
http://130.12.180.64/splx86c3c5917188e96e623db9af3452fed9c0339e633b7f4890edc1e954ae60ac2424 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-21T12:35:00Z UTC
Last seen:
2025-12-23T12:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=c389b09a-1900-0000-af7f-34cdd7090000 pid=2519 /usr/bin/sudo guuid=6658f59d-1900-0000-af7f-34cddf090000 pid=2527 /tmp/sample.bin guuid=c389b09a-1900-0000-af7f-34cdd7090000 pid=2519->guuid=6658f59d-1900-0000-af7f-34cddf090000 pid=2527 execve
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-21 15:30:32 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c84b0aa49c19799f9019444fee7e488eac73fe0af1997d4d1c60879dd38e8e80

(this sample)

  
Delivery method
Distributed via web download

Comments