MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c8b4c20ce8f4c03f0b57f78385effb917b8efded2f3afc1459e84eec3dde94e7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: c8b4c20ce8f4c03f0b57f78385effb917b8efded2f3afc1459e84eec3dde94e7
SHA3-384 hash: fa4de86242616285136228bba112d78483cc42d3376c41aad13e4ab600b8944efba21fb3f94bc232efebf7312056536d
SHA1 hash: c79bcb11132b39d1216b1904460cff777629522b
MD5 hash: 58c6525062f7e85295421658431d8786
humanhash: fruit-cola-blue-march
File name:2.sh
Download: download sample
Signature Mirai
File size:3'210 bytes
First seen:2025-11-20 16:44:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:/4LdGVVeHa04cUPFy+MRJh+JB0ryA/NvsuNQ:/4LdGVVeHa04cUPFy+LJB0ryA/NVQ
TLSH T1CC6172F6518807356CE2AB97627D4048709692A740FA7F23A7DC38B15D8DFDCBC41663
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://41.216.189.110/00101010101001/S3o.x86d3f10f6d5e3c2b912e20a40579c75536930b660f07129c21bbd9788ac4efc728 Miraielf geofenced mirai opendir ua-wget USA x86
http://41.216.189.110/00101010101001/S3o.mips21782793f8c22a44cc00c57d28fc4468469c09be0879bae0921e423ff5a55f17 Miraielf geofenced mips mirai opendir ua-wget USA
http://41.216.189.110/00101010101001/S3o.arc20b10e19db7094870b5c049dfab380a9af22bf0ab6b857d016f6e1870e0555a6 Miraiarc elf geofenced mirai opendir ua-wget USA
http://41.216.189.110/00101010101001/S3o.i468n/an/aelf ua-wget
http://41.216.189.110/00101010101001/S3o.i68666f67c3960faab5dafa836ccaf9bc63733dc49a84e972fdd81bc47c45e6eb5fa Miraielf geofenced mirai opendir ua-wget USA x86
http://41.216.189.110/00101010101001/S3o.x86_6413c4df50e1cac452500fa11a328b86e70414281a294016b02151dff0152faf5c Miraielf geofenced mirai opendir ua-wget USA x86
http://41.216.189.110/00101010101001/S3o.mpsl5c08ebe6558b86f3ab363b062cefb8e699a27f699d7d1e4cc67d90fb3e5766c6 Miraielf geofenced mips mirai opendir ua-wget USA
http://41.216.189.110/00101010101001/S3o.armfbe97ea7d5fad0c72fe5249bbfadff0d9c0f5ec90b0bcd4b1ad354bba51abba4 Miraiarm elf geofenced mirai opendir ua-wget USA
http://41.216.189.110/00101010101001/S3o.arm548494bc2a98774569b60d6e657af2c1c781be83867fe60a12a8fa2f4279964b6 Miraiarm elf geofenced mirai opendir ua-wget USA
http://41.216.189.110/00101010101001/S3o.arm686d1089b91ce9ce616774fee8146704ea26f33188be13aa4aba1efff6c5ec79c Miraiarm elf geofenced mirai opendir ua-wget USA
http://41.216.189.110/00101010101001/S3o.arm7759b7b535e312929274b186c9baa02472a9cc3731e56c997c8fdf401a7dd9a61 Miraiarm elf geofenced mirai opendir ua-wget USA
http://41.216.189.110/00101010101001/S3o.ppc81f81e4ad3508cd865b9245b2c856241111d01b7fa839f20e202815589a0f043 Miraielf geofenced mirai opendir PowerPC ua-wget USA
http://41.216.189.110/00101010101001/S3o.spc3789076d4c74180c9ea1f824f606fb32b2ef97c635cc8f567cd8b0bd598ca2e8 Miraielf geofenced mirai opendir sparc ua-wget USA
http://41.216.189.110/00101010101001/S3o.m68kbb719d6a4197953f3bf91eff21abb3692df553e35cf0c78a87ca25834731b6dd Miraielf geofenced m68k mirai opendir ua-wget USA
http://41.216.189.110/00101010101001/S3o.sh4a1cbc4b0188f1476ed7c316842583952b48c0069473d00b1b212fac91764450f Miraielf geofenced mirai opendir SuperH ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-20T09:59:00Z UTC
Last seen:
2025-11-20T11:58:00Z UTC
Hits:
~10
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-11-20 15:31:49 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c8b4c20ce8f4c03f0b57f78385effb917b8efded2f3afc1459e84eec3dde94e7

(this sample)

  
Delivery method
Distributed via web download

Comments